Skip to main content

Echobot Botnet

Echobot is a newly observed botnet based upon the source code of Mirai. Like Mirai, Echobot primarily targets IoT devices but can target other platforms including web servers and private data centres.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Echobot is a newly observed botnet based upon the source code of Mirai. Like Mirai, Echobot primarily targets IoT devices but can target other platforms including web servers and private data centres.


Threat details

The attackers behind Echobot continue to develop the malware and at present it is known to be able to exploit 26 vulnerabilities in order to propagate.

At present the botnets purpose is to increase it's size and enrol new devices.

For further information


Remediation steps

Type Step

To avoid devices becoming part of an Echobot botnet, NHS Digital recommends organisations should:

  • Review the network security of IoT devices on the estate.
  • Change any IoT device default usernames and passwords.
  • Review the list of targeted vulnerabilities and apply the relevant vendor patches where appropriate.

Last edited: 14 February 2020 2:47 pm