Security experts reported that hackers have managed to infect malware some devices IoT still running Windows 7 and designed by three of the world's largest manufacturers with 
The discovery was made by TrapX, who believe it may be a “supply chain attack.”
According to the data, the infection took place a few months ago, in October 2019. Hackers infected IoT devices with malware that belongs to the category of cryptocurrency miners. The affected IoT devices include self-guided vehicles (AGVs, robots), a printer, and a smart TV.
“The malware sample analyzed by TrapX® is part of the Lemon_Duck family that executes via double-click or persistence mechanisms,” TrapX researchers report. “Initially, the malware scanned the network for potential targets, primarily those with SMB (445) or MSSQL (1433) services open. Once a potential target was identified, the cryptocurrency miner would begin its work.”
According to experts, the attacks on the IoT devices of the three manufacturers are likely part of the same hacking campaign. The attackers infected at least 50 sites of the companies in the Middle East, North America and Latin America.
The attackers used a downloader that executes malicious scripts related to the cryptocurrency miner Lemon_Duck. Researchers say that this malware spreads very quickly, which is why it is considered “extremely dangerous.”

“Once again, the entry point was an IoT device running Windows 7. The attacks caused confusion in the production process, destroying the AGV robots. The malware spread quite quickly,” the researchers said. “TrapX software provided early detection of the cryptocurrency malware and allowed the security team to immediately disconnect the infected AGVs from the network.” AGVs are IoT-enabled robotic vehicles that are typically used to transport materials in factories.
Windows 7 was discontinued by Microsoft about a month ago. However, many users around the world continue to use it, leaving their devices vulnerable. Cybercriminals know this and are looking for vulnerable IoT and other systems to attack.
Experts found several automated guided vehicles (AGVs), running Windows 7, to be infected with the cryptocurrency miner.
The cryptocurrency miner was also found on an HP DesignJet SD Pro printer that had been used to print designs containing sensitive data related to the target's manufacturing process. The hackers infected their device and gained access to the target's network.
Finally, the malware was installed on a smart TV with a built-in computer that also ran Windows 7.
TrapX experts speculate that it was a supply chain attack and that the malware was first installed on vulnerable devices and then affected the manufacturers' sites.
More details about the infection of IoT devices can be found in the report published by TrapX.
