Skip to main content

New ‘BrickerBot’ malware attack kills unsecured Internet of Things devices

microsoft security intelligence report 2016 online piracy
Mopic / Shutterstock
The Internet of Things (IoT) is at the heart of many modern technology devices, not the least of which are the increasingly popular smart home components that unlock our doors and control our heating and lighting. The security of IoT devices is, therefore, paramount if these increasingly ubiquitous devices are going to bring more benefit than cost.

Unfortunately, IoT has been the source of significant malware attacks in recent months, including the distributed denial of service (DDoS) attack that took down a large swatch of the internet in October 2016. Now, a new piece of malware, dubbed BrickerBot, is in the wild and targeting IoT device running the open-source Linux operating system, as Readwrite reports.

According to security firm Radware, whose honeypot was used to discover the malware, BrickerBot works in similar fashion to Mirai in that both programs attempt to leverage the tendency for users to neglect to change the factory default username and password combo that ships on IoT devices. The primary difference between the two is that while Mirai aims to take over and add them to botnets with the express purpose of conducting DDoS attacks, BrickerBot — as its name implies — simply wants to kill the devices instead. This kind of attack is called Permanent Denial of Service (PDoS), and it’s apparently becoming increasingly popular.

Because they both rely on remote access into unsecured devices, both BrickerBot and Mirai can most easily be combatted by simply changing the default username and password and by turning off Telnet remote access wherever possible. Radware notes a few other highly technical responses to BrickerBot that technology staff can use but that are likely beyond the means of the typical smart home customer.

While Mirai is of greater concern on a widespread basis given its ability impact the entire internet, BrickerBot can cause some serious inconvenience to casual users by leaving their devices dead and unusable. Of even greater concern, however, is the potential impact on commercial concerns, where losing hundreds of IoT devices that are used for critical infrastructure could be crippling. For those organizations, taking Radware’s more technical advice into consideration would be highly recommended.

Editors' Recommendations

Mark Coppock
Mark has been a geek since MS-DOS gave way to Windows and the PalmPilot was a thing. He’s translated his love for…
How to do hanging indent on Google Docs
Google Docs in Firefox on a MacBook.

The hanging indent is a classic staple of word processing software. One such platform is Google Docs, which is completely free to start using. Google Docs is packed with all kinds of features and settings, to the point where some of its more basic capabilities are overlooked. Sure, there are plenty of interface elements you may never use, but something as useful as the hanging indent option should receive some kind of limelight.

Read more
How to disable VBS in Windows 11 to improve gaming
Highlighting VBS is disabled in Windows 11.

Windows 11's Virtualization Based Security features have been shown to have some impact on gaming performance — even if it isn't drastic. While you will be putting your system more at risk, if you're looking to min-max your gaming PC's performance, you can always disable it. Just follow the steps below to disable VBS in a few quick clicks.

Plus, later in this guide, we discuss if disabling VBS is really worth it, what you'd be losing if you choose to disable it, and other options for boosting your PCs gaming performance that don't necessarily involve messing with VBS.

Read more
How to do a hanging indent in Microsoft Word
A person typing on a keyboard, connected to a Pixel Tablet.

Microsoft Word is one of the most feature-rich word processing tools gifted to us human beings. In fact, the very word “Word” has invaded nomenclature to the point where any discussion of this type of software, regardless of what the product is actually called, typically results in at least one person calling the software “Word.”

Read more