IoT devices still major target for cyberattacks

IoT
Image Credit: Shutterstock (Image credit: Shutterstock)

During the first half of 2019, cybercriminals increased the intensity of both IoT and SMB-related attacks according to a new report from F-Secure.

The firm's “Attack Landscape H1 2019” report highlighted the threat unsecured IoT devices can pose to businesses and consumers as well as the continued popularity of Eternal Blue and similar exploits two years after the WannaCry ransomware was released on the world.

F-Secure uses decoy servers called honeypots to lure in attackers to collect information on their activities and this year its honeypots measured a twelvefold increase in IoT and SMB-related attacks compared to the same period a year ago. This increase was driven by traffic targeting the Telnet and UPnP protocols, which are used by IoT devices, as well as the SMB protocol, which is used by the Eternal family of exploits to spread ransomware and banking Trojans.

Telnet, UPnP and SMB traffic

The largest share of traffic during H1 2019 was led by Telnet with over 760m attack events logged or around 26 percent of traffic. UPnP was the next most frequent with 611m attacks followed by SSH, which is also used to target IoT devices, at 456m attacks.

IoT devices that have been infected with malware such as Mirai are likely sources of this traffic as Mirai was the most common malware family observed by F-Secure's honeypots. Mirai targets and infects routers, security cameras and other IoT devices which use factory default credentials.

F-Secure also found that traffic to SMB port 445 accounted for 556m attacks. The high level of SMB traffic indicates that the Eternal family of exploits, which were first used in 2017's WannaCry ransomware outbreak, are still being used by cybercriminals looking to target millions of machines that have not yet been patched.

Principal researcher at F-Secure, Jarno Niemela provided further insight on the report's findings, saying:

“Three years after Mirai first appeared, and two years after WannaCry, it shows that we still haven’t solved the problems leveraged in those outbreaks. The insecurity of the IoT, for one, is only getting more profound, with more and more devices cropping up all the time and then being co-opted into botnets. And the activity on SMB indicates there are still too many machines out there that remain unpatched.” 

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
The Google Gemini logo against a black background.
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's upcoming Flash 2.0 built-in image upgrade
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all