Researchers reported that the Hide ‘N Seek malware evolved into a multi-stage IoT botnet that compromises internet-exposed devices through known exploits and brute-forced default credentials, then links them through a custom peer-to-peer UDP network instead of relying on centralized command-and-control. Analysis tied parts of its scanner module to Mirai code reuse, while the botnet’s protocol supported peer discovery, file distribution, and exfiltration from infected systems. Early tracking showed a network of roughly 1,000 peers with rapid daily growth, and later variants added stronger persistence and broader targeting across routers, Android devices exposed through ADB, and misconfigured services including MongoDB and CouchDB.
Subsequent samples showed the botnet continuing active development and widening its exploitation arsenal. Researchers said a 2019 variant added remote code execution attacks for ThinkPHP via CVE-2018-20062 and Sonatype Nexus Repository Manager via CVE-2019-7238, with evidence that Hide ‘N Seek exploited the Nexus flaw in the wild before other botnets publicly did. The malware also retained earlier capabilities such as hard-coded P2P peers, XOR-obfuscated strings, multi-architecture Linux binaries, and delivery of a Monero miner, although observed mining revenue appeared limited and the operators’ broader objectives remained unclear.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
A new Hide 'N Seek variant was first seen on 2019-02-21. It added exploitation for ThinkPHP CVE-2018-20062 and Nexus Repository Manager CVE-2019-7238 while retaining earlier exploit and peer-to-peer capabilities.
Unit 42 reported that Hide 'N Seek exploited CVE-2019-7238 in February 2019. The activity predated previously noted public exploitation of the same flaw by the DDG botnet in May 2019.
As of 2018-10-31, researchers observed that the botnet's Monero-mining operation had earned almost 0.9 XMR, worth roughly $90 at the time. The miner was based on coinminer-opt and used the moriaxmr.com pool.
In May 2018, researchers said Hide 'N Seek became the first known IoT malware capable of surviving device reboots. This marked a notable persistence milestone in the botnet's evolution beyond earlier IoT-focused infections.
In April 2018, Fortinet researcher J. Manuel reported signs that Hide 'N Seek reused code from the leaked Mirai source, particularly in its scanner module. This linked the botnet's propagation logic to earlier Mirai-derived malware.
By 2018, newer Hide 'N Seek samples had added persistence by copying themselves into init directories and expanded exploit coverage beyond TP-Link and Netgear to targets including Cisco, Belkin, AVTECH, HomeMatic, MongoDB, and CouchDB. This showed the botnet was evolving its post-infection durability and infection surface.
Bitdefender reported the Hide 'N Seek IoT botnet in late January 2018, marking its initial discovery in the wild. The botnet was notable for using a custom peer-to-peer communication model and infecting internet-exposed IoT devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
labs.bitdefender.com
Open sourcelabs.bitdefender.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.avast.com
Open sourceblog.netlab.360.com
Open sourcebleepingcomputer.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.