HomeSecurityResearchers uncover a thriving underground economy for malware targeting IoT devices

Researchers uncover a thriving underground economy for malware targeting IoT devices

Researchers uncover a thriving underground economy for malware targeting IoT devices.

Kaspersky researchers have discovered a thriving dark web economy that offers exploits for zero-day vulnerabilities in IoT devices, as well as IoT malware accompanied by infrastructure and supporting tools.

IoT malware

The most notable service, in high demand among hackers, was found to be Distributed Denial of Service (DDoS) attacks orchestrated via IoT botnets.

IoT devices are non-standard computing hardware used to extend internet connectivity beyond traditional devices. IoT devices include sensors, actuators, or devices that are capable of connecting to the internet. These devices can be monitored or controlled remotely and are used in both industrial and end-consumer products, including mobile devices, industrial equipment, and medical devices.

While the primary means of infection of IoT devices was found to be brute-force brute-force passwords, which has been the preferred method for some time, it was also found that exploiting vulnerabilities in network services was a popular method for breaching the security of IoT devices.

Additionally, vulnerabilities have been identified in IoT devices due to exploitation of the services they use. These attacks typically involve executing malicious commands by exploiting vulnerabilities in the web interfaces of IoT devices, resulting in significant consequences, such as the spread of malware.

The research also revealed that the cost of these services varies depending on factors such as DDoS protection, CAPTCHA , and JavaScript verification on the victim's side, ranging from $20 per day to $10,000 per month.

“On average, ads offered these services for $63.50 per day or $1350 per month,” Kaspersky said in a statement.

“Kaspersky urges vendors to prioritize cybersecurity in both consumer and industrial IoT devices. We believe they should make it mandatory to change default passwords on IoT devices and consistently issue patches to fix vulnerabilities,” said Yaroslav Shmelev, security expert at Kaspersky.

Source of information: thehindu.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS