Recently, security researchers at Netlab (the network security arm of Chinese tech giant “Qihoo 360”) discovered a new botnet called HEH, which contains code that can remove all data from infected systems, such as routers, servers, and IoT (Internet of Things) devices. The HEH botnet spreads through brute-force attacks carried out against any internet-connected system that has its SSH ports (23 and 2323) exposed to the internet.
If the device uses default SSH credentials or SSH credentials that are easy to guess, the botnet gains access to the target system, where it immediately downloads one of seven binaries that install the HEH malware. This malware does not have any “offensive” features, such as the ability to perform DDoS attacks, install crypto-miners, or code to run proxies.
As ZDNet reports, the only features of this malware are a feature that traps infected devices and forces them to perform SSH brute-force attacks over the internet to help bolster the botnet. This feature allows hackers to execute Shell commands on the infected device. At the same time, a variant of this second feature that executes a list of predefined Shell operations removes all data from a device.
HEH was first analyzed in a report published yesterday. Because it is a relatively new botnet, Netlab researchers cannot determine whether the device data removal feature is intentional or just a poorly coded self-destruct routine. But regardless of its purpose, if activated, it could disable hundreds or even thousands of devices.

HeH targets home routers, smart IoT devices, and Linux servers, among other things. The botnet can infect anything with weak SSH ports, even Windows. However, the HEH malware only works on *NIX platforms.
Additionally, HeH also affects a device’s firmware or operating system, potentially rendering the device inoperable until the firmware or operating system is reinstalled. Some device owners may not know how to reinstall firmware on their IoT equipment and may simply choose to throw away the old device and buy a new one.

Netlab said it has detected HEH samples that can run on the following CPU architectures: x86 (32/64), ARM (32/64), MIPS (MIPS32/MIPS-III), and PPC. The botnet is still spreading.
HEH, although it has not taken down any devices so far, would not be the first botnet to remove data from IoT devices, as two other botnets – BirckerBot and Silex.

