Menu
IoT malware behind record DDoS attack is now available to all hackers

IoT malware behind record DDoS attack is now available to all hackers

The Mirai trojan enslaved over 380,000 IoT devices, its creator claims

The source code for a trojan program that infected hundreds of thousands of internet-of-things devices and used them to launch distributed denial-of-service attacks has been published online, paving the way for more such botnets.

The code for the trojan, which its creator calls Mirai, was released Friday on an English-language hackers' forum, cybersecurity blogger Brian Krebs reported over the weekend. Krebs' website was the target of a record DDoS attack two weeks ago that was launched from the Mirai botnet.

The trojan's creator, who uses the online handle Anna-senpai, said that the decision to release the source code was taken because there's a lot of attention now on IoT-powered DDoS attacks and he wants to get out of this business.

Mirai used to enslave around 380,000 IoT devices every day using brute-force Telnet attacks, according to Anna-senpai. However, after the DDoS attack against krebsonsecurity.com, ISPs have started to take action and block compromised devices, so the daily rate of Mirai infections has dropped to 300,000 and is likely to go down even further, the malware writer said.

It's worth noting that unlike malware infections on desktop computers, infections on IoT and embedded devices are usually temporary and disappear when those devices are rebooted because they use volatile storage. In order to maintain their size, IoT botnets need to find and reinfect devices every single day.

The hijacking of home routers, DSL modems, digital video recorders, network-attached storage systems and other such devices to launch DDoS attacks is not new. For example, in October 2015, security firm Incapsula mitigated a DDoS attack launched from around 900 closed-circuit television (CCTV) cameras.

However, the IoT DDoS botnets seem to have reached their full potential over the past few months. After the unprecedented 620Gbps DDoS attack against Krebs' website two weeks ago, French server hosting firm OVH was hit with a 799Gbps DDoS attack launched from a botnet of over 140,000 hacked digital video recorders and IP cameras.

Such a large botnet is capable of launching crippling attacks that could easily exceed 1Tbps, the OVH's CTO warned at the time.

There are very few DDoS mitigation providers in the world who are capable of protecting customers against 1Tbps attacks. Content delivery network Akamai, which also offers DDoS protection services, dropped Krebs as a customer when his website was recently attacked because the attack was too costly to mitigate.

And things are only going to get worse because the market of IoT devices is rapidly expanding and many of these devices come with basic security holes, such as remote administrative interfaces exposed to the Internet and protected with weak credentials that users never change.

The release of Mirai's source code is very likely to lead to the creation of more IoT botnets, and it wouldn't be the first time. In early 2015 the source code for LizardStresser, a DDoS bot for Linux systems written by the infamous Lizard Squad attacker group, was released online. As of June this year, security researchers had identified over 100 botnets built using malware based on LizardStresser.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags hackersddosIoT

Featured

Slideshows

Reseller News launches inaugural Hall of Fame lunch

Reseller News launches inaugural Hall of Fame lunch

Reseller News welcomed 2015 and 2016 inductees - Darryl Swann, Dave Rosenberg, Gary Bigwood, Keith Watson, Mike Hill and Scott Green - to the inaugural Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed how the channel can collectively work together to benefit New Zealand, the Kiwi skills shortage and the future of the industry. Photos by Maria Stefina.

Reseller News launches inaugural Hall of Fame lunch
Educating from the epicentre - Why distributors are the pulse checkers of the channel

Educating from the epicentre - Why distributors are the pulse checkers of the channel

​As the channel changes and industry voices deepen, the need for clarity and insight heightens. Market misconceptions talk of an “under pressure” distribution space, with competitors in that fateful “race for relevance” across New Zealand. Amidst the cliched assumptions however, distribution is once again showing its strength, as a force to be listened to, rather than questioned. Traditionally, the role was born out of a need for vendors and resellers to find one another, acting as a bridge between the testing lab and the marketplace. Yet despite new technologies and business approaches shaking the channel to its very core, distributors remain tied to the epicentre - providing the voice of reason amidst a seismic industry shift. In looking across both sides of the vendor and partner fences, the middle concept of the three-tier chain remains centrally placed to understand the metrics of two differing worlds, as the continual pulse checkers of the local channel. This exclusive Reseller News Roundtable, in association with Dicker Data and rhipe, examined the pivotal role of distribution in understanding the health of the channel, educating from the epicentre as the market transforms at a rapid rate.

Educating from the epicentre - Why distributors are the pulse checkers of the channel
Kiwi channel reunites as After Hours kicks off 2017

Kiwi channel reunites as After Hours kicks off 2017

After Hours made a welcome return to the channel social calendar last night, with a bumper crowd of distributors, vendors and resellers descending on The Jefferson in Auckland to kickstart 2017. Photos by Maria Stefina.

Kiwi channel reunites as After Hours kicks off 2017
Show Comments