• About
  • Advertise
  • Contact
Sunday, December 14, 2025
No Result
View All Result
NEWSLETTER
iotwashington
  • Home
  • Internet of Things
  • Security
  • WAN
  • Cloud Computing
  • Data Centers
  • Mobile
  • Networking
  • Software
  • Home
  • Internet of Things
  • Security
  • WAN
  • Cloud Computing
  • Data Centers
  • Mobile
  • Networking
  • Software
No Result
View All Result
iotwashington
No Result
View All Result
Home Security

IoT malware behind record DDoS attack is now available to all hackers

in Security
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter

The source code for a trojan program that infected hundreds of thousands of internet-of-things devices and used them to launch distributed denial-of-service attacks has been published online, paving the way for more such botnets.

The code for the trojan, which its creator calls Mirai, was released Friday on an English-language hackers’ forum, cybersecurity blogger Brian Krebs reported over the weekend. Krebs’ website was the target of a record DDoS attack two weeks ago that was launched from the Mirai botnet.

The trojan’s creator, who uses the online handle Anna-senpai, said that the decision to release the source code was taken because there’s a lot of attention now on IoT-powered DDoS attacks and he wants to get out of this business.

Mirai used to enslave around 380,000 IoT devices every day using brute-force Telnet attacks, according to Anna-senpai. However, after the DDoS attack against krebsonsecurity.com, ISPs have started to take action and block compromised devices, so the daily rate of Mirai infections has dropped to 300,000 and is likely to go down even further, the malware writer said.

It’s worth noting that unlike malware infections on desktop computers, infections on IoT and embedded devices are usually temporary and disappear when those devices are rebooted because they use volatile storage. In order to maintain their size, IoT botnets need to find and reinfect devices every single day.

The hijacking of home routers, DSL modems, digital video recorders, network-attached storage systems and other such devices to launch DDoS attacks is not new. For example, in October 2015, security firm Incapsula mitigated a DDoS attack launched from around 900 closed-circuit television (CCTV) cameras.

However, the IoT DDoS botnets seem to have reached their full potential over the past few months. After the unprecedented 620Gbps DDoS attack against Krebs’ website two weeks ago, French server hosting firm OVH was hit with a 799Gbps DDoS attack launched from a botnet of over 140,000 hacked digital video recorders and IP cameras.

Such a large botnet is capable of launching crippling attacks that could easily exceed 1Tbps, the OVH’s CTO warned at the time.

There are very few DDoS mitigation providers in the world who are capable of protecting customers against 1Tbps attacks. Content delivery network Akamai, which also offers DDoS protection services, dropped Krebs as a customer when his website was recently attacked because the attack was too costly to mitigate.

And things are only going to get worse because the market of IoT devices is rapidly expanding and many of these devices come with basic security holes, such as remote administrative interfaces exposed to the Internet and protected with weak credentials that users never change.

The release of Mirai’s source code is very likely to lead to the creation of more IoT botnets, and it wouldn’t be the first time. In early 2015 the source code for LizardStresser, a DDoS bot for Linux systems written by the infamous Lizard Squad attacker group, was released online. As of June this year, security researchers had identified over 100 botnets built using malware based on LizardStresser.

Join the Network World communities on Facebook and LinkedIn to comment on topics that are top of mind.
Premium WordPress Themes Download
Free Download WordPress Themes
Download WordPress Themes Free
Premium WordPress Themes Download
free download udemy paid course
download redmi firmware
Download Nulled WordPress Themes
ZG93bmxvYWQgbHluZGEgY291cnNlIGZyZWU=
Tags: IoT malware behind record DDoS attack is now available to all hackers
Next Post

Building a Raspberry Pi-powered Barkometer, Part 4

Recommended

Amazon investing $2 billion more in India as online retail booms

Samsung Developer Conference: Wearables, virtual reality, and the smart home

Facebook Twitter Youtube RSS

Newsletter

Subscribe our Newsletter for latest updates.

Loading

Category

  • AI
  • Careers
  • Cloud Computing
  • Connected Cars
  • Connected Vehicles
  • Data & Analytics
  • Data Center
  • Data Centers
  • Databases
  • Development
  • Enterprise
  • Hardware
  • Healthcare
  • IIoT
  • Infrastructure
  • Internet of Things
  • IoT
  • IT Leadership
  • Manufacturing
  • Mobile
  • Networking
  • Oil & Gas
  • Open Source
  • Security
  • Smart Cities
  • Smart Homes
  • Software
  • Software Development
  • Standards
  • Technology Industry
  • Uncategorized
  • Unified Communications
  • Virtualization
  • WAN
  • Wearables

About Us

Advance IOT information site of Washington USA

© 2024 iotwashington.com.

No Result
View All Result
  • Home
  • Internet of Things
  • Security
  • WAN
  • IoT
  • Cloud Computing
  • Data Centers
  • Mobile
  • Networking
  • Software

© 2024 iotwashington.com.

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In