Skip to main content

Gucci Botnet

A botnet called Gucci has been discovered, which is capable of launching multiple types of distributed denial-of-service (DDoS) attacks.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A botnet called Gucci has been discovered, which is capable of launching multiple types of distributed denial-of-service (DDoS) attacks.


Threat details

At the time of publication it is unclear how Gucci binaries are being distributed.

Analysis of the distributed binaries shows that Gucci is targeting ARM, x86, MIPS, PPC, M68K and other architectures. The Gucci bot attempts to connect to a command and control via an IP address over TCP port 5555.

Analysis of the command and control server shows that the Gucci botnet is capable of conducting a variety of DDoS attacks, including UDP flood, SYN flood, ACK flood and GRE IP flood.


Remediation steps

Type Step

To help detect and prevent an infection of Gucci botnet, organisations should:

  • Review the network security of IoT devices on the estate.
  • Change any IoT device default usernames and passwords.
  • Monitor Network, proxy and firewall logs for suspicious activity.

Last edited: 14 February 2020 2:55 pm