Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
After logging in successfully via telnet into a ZyXEL PK5001Z modem, the third one (CVE-2016-10401) is used to escalate the user to root using ‘su’ with password ‘zyad5001’.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
"Botezatu says an HNS bot can receive and execute several types of commands, such as 'data exfiltration, code execution and interference with a device’s operation.'"
According to Netlab researchers, the botnet is now capable of infecting the following types of devices, with the following types of exploits: TPLink-Routers RCE ... Netgear RCE ... AVTECH RCE ... CISCO Linksys Router RCE ... JAW/1.0 RCE ... OrientDB RCE ... CouchDB RCE
Bitdefender researchers announced they found an IoT malware strain that under certain circumstances copies itself to /etc/init.d/, a folder that houses daemon scripts on Linux-based operating systems ... By placing itself in this menu, the device's OS will automatically start the malware's process after the next reboot.
Bitdefender researchers announced they found an IoT malware strain that under certain circumstances copies itself to /etc/init.d/, a folder that houses daemon scripts on Linux-based operating systems ... By placing itself in this menu, the device's OS will automatically start the malware's process after the next reboot.
As a side-effect for adding more payloads, HNS is also noisier now, as it needs to scan more ports to find new hosts to infect. Experts say they've seen HNS bots initiating scans on ports: 23 Telnet 80 HTTP Web Service 2480 OrientDB 5984 CouchDB 8080 HTTP Web Service ... but also random ports
The HNS communicates through the P2P mechanism... HNS node contacts to other P2P peers with the following 3 methods... From a hard-coded built-in list of 171 peer addresses From the command-line args From the other P2P peers
But HNS was easy to spot anyway because it's only the second major IoT botnet besides Hajime known to use a P2P structure
"If the victim has the same LAN as the bot, the bot sets up TFTP server to allow the victim to download the sample from the bot. If the victim is located on the internet, the bot will attempt a specific remote payload delivery method to get the victim to download and run the malware sample."
Netlab says HNS has also started dropping a coinminer payload on some of the infected systems. Fortunately, for the time being, it appears that these deployments have all failed, as the additional coinminer payload failed to start and generate funds for the HNS operators.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.