Skip to main content
  1. Home
  2. Computing
  3. Business
  4. Emerging Tech
  5. Web
  6. News

Hackers could seize robots with ransomware, costing companies millions

Add as a preferred source on Google
Image used with permission by copyright holder

Security consultants IOActive recently created a proof-of-concept attack that uses ransomware to disrupt big corporations. The attack didn’t land on corporate PCs to encrypt files for ransom. Instead, the researchers attacked robots, which are vital in many markets such as automobile manufacturing, healthcare, and more. Disrupting these robot-powered environments can cost businesses money every second they are offline. 

One attack vector relies on how robots deal with data. Although they typically include internal storage, most of the data handled by robots remains “in transit,” meaning robots receive data, process the data, and then send the data back to be stored at the source. That data could contain high-definition video, captured audio, payments received by customers, instructions on how to perform the current task, and so on. 

Recommended Videos

“Instead of encrypting data, an attacker could target key robot software components to make the robot non-operational until the ransom is paid,” the researchers state. 

To prove their theory, the researchers focused their attack on NAO, a highly used robot in the research and education fields with a roster of 10,000 units in active duty across the globe. It has “nearly the same” operating system and vulnerabilities as SoftBank’s Pepper, a business-oriented robot with a massive roster of 20,000 units deployed in 2,000 businesses. Even Sprint is using Pepper to assist customers in its retail stores. 

The attack starts off by exploiting an undocumented function that allows anyone to remotely execute commands. After that, they could disable administration features, change the robot’s default functions, and route all video and audio feeds to a remote server on the internet. Others steps include elevating user privileges, disrupting the factory reset mechanism, and infect all behavior files. In other words, they can make the robot very unpleasant, even physically harmful.

By hijacking robots, hackers could interrupt service altogether, causing corporations to lose money with each passing moment. They could even force the robots to show explicit porn to customers, curse at customers during one-on-one interaction, or perform violent movements. The only way to reverse the behavior is to succumb to hackers because, ultimately, paying the ransom could be cheaper than repairs. 

That scenario even applies to sex robots given the privacy and intimacy aspects. Users will likely shell out money to hackers rather than call technical support, deal with customer care, and arrange for someone to get the unit for “repairs.” At least sex robots don’t have any moving parts … or rather, not yet. 

“They aren’t cheap,” the report states. “It’s not easy to factory reset them or fix software and hardware problems. Usually, when a robot malfunctions, you have to return it to the factory or employ a technician to fix it. Either way, you may wait weeks for its return to operational status.” 

The researchers compare disrupting robots in corporate environments to halting cryptocurrency mining farms. Interrupt those PCs with ransomware and miners lose money every second those devices aren’t online digging for digital coins. 

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
ChatGPT’s Computer History has one big privacy problem
The feature stores interaction data locally, but OpenAI says those files aren't encrypted.
ChatGPT Computer History Feature in action

We've already covered how ChatGPT's Computer History feature lets the Mac app remember what users have been doing across apps and websites, using interaction events such as clicks, typing, and app switching rather than screenshots or recordings. However, a rather uncomfortable detail in OpenAI's official documentation is that the files containing that history aren't encrypted.

Your Mac history is stored as plain text

Read more
Are classroom screens making children less cognitively capable? Experts are divided
A neuroscientist wants fewer screens in schools, but not everyone agrees
school-screentime

Jared Cooney Horvath has spent over 15 years studying how people learn, and he says the picture for today's kids isn't good. The neuroscientist and former teacher argues that classroom technology is quietly eroding how children think and retain knowledge, according to a report from The Guardian.

Horvath's new book, The Digital Delusion, lays out the case that generational progress in health and education has stalled since around 2000, right around the time kids started to get access to screens. Concerns about early exposure run even deeper, with some researchers now warning that screen habits formed before age two carry their own developmental risks.

Read more
Mac users now have an easier way to install apps from DMG files
With EasyDMG, you'll never have to drag and drop a DMG file again.
easydmg-free-mac-app-install-dmg-files

If you have ever installed a new app on a Mac, you already know the slightly tedious dance that comes with it. You download a DMG file, double-click it, wait for the virtual disk to mount, drag the app icon into your Applications folder, and delete the leftover file. This installation method has barely changed since it debuted alongside Mac OS X back in 2001, and developer Jeff Schumann finally got fed up enough to fix it himself.

How EasyDMG simplifies the process of installing apps on Mac

Read more