TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Mirai: The IoT Bot that Took Down Krebs and Launched a Tbps Attack on OVH

2016-10-06 · Read original ↗

ATT&CK techniques detected

2 predictions
T1584.005Botnet
36%
"server consuming webserver resources. bypassing mitigation devices while analyzing mirai ’ s offered attacks, we took the perspective of how to mitigate it. according to mirai ’ s creator, the so called “ tcp stomp ” attack is a variation of the simple ack flood intended to bypas…"
T1572Protocol Tunneling
32%
"mirai : the iot bot that took down krebs and launched a tbps attack on ovh “ dns water torture ” technique this technique is different from the regular dns reflection and amplification attack as it requires significantly less queries to be sent by the bot, letting the isp ’ s rec…"

Summary

The Mirai botnet has infected hundreds of thousands of Internet of Things (IoT) devices, specifically security cameras, by using vendor default passwords for Telnet access.