April 27, 2017 By Larry Loeb 2 min read

Sierra Tel (ST) won’t forget April 10. On that date this year, the California-based telecommunications company may have been taken down by two warring families of botnets that attacked an Internet of Things (IoT) device in its network.

An IoT Device With a Checkered History

When its customers in Mariposa and Oakhurst, California, started to complain that they had lost all connectivity, the company determined that all these customers were using the same modem, the ZyXel HN51.

While ST diagnosed the cause of the problem rather quickly, Bleeping Computer reported that it took until April 22 for all the affected customers to obtain replacement devices. Frustrated customers quickly exhausted available supplies of the modem when the company offered them an opportunity to swap out old devices at its offices.

The ZyXel HN51 has a checkered history. This is the same modem that caused Deutsche Telekom to go offline for nearly a full day last year, according to Bleeping Computer. It took the German ISP about that long to regain control over its devices through a firmware update. A week later, some British ISPs experienced the same problem. At the time, the Mirai IoT botnet was thought to be the culprit.

The ZyXel modem uses the TR-069 control interface as a way for system administrators to assert hardware-level control on modems in a network. But that interface can be exploited, according to SANS, requiring strict filtering at the network or modem interface to prevent the exploits from occurring.

Vigilante Justice

It’s possible that a vigilante IoT construct could have caused this failure while trying to neutralize rogue IoT devices. One such construct, BrickerBot, is said to be able to wipe any onboard memory in a device and rewrite it with random garbage, Bleeping Computer reported. That would require device replacement, which is just what ST was forced to do.

A clear solution is nowhere in sight. Other unknown threat actors may be at work here as well, and this particular modem has proven to be exploitable. But a system operator such as ST must be aware of the actions that need to be implemented by a network to avoid bricked devices. No matter how or why they get bricked, they’ll almost always come with irate customers attached.

More from

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today