Abstract
From its origins in “Weiser’s vision” in the 90’s there has been widespread adoption of Internet of Things (IoT) technologies across consumer, commercial, industrial, logistics, utilities, and healthcare environments. This has brought with it an expansion and rise in vulnerabilities and malware threats due to an increase in potential vectors of attacks and the general discovery, privacy and security issues facing IoT solutions. Many IoT systems across these sectors contain a mixture of Information Technology (IT) and Operational Technology (OT) network segments and many existing legacy networks of systems have incorporated or adopted IoT components or services into their networks. These are generally built with compatibility and operability in mind with security usually less considered or as an afterthought. A large variety of IoT malware exists including botnet and Denial of Service (DoS) variants, brickers, cryptominers, ransomware, stalkerware and Industrial Controller Systems (ICS) malware variants and there can also be significant threat leveraged from IoT malware to certain critical systems or services being controlled or monitored. Threats can also be leveraged from a compromised IoT system and used for deployment of threats including DoS reflection or amplification attacks. The research presented here provides a review and threat analysis of the varieties of IoT malware that currently exist with a case analysis and comparison of two high profile ICS capable targeting malware known as BlackEnergy and Industroyer. These variants were responsible for the attack and compromise of energy utilities providers networks in Ukraine between 2014 and 2022 and show examples of malware threats using different routines to gain compromise of critical ICS systems.
| Original language | English |
|---|---|
| Title of host publication | CROSS-SEC 2026 |
| Subtitle of host publication | The First International Conference on Cross-Domain Security in Distributed, Intelligent and Critical Systems |
| Editors | Andreas Aßmuth, Christoph P. Neumann, Sebastian Fischer |
| Publisher | International Academy, Research, and Industry Association (IARIA) |
| Pages | 112-127 |
| Number of pages | 16 |
| ISBN (Print) | 9781685584429 |
| Publication status | Published - 19 Apr 2026 |
| Event | The First International Conference on Cross-Domain Security in Distributed, Intelligent and Critical Systems - Lisbon, Portugal Duration: 19 Apr 2026 → 23 Apr 2026 Conference number: 1st https://www.iaria.org/conferences2026/ProgramCROSS-SEC26.html |
Conference
| Conference | The First International Conference on Cross-Domain Security in Distributed, Intelligent and Critical Systems |
|---|---|
| Abbreviated title | CROSS-SEC 2026 |
| Country/Territory | Portugal |
| City | Lisbon |
| Period | 19/04/26 → 23/04/26 |
| Internet address |
Keywords
- IoT malware
- IoT threat analysis
- IoT security
- BlackEnergy
- Industroyer
Fingerprint
Dive into the research topics of 'An analysis of malware threats fating the IoT: a taxonomy of IoT malware'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver