Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you suspect an IoT device has a Linux backdoor, isolate it from the internet or other devices when doing so is safe, preserve useful evidence, and recover it only with instructions for its exact model from the manufacturer. A factory reset or deleting a suspicious process does not by itself prove the backdoor is gone. If the device supports a safety-critical or essential service, coordinate with its operator or vendor before disconnecting it.

1. Contain the device without creating a safety problem

For a noncritical camera, smart appliance, or similar endpoint, block its network access at the router or switch if possible. Network isolation can limit communication while leaving the device powered on. If you cannot isolate it that way, disconnecting it from the network may be appropriate.

Do not automatically power off a router, alarm, medical device, gateway, or controller that other systems depend on. Taking it offline can interrupt service or affect a physical process. Contact the responsible operator, manufacturer, or a qualified responder and follow the site’s incident-response procedure.

CISA describes one response in which it took a compromised system offline, isolated the application from the rest of the network, and began a forensic investigation. That is an example of containment in a particular incident, not a universal instruction for every IoT device. CISA’s CSAT Ivanti notification

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

2. Record what happened before resetting

If you can do so without delaying necessary containment, document the device and the signs of compromise before resetting or reinstalling it. A reset can remove information that would help identify how the device was accessed or whether other systems were affected.

  • Record the make, model, serial number, firmware version if available, and the time the issue was detected.
  • Describe symptoms, alerts, suspected entry points, and any unusual outbound destinations or connections.
  • Save relevant device, router, cloud-account, or security logs if available. For an organization, coordinate collection and handling with its incident-response team.

Digital forensics and incident handling are distinct parts of response for operational technology. NIST’s NISTIR 8428, Digital Forensics and Incident Response Framework for Operational Technology, is intended for that OT context.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

3. Check what the device could access

Identify the credentials, tokens, and systems the device could reach. Consider administrator logins, Wi-Fi credentials, cloud accounts, remote-access accounts, and connections to other local devices. From a trusted device, review available account and network logs for unfamiliar access, and check linked systems for suspicious activity.

NIST’s Federal Profile for IoT Device Cybersecurity Capabilities discusses monitoring local, network, and remote connections, and responding to malware detections with measures such as alerts, quarantine, or shutdown when appropriate. Its recommendation is conditional: shutting down a device may not be suitable where doing so would disrupt an essential operation. NIST Federal Profile for IoT Device Cybersecurity Capabilities

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

4. Restore the device using its manufacturer’s procedure

Find the official recovery instructions for the exact manufacturer and model. Ask the vendor to confirm the correct process if the instructions are unclear or the device is safety-sensitive. Depending on the device, the supported recovery may involve a factory reset, reinstalling vendor-provided firmware, or another model-specific procedure. Do not assume every device uses the same steps.

  • Use firmware and recovery files only from the manufacturer’s official channel; avoid unofficial mirrors.
  • If the manufacturer specifies a reset and signed-firmware reinstall, follow those instructions and replace default credentials.
  • Do not treat killing a process or deleting a file as proof of removal. Embedded devices can have model-specific recovery and persistence mechanisms.
  • If the vendor cannot provide a recovery method you can trust, consider keeping the device out of service and asking about supported replacement or specialist recovery. The safest choice depends on the device and its role.

General IoT and OT security guidance cannot substitute for the recovery procedure of a particular product. NIST’s Federal Profile covers device cybersecurity capabilities, while NISTIR 8428 addresses OT incident handling and forensics; neither supplies a universal Linux-backdoor removal procedure.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Secure credentials and connected accounts

From a device you trust, change passwords that were reused or that the compromised IoT device could access. Review associated cloud accounts, network administration, and other connected devices for unauthorized activity. If you find evidence that another system or account was accessed, handle it as part of the same incident rather than assuming the IoT device was the only affected asset.

CISA’s incident-response recommendations include isolating affected systems, collecting logs and artifacts, resetting reused passwords, securing backups, and seeking specialist help when appropriate. CISA and partner agencies: Understanding and Mitigating Russian State-Sponsored Cyber Threats to U.S. Critical Infrastructure

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Put the device back into service cautiously

After the vendor-supported recovery, watch for the original suspicious behavior and review network activity for unexpected connections. Install security updates when the manufacturer makes them available, replace default credentials, disable remote access you do not need, and restrict the device to the network services it requires. These controls can reduce exposure and limit what a compromised device could reach; they are not a guarantee that an infection has been removed.

NIST’s small-business and home IoT guidance describes device constraints and the risks of network-based attacks against compromised IoT devices. NIST SP 1800-15, Securing Small-Business and Home Internet of Things Devices

When to get specialist help

Contact the manufacturer for device-specific recovery advice. For industrial, medical, safety-relevant, or organization-managed equipment, involve the responsible operator and incident-response team; OT forensics expertise may be needed to preserve evidence and restore service safely. NISTIR 8428 provides an OT-focused framework for digital forensics and incident response.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.