logo

New Rapidly-Spreading Hide and Seek IoT Botnet Identified by Bitdefender

ID: 4bfa1101-d8fd-5a2f-bdb6-d7cce08ead11

STIX ID: report--4bfa1101-d8fd-5a2f-bdb6-d7cce08ead11

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2018-01-24

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

BitDefender researchers identified a rapidly spreading IoT botnet dubbed Hide and Seek (HNS) that uses worm-like IP scanning and Telnet credential attacks to infect devices worldwide (reported ~14,000 devices). HNS implements a custom peer-to-peer architecture, ECC-based command authentication, signed remote configuration updates, and opens random UDP ports for command/control; it can exfiltrate information (potential espionage/extortion) and continuously evolves, though it does not achieve persistence (reboot clears infection).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.