Hide and Seek (also referred to as Hide 'N Seek or HNS) is an IoT botnet malware family first observed in early 2018. It targets Linux-based routers and other IoT devices and uses a custom peer-to-peer control protocol rather than a conventional centralized C2 model. Reported targets include IP cameras, DVRs, NVRs, IPTV boxes, and later Android devices exposing Android Debug Bridge (ADB) over Wi-Fi.
Its propagation methods include exploitation of known vulnerabilities, Telnet scanning and brute-force login attempts, and abuse of exposed ADB services on TCP port 5555. Reported exploited products include AVTECH IP cameras/NVRs/DVRs and the Wansview NCS601W camera. Hide and Seek also attempts device-aware default credentials for at least some device types instead of only generic credential guessing. Samples were compiled for multiple architectures, including MIPS, ARM, Motorola 68020, SuperH, PowerPC, x86, and x64, with reporting also noting ten binaries for ten device architectures.
A notable characteristic is persistence: Bitdefender reported it as the first known IoT malware strain observed to survive device reboots under some conditions. It achieves persistence on Linux-based devices by copying itself into /etc/init.d/ so it is restarted automatically after reboot. This persistence is not universal; researchers stated it requires infections obtained via Telnet because root privileges are needed to place the binary in init.d.
At the time of the cited reporting, Hide and Seek was described as still evolving. Researchers reported support for remote code execution and data exfiltration, likely via a plugin or module system, but said they had not observed those functions being actively used. They also stated that the botnet did not yet include a DDoS module at that time. Bitdefender tracking cited rapid growth, with roughly 32,000 bots by the end of January 2018 and about 90,000 unique infected devices over time; the later ADB propagation vector was estimated to expose roughly 40,000 additional devices, particularly in Taiwan, Korea, and China.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Bitdefender researchers announced they found an IoT malware strain that under certain circumstances copies itself to /etc/init.d/, a folder that houses daemon scripts on Linux-based operating systems ... By placing itself in this menu, the device's OS will automatically start the malware's process after the next reboot.
Bitdefender researchers announced they found an IoT malware strain that under certain circumstances copies itself to /etc/init.d/, a folder that houses daemon scripts on Linux-based operating systems ... By placing itself in this menu, the device's OS will automatically start the malware's process after the next reboot.
experts have found new HNS versions that have added support not only for two other exploits but also for brute-force operations. What this means is that HNS infected devices will scan for other devices that have an exposed Telnet port and attempt to log into that device using a list of preset credentials.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an IoT botnet with persistence features; the article notes Torii shares some features with it but they are separate malware families.
A peer-to-peer IoT botnet focused on expanding its size by infecting diverse device types including IP cameras, DVRs, NVRs, IPTV boxes, routers, and Android devices via exposed ADB, telnet brute-forcing, and camera vulnerabilities. It supports data exfiltration and code execution and added persistence to survive reboots on infected routers.
IoT botnet noted for achieving persistence across device reboots before VPNFilter was analyzed.
IoT botnet malware that can achieve reboot persistence on some infected Linux-based routers and IoT devices by copying itself to /etc/init.d/ when infection occurs via Telnet with root privileges. It uses a custom P2P protocol, supports multiple exploits and brute-force attacks against exposed Telnet services, can steal data, execute code, and supports a plugin/module system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.