The three million toothbrush botnet story isn’t true.

Here’s the original source of the story: https://archive.is/2024.01.30-203406/https://www.luzernerzeitung.ch/wirtschaft/kriminalitaet-die-zahnbuersten-greifen-an-das-sind-die-aktuellen-cybergefahren-und-so-koennen-sie-sich-schuetzen-ld.2569480

It’s simply a made up example. It doesn’t exist. It starts talking about NoName Ddosia, too, which also isn’t toothbrushes.

The toothbrush thing has gone viral despite it being total bollocks.

Now NoName have picked up the fake toothbrush story as propaganda for their members.

Good job, Fortigate.

Fortigate haven’t replied to my PR question about it. Given this is several times the size of the world’s biggest botnet, you’d think they’d have any evidence.. at all.

Kudos to @BleepingComputer for doing actual journalism.

Fortinet also declined to comment to me.

It's a completely made up story, which is now being circulated as Russian propaganda.
https://www.bleepingcomputer.com/news/security/the-unlikely-3-million-electric-toothbrush-ddos-attack/

The unlikely 3 million electric toothbrush DDoS attack

A widely reported story that 3 million electric toothbrushes were hacked with malware to conduct distributed denial of service (DDoS) attacks is likely a hypothetical scenario instead of an actual attack.

BleepingComputer
Fortigate have issued me a statement. The toothbrush DDoS story is completely made up.
I’d like to thank all the Mastodon reply guys in the thread who decided the story was real, btw, based on vibes.
Probably the best reply on one of the stories so far.
It’s now made it to YouTubers 🤣 who are doing better journalism and threat intel than.. journalists and threat intel. https://youtu.be/sVpe0ZEZ1Ho
Did a Massive Toothbrush DDOS Just Happen?

YouTube

The newspaper that had the first article about the Fortigate toothbrush botnet have updated the story and doubled down:

“The article originally said that the case "really happened like that."
This information came from the company Fortinet, which had described the case as real in the interview and proofread the article before publication. Fortinet is now correcting this statement and calling it a "hypothetical scenario". https://www.luzernerzeitung.ch/wirtschaft/kriminalitaet-die-zahnbuersten-greifen-an-das-sind-die-aktuellen-cybergefahren-und-so-koennen-sie-sich-schuetzen-ld.2569480

Cybergefahren: So schützen Sie sich

Die Zahl der Angriffe erreicht unvorstellbare Höhen, wie neue Daten der Cybersicherheitsfirma Fortinet zeigen. Welche Entwicklungen Sorgen bereiten und warum es trotzdem Anlass zur Zuversicht gibt.

Luzerner Zeitung
Zahnbürsten-Cyberangriff: Hintergründe zu einer ungewöhnlichen Geschichte

Ein Artikel in dieser Zeitung über elektrische Zahnbürsten, die in einen Cyberangriff verwickelt gewesen sein sollen, ist viral gegangen. In Expertenkreisen löste er Skepsis aus. Die Hintergründe.

Luzerner Zeitung

During the whole toothbrush botnet thing, people said ‘yes, the story is fake but it COULD happen’.

Almost every smart toothbrush uses Bluetooth so no, it could not.

Somebody pointed me towards one on Amazon which says it uses wi-fi, so I ordered it and investigated.

The toothbrush only has Bluetooth. The charger uses wi-fi - but has no open TCP or UDP ports. Traffic is outbound only, TLS 1.3.

So no, it was just total nonsense.

@GossiTheDog What does the charger do with WiFi?
@GossiTheDog Switch the toothbrushes to Tuya devices and then maybe we can have one million smart bulbs dos something
@GossiTheDog @SwiftOnSecurity but IT COULD HAPPEN as soon as someone makes a toothbrush with a 2lbs battery in it! It COULD!
@GossiTheDog, why are you letting facts get in the way of a good story?
atc1441 (@atc1441) on X

WIFI Toothbrush completely OTA under full control, no need of pressing buttons🥳 "Exploit" ESP32 Opens WIFI Network: evowera 12345678 (default set in Toothbrush🤪) and answers all the right requests to make the custom firmware update Demo video here🎬: https://t.co/2rPXHyO6ft

X (formerly Twitter)

@GossiTheDog

I wonder where the toothbrush gets the time and date from, to validate the TLS certificate chain.

...and how it alerts the user to an invalid server TLS 1.3 certificate.

BTW, how does TCP work with outbound traffic only? UDP maybe but TCP?

Without inbound traffic, it surely has to have an Ethernet cable connection or a WPS button.
Given that you can't tell it about the Wireless network to use.

Questions upon questions. Even without asking the obvious question of...why?

@GossiTheDog could there be a ddos botnet that incorporated something that talked to toothbrushes? Sure, but the toothbrushes themselves would just be an amusing side note to a pathetically tiny botnet.

