HomeSecurityComeback of old malware due to insecure IoT devices!

Comeback of old malware due to insecure IoT devices!

The increased use of Internet of Things (IoT) devices and unsupported operating systems leaves networks vulnerable to cyberattacks and malware.

One of the malware exploiting this situation is Conficker. Conficker first appeared in 2008 and exploited vulnerabilities in Windows XP and older Microsoft operating to systems , spread to vulnerable machines and join them in a botnetaccording to researchers, the malware is still a threat 12 years later.

This type of malware was not particularly destructive and its creators had restricted its use for a while, as it had attracted the attention of experts. However, the worm remains active and hundreds of thousands of machines are at risk.

A new report from Palo Alto Networks has shown that attacks have increased, and that the number of infected machines has recently reached 500,000.

One of the ways Conficker continues to spread is by infecting connected medical devicesone running outdated versions of Windows. According to researchersin five Palo Alto Networks customers have been infected with Conficker in the past two years.

One specific incident was identified by researchers when Palo Alto Networks' Zingbox IoT security software detected unusual behavior on the network.

The unusual activity originated from a mammography machine, and within days it was discovered that Conficker had also infected other medical devices connected to the same network, including a mammography machine, a digital imaging unit, a radiology machine, and other devices.

Hospital staff attempted to remove the infections by rebooting the connected devices, but a few hours after they returned to the network, Conficker reinfected thembecause the devices had not received patches . Therefore, they remained vulnerable.

The hospital (whose name has not been released) was forced to shut down all devices. It then installed the latest security updates and gradually restored all systems. It took a week for all devices and networks to be back up and running.

Comeback of old malware due to insecure IoT devices!

One of the main reasons why the Conficker worm was able to spread to medical IoT devices is that these devices are not monitored like other computers on the network, allowing hackers to use malicious programs and gain access to networks.

Hackers know this and are increasingly turning to developing botnets that target IoT, such as Mirai. Releases of the Mirai source code have helped increase the number of IoT-based attacks.

However, organizations can protect IoT devices on their network by following a few simple steps:

  • First, organizations should scan their networks to discover all IoT devices.
  • Second, common IoT devices like printers and cameras (and patient monitoring systems) should receive regular updatesto patch potential vulnerabilities.
  • Third, IoT devices should be on a separate network , not the same network as computers and laptops. This way, if a hacker compromises an IoT device and infects it with malware, they won't be able to affect other systems.

But the key is to update all potentially vulnerable devices. The vulnerability exploited by Conficker is over ten years old, so the update should have been done long ago.

“You are at risk if you are running an outdated operating system, such as Windows XP, Windows Vista, Windows Server 2003, or Windows Server 2008. Users should also disable SMB and upgrade their Windows operating systems to the latest version . Finally, critical devices should be denied internet access,” said May Wang, an executive at Palo Alto Networks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS