August 1, 2017 By Larry Loeb 2 min read

The creator of the BrickerBot malware claimed credit for a cyberattack that caused over 60,000 internet outages in India from July 25 to July 29, 2017, Bleeping Computer reported.

The two companies affected were Bharat Sanchar Nigam Limited (BSNL) and Mahanagar Telephone Nigam Limited (MTNL), which are both state-owned telecommunications service providers. The malware also affected routers that were part of BSNL’s National Internet Backbone (NIB). Fortunately, these NIB routers were brought back up quickly, but thousands of users were without internet connectivity for an extended period of time.

Reset Modems Still Vulnerable to Attack

According to Bleeping Computer, BSNL said that the malware affected modems that had their default passwords enabled, and advised users to change them. But one local newspaper, The Hindu, reported that the reset modems were still vulnerable to the malware, even with new passwords.

The previously seen BrickerBot malware infects Linux-based Internet of Things (IoT) and networking devices. It does not turn devices into botnets for distributed denial-of-service (DDoS) attacks but bricks the equipment by directly rewriting its flash storage. Sometimes this is reversible, sometimes it is not.

BrickerBot Author Emerges

Over the weekend, the BrickerBot author told Bleeping Computer in an email that he was the author of the malware. Further, he blamed the cause of the attack on BSNL and MTNL, and claimed that he developed and spread the malware to make internet service providers (ISPs) aware that unsecured devices should be safeguarded against bricking.

The author told Bleeping Computer that “BSNL’s devices are generally insecure, and BSNL isn’t being honest about the situation by blaming its customers for negligence.”

Painting himself as a cybervigilante, he also told the source, “They have hundreds of thousands of modems with unprotected TR069 (TR064) interfaces, which allow anybody to reconfigure the devices for MitM attacks or DNS hijacking. There isn’t much that an affected customer can do to prevent such attacks since the BSNL network and its devices are insecure by design.”

Filtering Port 7547 Ends Attacks

The author said that the cause of the attack was that the ISPs were allowing external connections into their network via port 7547. This is the port that is used by TR069, which is a protocol often leveraged by ISPs to send commands and manage routers at a user’s location. Such external connections could easily be misused.

Both of the affected providers limited access to port 7547 over the weekend, and the situation quieted down. While this malware seems to have been reversible, not all cases are, and users must take advantage of every security control offered to ensure they don’t become victims in the future.

More from

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Communication platforms play a major role in data breach risks

4 min read - Every online activity or task brings at least some level of cybersecurity risk, but some have more risk than others. Kiteworks Sensitive Content Communications Report found that this is especially true when it comes to using communication tools.When it comes to cybersecurity, communicating means more than just talking to another person; it includes any activity where you are transferring data from one point online to another. Companies use a wide range of different types of tools to communicate, including email,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today