@GossiTheDog

Supply chain toothbrush charger attack

Boom. Gottem

@GossiTheDog I have my toothbrush set to flight mode...

@GossiTheDog Still a reasonable chance it accepts any cert or is vulnerable to downgrade attacks or something.

Remember, the S in IOT stands for security.

@GossiTheDog

Now, why does a toothbrush **charger** connect to anything?

@GossiTheDog The whole (bogus) story about a toothbrush botnet made me think. What exactly could "smart" enablement add to a toothbrush that would justify the development cost and the e-waste? What's next? Smart toilet paper? As you wipe your bum, it gives you directions and congratulates you at the end for doing a good job?

But hey. I probably got to that age where I just go "back in my day...", as younger folks roll their eyes

@GossiTheDog a.k.a. Kevin explores how far he can push the training expenses on his next tax returns.
@GossiTheDog @SwiftOnSecurity Just as expected. But it sure was a clockbaity “exciting” story. For people who have no understanding about technology.
@GossiTheDog So, finally, journalists were doing their job :)

@GossiTheDog This one is nice, too:

Das globale Management von Fortinet hat nun zurückgerudert mit seinem Statement, das an verschiedene internationale Medien gesendet wurde. Dieses auch an CH Media zu schicken, hat die Firma unterlassen. Auch sonst liegt uns bisher kein weiteres Statement von Fortinet vor.

"Fortinet's global management has now backtracked with its statement that was sent to various international media outlets. The company neglected to also send this to CH Media. We have not yet received any further statements from Fortinet."

@GossiTheDog also, the security press only covers fiery car crashes
@GossiTheDog While I typically dont like the German/Swiss tradition of authorizing/proofreading quotes in articles (something nobody else does as far as I know), here it clearly paid off.
@GossiTheDog Sounds like Fortinet Switzerland will soon look for someone to replace a position...
@GossiTheDog storm in a toothbrush holder
iTWire - Malwarebytes shines as bogus toothbrush attack tale swallowed by most

Security firm Malwarebytes has been one of the few companies or individuals that refused to swallow a bogus report about three million smart toothbrushes being used in a DDoS attack. A large number of so-called tech publications simply regurgitated the report which first appeared in the Swiss newspa...

@GossiTheDog

I have been literally biting all my fingers *and* my tongue (for some reason) to stop myself from going into people's posts and replying

IT'S A FAKE STORY YOU MORON. IT'S CLICKBAIT AT BEST

So far I have been strong

#Toothbrush #SmartToothbrushes

@GossiTheDog It seems appropriate that vibes are used for attribution at this point
@GossiTheDog Vibes are the best way to evaluate electric toothbrushes.
@GossiTheDog can you comment on the “$25M transferred because of deepfake” story from earlier this week? Because that just screams out as being bullshit.
@GossiTheDog so. How much ad revenue was generated by all that noise I wonder?
@GossiTheDog you just did more journalism with one email than a disturbing number of websites
@GossiTheDog “due to translations”? The original reporting in German makes that claim already. ¯\_(ツ)_/¯ https://mastodon.social/@Kensan/111888828676462440
@GossiTheDog Sounds about right. My toothbrush has been on the internet for a few months and nothing bad has happened
@GossiTheDog Thought it was odd that a brand or model was nowhere to be found
@GossiTheDog I read 2 lines of the article and my BS detector was off the charts.

@GossiTheDog

Do you mean that FortiGate…brushed off any specific occurence of this?

@GossiTheDog @BleepingComputer yeesh, declining to comment whilst their stock price spikes is some cynical shit. I'd like to hope this would damage trust in them but I'm not feeling that naive today.

@grimmware @GossiTheDog @BleepingComputer
You might think that Fortinet having had backdoors of their own (e.g. https://rhinosecuritylabs.com/enterprise-security/fortinet-backdoor-found-ssh-netscreen/), as well as critical RCE vulns, might affect the stock price too.

Possibly related: I've got a Fortigate 100D sitting here, unused in ages, if anyone wants to cover shipping etc.

Fortinet Backdoor Found in FortiGate Firewalls - Rhino Security Labs

Security researchers uncover hard coded SSH Fortinet backdoor vulnerability in FortiGate enterprise firewalls.

Rhino Security Labs
@tim_lavoie @GossiTheDog @BleepingComputer strangely enough you're not really selling the Fortigate ;)
@GossiTheDog @BleepingComputer I’m still trying to figure out what the problem was with toothbrushes that needed fixing with an internet connection.
@GossiTheDog @BleepingComputer I am glad that I was skeptical enough when I saw the story come through yesterday and didn't amplify.... figuring the DDOS dudes would sort it out...indeed they did. I wonder how many posts from yesterday were deleted today? Lol.