The Dangers of Hacker Attacks on IoT Devices: Real Stories

The infrastructure of modern megacities is built on Internet of Things devices: from road cameras to large hydropower plants and hospitals. Hackers can turn any connected device into a bot and use it for launching DDoS attacks.

Motives can vary widely: hackers may be funded by a government or corporation, or sometimes they are simply criminals looking to have fun and make money.

In Russia, the military increasingly alarms us with the potential for cyberattacks on 'critical infrastructure' (it was formally to protect against this that the law on a sovereign internet was enacted).

The Dangers of Hacker Attacks on IoT Devices: Real Stories

However, this is not just a scary tale. According to Kaspersky, in the first half of 2019, hackers attacked Internet of Things devices more than 100 million times — most often using the Mirai and Nyadrop botnets. Interestingly, Russia ranks only fourth in the number of such attacks (despite the ominous image of 'Russian hackers' created by the Western press); the top three are China, Brazil, and even Egypt. The United States is in fifth place.

So, can we successfully repel such attacks? First, let’s review some well-known cases of such assaults to find answers on how to secure your devices at least at a basic level.

Bowman Avenue Dam

The Bowman Avenue Dam is located in Rye Brook, New York, with a population of less than 10,000 people — its height is just six meters, and its width does not exceed five. In 2013, U.S. intelligence agencies detected malware in the dam's information system. Hackers did not use the stolen data to disrupt the facility (most likely because the dam was disconnected from the internet during repair work).

The Bowman Avenue Dam is needed to prevent flooding of areas near the stream during a spill. There could not have been any destructive consequences from disabling the dam — at worst, the basements of a few buildings downstream would be flooded with water, but that cannot even be called a flood.

The Dangers of Hacker Attacks on IoT Devices: Real Stories

The city's mayor, Paul Rosenberg, then suggested that hackers might have mistaken the structure for another large dam with the same name in Oregon. It's used for irrigating numerous farms, and a malfunction there could cause serious damage to local residents.

It's quite possible that the hackers were simply training on a small dam to later launch a serious attack on a major hydroelectric power plant or any other element of the U.S. energy system.

The attack on the Bowman Avenue dam was recognized as part of a series of bank system hacks successfully carried out by seven Iranian hackers over the course of a year (DDoS attacks). During this time, the operations of 46 of the country's largest financial institutions were disrupted, and bank accounts of hundreds of thousands of clients were blocked.

Later, accusations regarding the series of hacker attacks on banks and the Bowman Avenue dam were leveled against the Iranian Hamid Firouzi. It became clear that he used the 'Google dorking' method to find 'holes' in the dam's operation (later, local media unleashed a torrent of accusations against Google). Hamid Firouzi was not located in the U.S. Since there is no extradition from Iran to the States, the hackers received no real sentences.

2. Free subway in San Francisco

On November 25, 2016, a message appeared on all electronic fare terminals for public transport in San Francisco: 'You have been hacked, all data is encrypted.' All computers running Windows belonging to the city’s transport agency were also attacked. The malicious software HDDCryptor (a ransomware targeting the Windows boot sector) managed to reach the controller domain of the organization.

The Dangers of Hacker Attacks on IoT Devices: Real Stories

HDDCryptor encrypts local hard drives and network files using randomly generated keys, then overwrites the MBR of hard drives to prevent the proper loading of systems. The hardware is typically infected due to employees accidentally opening a trap file in an email, after which the virus spreads across the network.

The attackers offered the local government to contact them via email at cryptom27@yandex.com (yes, Yandex). In exchange for the key to decrypt all data, they demanded 100 bitcoins (about $73,000 at that time). The hackers also proposed to decrypt one machine for one bitcoin to prove that recovery was possible. However, the government managed to deal with the virus on their own, though it took more than a day. During the system recovery, subway rides were made free.

"We opened the turnstiles as a precautionary measure to minimize the impact of this attack on passengers," explained municipal spokesperson Paul Rose.

The criminals also claimed to have gained access to 30 GB of internal documents from the San Francisco Municipal Transportation Agency and promised to leak them online if the ransom was not paid within 24 hours.

By the way, a year earlier, the Hollywood Presbyterian Medical Center in the same state had been attacked. At that time, hackers were paid $17,000 to restore access to the hospital's computer system.

3. Emergency alert system in Dallas

In April 2017, at 11:40 PM in Dallas, 156 emergency sirens were activated to alert the public to emergencies. They could only be turned off two hours later. During this time, the 911 service received thousands of distress calls from local residents (a few days before the incident, three weak tornadoes had passed through Dallas, damaging several homes).

The Dangers of Hacker Attacks on IoT Devices: Real Stories

The emergency alert system was installed in Dallas in 2007, with sirens provided by Federal Signal. Authorities did not specify details on the workings of the systems, but stated that it uses "tone signals." These signals are typically broadcast by the meteorological service using Dual-Tone Multi-Frequency (DTMF) or Audio Frequency Shift Keying (AFSK). These are encrypted commands transmitted on a frequency of 700 MHz.

City officials suggested that the attackers recorded audio signals broadcast during the testing of the alert system and then replayed them (a classic replay attack). For this, hackers only needed to purchase test equipment for working with radio frequencies, which can be easily acquired at specialized stores.

Experts from the research company Bastille noted that conducting such an attack implies that the attackers thoroughly studied the city's emergency alert system, its frequencies, and codes.

The mayor of Dallas issued a statement the next day stating that the hackers would be found and punished, and that all alert systems in Texas would be upgraded. However, the culprits were never found.

***
The concept of smart cities carries significant risks. If the management system of a metropolis is hacked, attackers will gain remote access to control traffic situations and strategically important urban facilities.

Risks are also associated with the theft of databases that include not only information about the entire city's infrastructure but also personal data of residents. One must not forget about excessive energy consumption and network overloads—all technologies rely on communication channels and nodes, including the electricity consumed.

The anxiety level of IoT device owners is striving towards zero.

In 2017, Trustlook conducted a study on the awareness of IoT device owners regarding their security. It was found that 35% of respondents do not change the default (factory) password before starting to use the device. Moreover, more than half of users do not install third-party software to protect against hacker attacks. 80% of IoT device owners had never heard of the existence of the Mirai botnet.

The Dangers of Hacker Attacks on IoT Devices: Real Stories

At the same time, with the development of the Internet of Things, the number of cyberattacks will only increase. And while companies are purchasing 'smart' devices, forgetting the basic security rules, cybercriminals are gaining more opportunities to profit from careless users. For example, they use networks of infected devices to conduct DDoS attacks or as proxies.server for other malicious activities. Most of these unpleasant incidents can be prevented by following some simple rules:

  • Change the default password before you start using the device.
  • Install reliable internet security software on your computers, tablets, and smartphones.
  • Do your research before purchasing. Devices become smart because they collect a lot of personal data. You should know what type of information will be collected, how it will be stored and protected, and whether it will be transmitted to third parties.
  • Regularly check for firmware updates on the manufacturer's website.
  • Don't forget to audit the event log (primarily, analyze all USB port usage).

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster