Skip to main navigation Skip to search Skip to main content

An analysis of malware threats fating the IoT: a taxonomy of IoT malware

Research output: Chapter in Book/Report/Conference proceedingConference contribution

50 Downloads (Pure)

Abstract

From its origins in “Weiser’s vision” in the 90’s there has been widespread adoption of Internet of Things (IoT) technologies across consumer, commercial, industrial, logistics, utilities, and healthcare environments. This has brought with it an expansion and rise in vulnerabilities and malware threats due to an increase in potential vectors of attacks and the general discovery, privacy and security issues facing IoT solutions. Many IoT systems across these sectors contain a mixture of Information Technology (IT) and Operational Technology (OT) network segments and many existing legacy networks of systems have incorporated or adopted IoT components or services into their networks. These are generally built with compatibility and operability in mind with security usually less considered or as an afterthought. A large variety of IoT malware exists including botnet and Denial of Service (DoS) variants, brickers, cryptominers, ransomware, stalkerware and Industrial Controller Systems (ICS) malware variants and there can also be significant threat leveraged from IoT malware to certain critical systems or services being controlled or monitored. Threats can also be leveraged from a compromised IoT system and used for deployment of threats including DoS reflection or amplification attacks. The research presented here provides a review and threat analysis of the varieties of IoT malware that currently exist with a case analysis and comparison of two high profile ICS capable targeting malware known as BlackEnergy and Industroyer. These variants were responsible for the attack and compromise of energy utilities providers networks in Ukraine between 2014 and 2022 and show examples of malware threats using different routines to gain compromise of critical ICS systems.
Original languageEnglish
Title of host publicationCROSS-SEC 2026
Subtitle of host publicationThe First International Conference on Cross-Domain Security in Distributed, Intelligent and Critical Systems
EditorsAndreas Aßmuth, Christoph P. Neumann, Sebastian Fischer
PublisherInternational Academy, Research, and Industry Association (IARIA)
Pages112-127
Number of pages16
ISBN (Print)9781685584429
Publication statusPublished - 19 Apr 2026
EventThe First International Conference on Cross-Domain Security in Distributed, Intelligent and Critical Systems - Lisbon, Portugal
Duration: 19 Apr 202623 Apr 2026
Conference number: 1st
https://www.iaria.org/conferences2026/ProgramCROSS-SEC26.html

Conference

ConferenceThe First International Conference on Cross-Domain Security in Distributed, Intelligent and Critical Systems
Abbreviated titleCROSS-SEC 2026
Country/TerritoryPortugal
CityLisbon
Period19/04/2623/04/26
Internet address

Keywords

  • IoT malware
  • IoT threat analysis
  • IoT security
  • BlackEnergy
  • Industroyer

Fingerprint

Dive into the research topics of 'An analysis of malware threats fating the IoT: a taxonomy of IoT malware'. Together they form a unique fingerprint.

Cite this