New Rapidly-Spreading Hide and Seek IoT Botnet Identified by Bitdefender
ID: 4bfa1101-d8fd-5a2f-bdb6-d7cce08ead11
STIX ID: report--4bfa1101-d8fd-5a2f-bdb6-d7cce08ead11
Feed Name: Security Ledger
BitDefender researchers identified a rapidly spreading IoT botnet dubbed Hide and Seek (HNS) that uses worm-like IP scanning and Telnet credential attacks to infect devices worldwide (reported ~14,000 devices). HNS implements a custom peer-to-peer architecture, ECC-based command authentication, signed remote configuration updates, and opens random UDP ports for command/control; it can exfiltrate information (potential espionage/extortion) and continuously evolves, though it does not achieve persistence (reboot clears infection).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
