Research by F-Secure Labs has revealed that the scale of emerging malware threats affecting IoT devices has more than doubled in the past year.
Researchers attribute this escalation to the increasing popularity of IoT devices among both businesses and consumers. Currently, there are more IoT devices than people on the planet, an estimated 7.5 billion in 2018 and this figure is expected to triple by 2021.
Due to the easily exploitable nature of the technology, researchers say cybercriminals now view the devices as ‘easy prey’. Unpatched software and weak passwords were found to be the most commonly exploited vulnerabilities used by cybercriminals.
In 2017, the team at F-Secure labs discovered five major malware threats and three the previous year. However, in 2018 they uncovered 19 variants across 10 strands that posed a risk to the IoT ecosystem.
Recommended: The Internet of Things: A “Game-Changer” for Scotland’s Economy?
87% of threats detected were based on using weak or default credentials, unpatched software vulnerabilities, or a combination of both.
“The explosion of IoT devices in people’s homes and offices is attracting attention from cybercriminals,” the report stated. “And thanks to the security problems commonly found in these devices, they present attackers with low hanging fruit to pick.
“This explosion of attacks suggests that there is still plenty of “easy prey” out there and criminals are going after it.”
Public-facing devices such as routers, cameras and digital video recorders, researchers said, are among the most obvious targets for criminals. Appliances such as washing machines and fridges with embedded computers are almost as vulnerable due to more devices becoming connected.
The biggest threat is the automatic infection of IoT devices, with numerous ways to attack control interfaces – these include HTTP, SSH and Telenet ports.
In 2018, of all the attacks F-Secure observed on honeypot servers, 59% targeted Telnet ports.
“Deploying massive amounts of computing power without prioritising security and privacy has created a new target that criminals are just beginning to exploit,” the report explained.
“This requires immediate action by manufacturers, regulators and everyone responsible for connecting people to the internet. Because when these threats turn our technologies against us, no one can say that we weren’t warned.”
Looking to the future, researchers predict that the bulk of IoT threats will probably entail using hijacked computing power to help launch denial-of-service (DoS) attacks and for cryptocurrency mining.
Previously, businesses have been targeted by criminals via IoT devices such as aquariums and cardiac devices, which suggests in the future hackers are likely to pursue high-value targets through this method.
The report concluded by calling on governments to implement stronger regulations regarding IoT security and take a more active role. It suggests that legislators ought to create a framework around IoT security or establish clear responsibilities.






