Skip to main content

Internet of Things was the source of largest botnet attack in history

botnet cameras iot attack ismartalarm spot security camera 2
Security news site and blog KrebsonSecurity, was hit by the world’s largest denial of service (DDOS) attack last week, with more than 620 gigabits per second hammering its servers into submission. While astounding in its own right, what’s of more concern is the source: not infected PCs, but internet of things (IOT) devices like cameras and routers.

But the attackers didn’t stop there. Whoever was behind the DDOS was only just getting started. Since then we’ve seen assaults that peaked at over a terabit of data per second, with concerns that the botnet has the potential to deliver a further 50 percent more data if the timing is right.

Related Videos

Although as Ars reports, these numbers have yet to be officially confirmed, the sources are rather reliable. It would be easy to dismiss them based on their extravagance, since to date, the largest recorded botnet attack threw 363 gigabits per second of data. However, considering we’ve now seen attacks in excess of three times that much, we would expect to see many more large-scale attacks in the near future.

Related: Two Israeli teenagers arrested over vDOS DDoS-for-hire service

The reason this was possible at all is because of the Internet of Things. IOT devices have long been considered a security hole in the technological landscape, as they so often operate under the radar, and so receive less scrutiny from users and security professionals. However, they often have the ability to upload a lot of data at once, so it’s not always obvious when they’re used as part of an attack like this one.

We’ve seen hints of IOT devices like home routers being used in DDOS attacks before. The famous downing of the Xbox Live and PlayStation networks in 2015 was in part caused by botnet-connected home network hubs.

Even if you do notice that your IOT device is behaving oddly, reclaiming control of your hardware may not always be easy. By their very nature IOT devices tend to operate behind the scenes, so they often have minimal interfaces or ability to change important settings.

One preemptive security step people can take is to never put their hardware online at all. That may often defeat the point of a bit of smart tech and would of course be redundant for routers or similar devices, but there are a number of devices that don’t really need to be connected online all the time.

At the very least users should change their default passwords. Make them long, make them unique, and change them periodically to play it safe.

Editors' Recommendations

Google just thwarted the largest HTTPS DDoS attack in history
A depiction of a hacker breaking into a system via the use of code.

Google has confirmed that one of its cloud customers was targeted with the largest HTTPS distributed denial-of-service (DDoS) attack ever reported.

As reported by Bleeping Computer, a Cloud Armor client was on the receiving end of an attack that totaled 46 million requests per second (RPS) at its peak.

Read more
Google Fiber is bringing high-speed internet to five new states
google fiber tv hands on box remote 2

In what is the first significant expansion since pausing new construction in late 2016, Google recently detailed future plans to bring its Fiber internet services to more regions. The company now says it is planning to deliver high-speed internet through Google Fiber to five new states, specifically Arizona, Colorado, Nebraska, Nevada, and Idaho.

According to Google Fiber's Dinni Jain, Google has been busy the past several years behind the scenes. In a blog post, Jain mentioned the teams have been focusing on the Google Fiber vision and have been looking at refinements to service delivery and products. Jain also said the Google Fiber team traveled across the United States and had conversations with elected officials to bring internet to businesses and residents "as quickly as possible."

Read more
Intel could give us Wi-Fi 7 devices long before Apple gets around to it
Internals of Surface Laptop Studio.

Wi-Fi 7 may not exist in devices today, but that isn't stopping Intel from forging ahead with it. Intel is planning to introduce Wi-Fi 7 sometime in 2024 just as Apple turns to Wi-Fi 6E for its upcoming devices. Intel will be doubling down on Wi-Fi 7 development efforts over the coming year, according to Eric McLaughlin, Intel's vice-president of wireless solutions.

"We are currently developing Intel's Wi-Fi '802.11be' in order to obtain the 'Wi-Fi Alliance' certification, and it will be installed in PC products such as laptops by 2024," McLaughlin said in a press conference earlier today. "We expect it to appear in major markets in 2025."

Read more