DSLR cameras could be at risk from ransomware

(Image credit: Future)

By exploiting security vulnerabilities in popular internet-connected digital DSLR cameras, hackers could infect them with ransomware to render the devices useless or to deploy other types of malware on larger networks according to new research from Check Point Software.

Digital cameras use Picture Transfer Protocol (PTP) to transfer digital files and the firm's researchers discovered how to exploit vulnerabilities in the protocol to infect a camera with ransomware, which they showed off at this year's Defcon security conference.

Check Point decided to use the Canon EOS 80D for its tests as the device has both USB and Wi-Fi connectivity along with an active modding community that develops open source software for the camera. However, Check Point warns that not just this camera but any internet-connected digital camera could be vulnerable to ransomware attacks.

The researchers downloaded the firmware for the Canon camera and by using tools from the open source community, they were able to reverse engineer the code. They discovered several vulnerabilities including buffer flows that enabled code execution. This could be exploited to take control of a camera remotely using a malicious firmware update that would allow ransomware to be deployed.

This attack could also be executed through physical access to the camera via USB or by tricking a user into connecting to a rogue wireless network.

DSLR ransomware

In addition to the threat of having all of the photos stored on a device locked as a result of a ransomware attack, malware installed on a digital camera could also be used to launch other attacks.

Security researcher at Check Point, Eyal Itkin explained to ZDNet how a compromised camera could pose a serious risk to businesses, saying:

"Once compromised, the attacker has full control over the camera, and they could brick it, use it as an espionage tool, or ransomware it as we demonstrated. These vulnerabilities are critical and could cause major harm to any business or industry that relies on digital cameras." 

Since PTP is used by many different devices, it is also possible that other cameras could be impacted by similar attacks.

Check Point disclosed the vulnerabilities it found to Canon and the company has issued a security update for all of its devices. This attack method has yet to be used in the wild but Canon still recommends that all users apply the update.

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments