BrickerBot threatens to kill your IoT devices

Mirai-like botnet could permanently disable Internet of Things hardware

A new type of malware has been discovered that could permanently render IoT devices useless.

Dubbed BrickerBot, the malware was discovered by IT security firm Radware. Its Emergency Response Team (ERT) said it was designed to stop a victim's hardware from functioning.

It called this new type of attack a Permanent Denial-of-Service (PDoS), and said itis becoming increasingly popular in 2017 as more incidents evolving this hardware-damaging assault occur.

The type of attack is also known as "plashing"; damaging a system so badly that it requires replacement or reinstallation of hardware.

Advertisement - Article continues below
Advertisement - Article continues below

"By exploiting security flaws or misconfigurations, PDoS can destroy the firmware and/or basic functions of [a] system. It is a contrast to its well-known cousin, the DDoS attack, which overloads systems with requests meant to saturate resources through unintended usage," said Pascal Geenens, cyber security evangelistat Radware, who discovered the malware.

In just one four-day period, a honeypot set up by the company recorded 1,895 PDoS attempts performed from several locations around the world. The firm said the malware's sole purpose was to target IoT devices and corrupt their storage.

The malware used Telnet brute force - the same exploit vector used by Mirai - to breach a victim's devices, according to the researchers. Bricker does not try to download a binary, so no complete list of credentials that were used for the brute force attempt has been recorded. However, Radware was able to record that the first attempted username/password pair was consistently 'root'/'vizxv.

"Upon successful access to the device," said Geenens, "the PDoS bot performed a series of Linux commands that would ultimately lead to corrupted storage, followed by commands to disrupt internet connectivity, device performance, and the wiping of all files on the device."

When a device is successfully accessed, the malware carries out a series of Linux commands that would ultimately lead to corrupted storage, followed by commands to disrupt internet connectivity, device performance, and the wiping of all files on the device.

"Among the special devices targeted are /dev/mtd (Memory Technology Device - a special device type to match flash characteristics) and /dev/mmc (MultiMediaCard - a special device type that matches memory card standard, a solid-state storage medium)," he said.

Advertisement - Article continues below

"The sysctl commands attempt to reconfigure kernel parameters: net.ipv4.tcp_timestamps=0 disables TCP timestamps, which does not affect local LAN IPv4 connectivity, but seriously impacts the internet communication, and kernel.threads-max=1 limits the max number of kernel threads to one."

Organisations can protect IoT devices and networks by changing the device's factory default credentials and disabling Telnet access to the device, Radware explained.

Featured Resources

Digital Risk Report 2020

A global view into the impact of digital transformation on risk and security management

Download now

6 ways your business could suffer if you don’t backup Office 365

Office 365 makes it easy to lose valuable data regularly, unpredictably, unintentionally, and for good

Download now

Get the best out of your workforce

7 steps to unleashing their true potential with robotic process automation

Download now

8 digital best practices for IT professionals

Don't leave anything to chance when going digital

Download now


internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular


How to use Chromecast without Wi-Fi

5 Feb 2020
data protection

Google to shift UK user data to the US post-Brexit

20 Feb 2020
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020
cyber security

McAfee researchers trick Tesla autopilot with a strip of tape

21 Feb 2020