Hacker News new | ask | show | jobs
by nubinetwork 167 days ago
Based on the article, try looking for android devices with adb running on the network.
2 comments

This article[0] includes a link to a online checker: https://synthient.com/check

Have not tested it myself ymmv.

[0] https://synthient.com/blog/a-broken-system-fueling-botnets

It only references a database of publicly scanned IPs, it won't help you if the device is behind a nat router.
Does someone know if the port must be 5555 for this botnet?
It's the Android debugger port, and it's used for infection, but the article doesn't exclude other methods nor mentions ports used by the malware.