Site navigation

New IoT BotNet Threatens Massive Disruption

Brian Baglow

,

IoT Botnet IoTroop IoT_Reaper spreading rapidly

Over a million devices may already have been compromised.

Malware targeting IoT devices such as cameras.

Experts estimate the damage capability could ‘take down the Internet.’

In 2016 an IoT worm named Mirai made parts of the Internet accessible by targeting a wide range of devices which used the default passwords and login details set by the manufacturer – which in practice meant most of them.

The resulting Distributed Denial of Service attack took down a range of major services including Twitter, Spotify, Netflix, GitHub, Amazon and Reddit.

Now, two security organisations are warning of a new, more sophisticated worm, apparently based upon the same technology, which has the potential to wreak even more chaos.

Chinese security team Qihoo 360 and Israel’s Check Point are both reporting that a new IoT BotNet dubbed IoTroop (according to Check Point), or IoT_Reaper (according to Qihoo 360) is compromising devices more quickly than Mirai and offers far greater potential for damage than its predecessor.

The new botnet builds on elements of Mirai code. However, rather than guessing the passwords of the devices it attacks, it uses known security flaws in insecure machines, using a variety of hacking tools to infect and replicate itself more widely.

While IoTroop/IoT_Reaper has not yet been used for the kind of distributed denial of service attacks that Mirai and its successors have launched, that improved arsenal of features could potentially allow it to become even larger—and more dangerous—than Mirai ever was.

Both firms report that the botnet exploits known vulnerabilities in devices from multiple manufacturers. Qihoo 360 noted nine exploits integrated into the current form:

The Chinese team also note that the code has been modified and updated in the recent past, indicating that the creator is still adding new exploits to the worm, as they’re discovered.

Check Point reports that 60% of the networks it tracks have been infected with the malware. Qihoo states that 10,000 devices in the botnet communicate with the command-and-control server on a daily basis. In addition they report that that millions of devices are ‘queued’ i.e. compromised and only awaiting loader software to add them to the botnet.

While there has been no indication of an attack, the researchers note that the malware includes a software platform which allows new code modules to be downloaded to infected devices. This means the botnet could shift its tactics at any time and ‘weaponise’ its compromised routers and cameras.

The owners of the infected devices which are unlikely to be the main targets. The victims are far more likely to be major corporations and significant parts of the infrastructure of the Internet itself. McAfee reported that Mirai infected 2.5 million devices at the end of 2016, which was used to attack DNS provider Dyn, taking major companies and services including Spotify, Reddit, and The New York Times offline.

Both teams are urging companies to ensure they have defence mechanisms in place and are prepared for a full scale DDoS attack from one of the largest and most sophisticated botnets yet assembled.

With an estimated 30 billion IoT devices in use by 2020, the threat from IoT botnets is only likely to increase. Despite this, security for IoT devices seems to remain a low priority for manufacturers and device owners alike.

DIGIT will continue to report on the situation as it unfolds.

Movers and shakers

Brian Baglow

Editor

Latest News

Cybersecurity Featured Security

Proposed Police Scotland Cyber Centre Raises Duplication Questions

Cybersecurity Editor's Picks Events

Microsoft, NBCUniversal and Admiral Group Experts Set for CymruSec 2026

AI Business Editor's Picks

Salesforce Agentforce Bugs Exposed Wider AI Agent Risk, Research Finds

AI Cybersecurity

Despite AI Hype, Traditional Identity Fraud Prevails