logo

12 Years Later: Common Configuration Flaw + Internet of Things = Massive Attacks

ID: d92e8ee5-9428-5c28-8458-0612ef34053e

STIX ID: report--d92e8ee5-9428-5c28-8458-0612ef34053e

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2016-10-12

Date Updated: 2026-05-06

Author: Paul Roberts

...
...

Akamai researchers discovered SSHowDowN, a large-scale campaign abusing enabled SSH TCP port forwarding and default credentials on millions of IoT devices (cameras, NVRs, NAS, routers, etc.) to proxy credential-stuffing attacks against many websites; the campaign uses single-use devices and careful round-robin load balancing rather than traditional persistent bot binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.