Wednesday, May 7, 2025
HomeSecurity News“Hide 'N Seek” the First IoT Botnet with the Ability to Survive...

“Hide ‘N Seek” the First IoT Botnet with the Ability to Survive Device Reboots

Published on

SIEM as a Service

Follow Us on Google News

A new version of Hide and Seek botnet detected by Bitdefender researchers with plenty of improvements on the propagation side. The botnet has a history of infection close to 90,000  unique devices from the device it was detected.

The new version of the botnet is the world’s first one to communicate through custom-built peer to peer protocol and the first bot with the ability to survive a reboot.

With the new version, it includes additional binaries to leverage new vulnerabilities to
compromise more IPTV camera models, in addition to that, it also detects two new devices and their default credentials.

- Advertisement - Google News

Bitdefender researchers discovered the new version of Hide and Seek botnet targets generic devices and scans for the telnet service. If the service is found then it attempts a brute force.

If the login Succeeds it locks down the access of port 23 to prevent the device being it hijacked by competing botnet.

It attacks a wide range of devices and architectures, researchers said “the bot has 10
different binaries compiled for various platforms including x86, x64, ARM (Little Endian and Big Endian), SuperH, PPC and so on”.

Also Read HNS IoT Botnet Compromised More than 14k Devices that Spreads from Asia to the United States

In order to achieve its persistence, the malware copies itself into /etc/init.d/ and adds itself to start with the operating system. Also, it opens a random UDP port which allows attackers to establish communication with the device.

According to researchers the botnet still has no support for the DDoS attack, according to their analysis “the botnet is in the growth phase and attackers trying to seize as many devices as possible”. Attackers can expand the function of the botnet at any time.

As with any new technology, IoT promises to be the future of the Internet, bringing better connectivity and ease of use of the devices we use, but these botnet attacks show, an equal amount of stress must be placed on security.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...

Healthcare Sector Becomes a Major Target for Cyber Attacks in 2025

The healthcare sector has emerged as a prime target for cyber attackers, driven by...

SysAid ITSM Vulnerabilities Enables Pre-Auth Remote Command Execution

Security researchers have disclosed a chain of critical vulnerabilities affecting SysAid ITSM’s On-Premise solution,...

CISA Warns of Cyber Threats to Oil and Gas SCADA and ICS Networks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a new alert warning critical...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...