A new botnet is spreading around the world, targeting vulnerable IoT devices, mainly IP cameras. Its name is HNS (Hide N' Seek) and it was discovered by Bitdefender security researchers and has been active since January 10. 
Unlike all the Internet of Things (IoT) botnets that have appeared in recent weeks, HNS is not a new modification of the Mirai Bot source code. According to Bogdan Botezatu, a security analyst at Bitdefender, the HNS botnet is more similar to Hajime than to Mirai. However, if in the case of Hajime, the P2P functionality was based on the BitTorrent protocol, here we have a customized P2P communication mechanism. Each bot contains a list of IPs of other infected bots, which can be updated in real time on the status of the entire Botnet. They are able to perform functions similar to those of the P2P protocol. An HNS bot can receive and execute various types of commands, such as deleting or transferring data, executing code, and interfering with the operation of a device.
The DDoS attack is absent from this and its spread is done via brute-force attacks on devices with open Telnet ports. Like the P2P Bot management protocol, this spreading mechanism it uses is also very careful. The good news is that HNS cannot remain permanently on infected devices, which means that the malware is automatically removed with each device reboot.
Given that many of these new botnets disappear after a few weeks, let's hope that the HNS developer gets bored and abandons his "experiment.".
