IoT and OT malware saw a huge rise in 2023

DDOS Attack code concept art
(Image credit: Shutterstock / DaLiu)

Malware attacks against Internet of Things (IoT) and Operational Technology (OT) devices have increased four-fold in a year as criminals demonstrate persistence and the ability to adapt to evolving conditions, new research has claimed.

The ZscalerTM ThreatLabz 2023 Enterprise IoT and OT Threat Report, based on an analysis of some 300,000 blocked attacks on IoT devices in a six-month period, shows just how relentless cyberspace threat actors are.

As per the report, the attackers are going mostly for legacy vulnerabilities. Out of the 39 most popular IoT exploits, 34 abused flaws that have existed in these devices for at least three years. In two-thirds of all attacks (66%), the threat actors would try to deploy Mirai and Gafgyt, popular malware families that assimilate vulnerable devices into a botnet which can later be used for distributed denial of service (DDoS) attacks. 

Manufacturing and retail

Botnet-driven DDoS attacks cause “billions of dollars” in financial losses across industries, around the world, the report claims. Furthermore, by DDoSing OT devices, critical industrial processes can be disrupted, possibly even putting human lives at risk.

More than half of IoT device traffic comes from manufacturing and retail companies (52%), with 3D printers, geolocation trackers, industrial control devices, automotive multimedia systems, data collection terminals, and payment terminals sending the majority of signals over digital networks. 

At the same time, the manufacturing sector experiences 6,000 IoT malware attacks every week, on average. Another sector that can’t catch its breath due to a constant barrage of malware attacks is education. This is mostly because the education industry stores vast amounts of sensitive information that cybercriminals can leverage in different ways. IoT malware attacks in the education sector increased by nearly 1000%, the report claims.

Most infections for the year - 46% - happened in Mexico, followed by Brazil and Colombia (in no particular order). Almost all of the IoT malware (96%) is distributed from compromised IoT devices in the United States.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Android phone malware
Over 25 new malware variants created every single hour as smart device cyberattacks more than double in 2024
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
IoT’s botnet problem is up 500% – three things admins must do now
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Industrial routers are being hit by zero-days from new Mirai botnets
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Dangerous new botnet targets webcams, routers across the world
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
Android Auto
Android Auto 14.0 is rolling out now – and it'll soon swap Google Assistant for the smarter Gemini
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update