August 1, 2017 By Larry Loeb 2 min read

The creator of the BrickerBot malware claimed credit for a cyberattack that caused over 60,000 internet outages in India from July 25 to July 29, 2017, Bleeping Computer reported.

The two companies affected were Bharat Sanchar Nigam Limited (BSNL) and Mahanagar Telephone Nigam Limited (MTNL), which are both state-owned telecommunications service providers. The malware also affected routers that were part of BSNL’s National Internet Backbone (NIB). Fortunately, these NIB routers were brought back up quickly, but thousands of users were without internet connectivity for an extended period of time.

Reset Modems Still Vulnerable to Attack

According to Bleeping Computer, BSNL said that the malware affected modems that had their default passwords enabled, and advised users to change them. But one local newspaper, The Hindu, reported that the reset modems were still vulnerable to the malware, even with new passwords.

The previously seen BrickerBot malware infects Linux-based Internet of Things (IoT) and networking devices. It does not turn devices into botnets for distributed denial-of-service (DDoS) attacks but bricks the equipment by directly rewriting its flash storage. Sometimes this is reversible, sometimes it is not.

BrickerBot Author Emerges

Over the weekend, the BrickerBot author told Bleeping Computer in an email that he was the author of the malware. Further, he blamed the cause of the attack on BSNL and MTNL, and claimed that he developed and spread the malware to make internet service providers (ISPs) aware that unsecured devices should be safeguarded against bricking.

The author told Bleeping Computer that “BSNL’s devices are generally insecure, and BSNL isn’t being honest about the situation by blaming its customers for negligence.”

Painting himself as a cybervigilante, he also told the source, “They have hundreds of thousands of modems with unprotected TR069 (TR064) interfaces, which allow anybody to reconfigure the devices for MitM attacks or DNS hijacking. There isn’t much that an affected customer can do to prevent such attacks since the BSNL network and its devices are insecure by design.”

Filtering Port 7547 Ends Attacks

The author said that the cause of the attack was that the ISPs were allowing external connections into their network via port 7547. This is the port that is used by TR069, which is a protocol often leveraged by ISPs to send commands and manage routers at a user’s location. Such external connections could easily be misused.

Both of the affected providers limited access to port 7547 over the weekend, and the situation quieted down. While this malware seems to have been reversible, not all cases are, and users must take advantage of every security control offered to ensure they don’t become victims in the future.

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today