Summary
Silex is a newly observed worm targeting unsecured Internet-of-Things (IoT) devices.
Affected platforms
The following platforms are known to be affected:
Threat details
It's author has stated that it is based on the older Brickerbot permanent denial-of-service (PDoS) malware and that it is intended to prevent said devices being enrolled in botnets such as Mirai.
Devices are compromised using default Telnet (port 23) credentials. Once it has gained access, Silex will add iptables entries to drop all incoming or outgoing connections before writing random data to any storage partitions it discovers. It will then halt or reboot the device, resulting in a boot failure.
Remediation steps
| Type | Step |
|---|---|
|
Telnet is a known insecure protocol. Organisations should consider closing port 23 and use more secure protocols such as Secure Shell. Additionally, to prevent and detect an infection, ensure that:
|
Last edited: 11 January 2022 9:48 am