https://www.engineeringnews.co.za

A new botnet is lurking as Hajime has 300,000 devices waiting orders

29th May 2017

     

Font size: - +

This article has been supplied.

Westcon-Comstor  (0.03 MB)

If you thought the IoT botnet Mirai was bad, Westcon-Comstor warns of Hajime, which currently has 300,000 obeying devices which is currently conquering the Internet of Things world.
 
Hajime is, according to Westcon-Comstor vendor partner Kaspersky “a mysterious evolving Internet of Things (IoT) malware that builds a huge peer-to-peer botnet”. Notably the botnet has of late been propagating extensively and infecting multiple devices worldwide, reports reveal that there are almost 300,000 malware-compromised devices. 
 
“If the Mirai attack is still fresh in your minds, the fact that there are 300,000 malware-compromised devices, all ready to work as one to act under the instructions of their master without our knowledge, is a terrifying thought,” states Andrew Potgieter, Director Security Solutions at Westcon-Comstor Southern Africa. “While Hajime’s purpose is still unknown, it surely can’t be for the good of the world if it has been slowly growing in scale since it was first detected in October 2016.”
 
Not dissimilar to Mirai, Hajime is once again building a huge peer-to-peer botnet – a decentralised group of compromised machines discreetly performing spam or DDoS attacks. While Kaspersky Labs cites that there is no actual attacking code or capability they can see in Hajime and it is still only has a propagation module, the family of tools are different. Particularly in that they make use of different techniques – mainly brute-force attacks on device passwords – to infect devices, and then takes a number of steps to conceal itself from the compromised victim. 
 
“The devices currently targeted by Hajime to date are reportedly Digital Video Recorders, followed by web-cameras and routers. But that said this particular threat doesn’t attack a specific device and will snoop out any device connected to the Internet. The name Hajime, means ‘beginning’ in Japanese, it is important we are forewarned so that this is not the beginning of another large scale cyber-attack that takes the world’s Internet down for a day,” adds Potgieter. 
 
According to Kaspersky Lab researchers the infections they have noted to date have primarily come from Vietnam (over 20%), Taiwan (almost 13%) and Brazil (around 9%) at the time of their research and most of the compromised devices are located in Iran, Vietnam and Brazil.
 
“In order to get ahead of Hajime the basic principles apply and we urge all customers to change the passwords on all IoT and Internet-enabled devices. More importantly as Hajime uses brute force, passwords need to be clever and difficult to crack. Additionally, users must update their firmware on devices, if this is an option. Such simple tactics can stop an attack in its tracks.
 
“While we sit in wait to see what the purpose of Hajime is, it is better to be forewarned and forearmed,” ends Potgieter.

Edited by Creamer Media Reporter

Article Enquiry

Email Article

Save Article

Feedback

To advertise email advertising@creamermedia.co.za or click here

Showroom

The Steel Tube Export Association of South Africa
Steel Tube Export Association of South Africa

The Steel Tube Export Association of South Africa was established to develop sustainable, internationally competitive carbon steel tube and pipe...

VISIT SHOWROOM 
Rentech
Rentech

Rentech provides renewable energy products and services to the local and selected African markets. Supplying inverters, lithium and lead-acid...

VISIT SHOWROOM 

Latest Multimedia

sponsored by

Option 1 (equivalent of R125 a month):

Receive a weekly copy of Creamer Media's Engineering News & Mining Weekly magazine
(print copy for those in South Africa and e-magazine for those outside of South Africa)
Receive daily email newsletters
Access to full search results
Access archive of magazine back copies
Access to Projects in Progress
Access to ONE Research Report of your choice in PDF format

Option 2 (equivalent of R375 a month):

All benefits from Option 1
PLUS
Access to Creamer Media's Research Channel Africa for ALL Research Reports, in PDF format, on various industrial and mining sectors including Electricity; Water; Energy Transition; Hydrogen; Roads, Rail and Ports; Coal; Gold; Platinum; Battery Metals; etc.

Already a subscriber?

Forgotten your password?

MAGAZINE & ONLINE

SUBSCRIBE

RESEARCH CHANNEL AFRICA

SUBSCRIBE

CORPORATE PACKAGES

CLICK FOR A QUOTATION







301

sq:0.057 1.2s - 143pq - 2rq
Subscribe Now