Sieren Botnet
Sieren is a botnet that can perform distributed denial-of-service (DDoS) attacks by sending floods of HTTP, HTTPS and UDP packets to specified web servers.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Sieren is a botnet that can perform distributed denial-of-service (DDoS) attacks by sending floods of HTTP, HTTPS and UDP packets to specified web servers.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is not known how Sieren initially infects new host devices. When Sieren is executed it sends the following system information to its command and control (C2) server:
- Username
- Machine name
- Operating system version
- Processor architecture
The C2 server responds with a target URL for the DDoS attack. Once the target URL is received, Sieren chooses the most relevant attack method and carries out the attack. Sieren stops the attack when the C2 server stops sending additional commands.
Sieren can also instruct infected hosts to install additional malware, update Sieren or uninstall Sieren.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 17 February 2020 1:00 pm