Symantec and reveals in new research how cybercriminal networks are exploiting the security flexibility of Internet of Things (IoT)to spread malwarecreate zombie networks or botnets, without the knowledge of their owners.
Symantec 's Security Response team has discovered that cybercriminals are invading home networks, as well as connected devices that consumers use every day, to launch distributed denial of service ( DDoS ) attacks against more profitable targets, usually larger companies. To achieve their goal, they need cheap bandwidth and achieve this by stitching together a wide range of consumer devices, which are easy to infect since they lack sophisticated security.

It should be noted that more than half of the total IoToriginate from China and the U.S., based on the location of the IP addresses that “point” to the origin of the malware. Also, a large number of attacks originate from Germany, the Netherlands, Russia, Ukraine and Vietnam. In some cases, the IP addresses are used through proxies, so that the attackers hide their real location.
Most IoT malwaretarget non-personal devices, such as servers, routers, modems, network attached storage (NAS) devices, closed-circuit television (CCTV) systems, and industrial control systems. Many of these systems may have access to the Internet, but due to their operating system and limited processing power, they may not have advanced security features.
As attackers are fully aware of the inadequate security of IoT, many of them pre-program the malware they create, including commonly used passwords, which allow easy intrusion into these devices. The low level of security in many IoT devices makes them easy targets, with victims often not even knowing they have been infected.
Additional findings from Symantec 's research include the following:
- 2015 was a record year for IoT, with a plethora of cases targeting home automation and home security devices. However, attacks to date have shown that attackers tend to care less about the victim, with the majority focusing on the device itself in order to add it to one of the botnets, most of which are used to carry out DDoS.
- IoT devices are the primary target, since they are designed to be connected and “forgotten” after the basic set - up .
- The most common IoT malware passwords are used to try to log into devices and as expected, the combination is “ root ” and “ admin ”, indicating that default passwords are often never changed!
- Attacks originating from multiple IoT will become more common in the future, as the number of embedded devices connected to the Internet continues to increase.
More information about Symantec's IoT research can be found at: https://www.symantec.com/connect/blogs/iot-devices-being-increasingly-used-ddos-attacks
