In the digital graveyard, a new threat stirs: Out-of-support devices becoming thralls of malicious actors
Outdated devices are often easy targets for attackers, especially if they have vulnerabilities that can be exploited and no patches are available due to their end-of-life status.
Hacks of outdated or vulnerable devices are an issue, but why would anyone attempt to hack discontinued devices or those running out-of-support software? To gain control? To spy on people? The answer is quite multifaceted.
The end of life is coming — for your device
There comes a time when a device becomes obsolete, be it because it gets too slow, the owner buys a new one, or it lacks functionalities compared to its modern replacement, with the manufacturer shifting focus to a new model and designating the old one as end of life (EOL).
At this stage, manufacturers stop the marketing, selling, or provisioning of parts, services, or software updates for the product. This can mean many things, but from our standpoint, it means that device security is no longer being properly maintained, making the end user vulnerable.
After support has ended, cybercriminals can start gaining the upper hand. Devices such as cameras, teleconferencing systems, routers, and smart locks have operating systems or firmware that, once obsolete, no longer receive security updates, leaving the door open to hacking or other misuse.
In 2024 estimates said that there were around 17 billion IoT devices in the world – from door cameras to smart TVs – and this number keeps increasing. Suppose that just a third of them become obsolete in five years. That would mean that a bit over 5.6 billion devices could become vulnerable to exploitation – not right away, but as support dries up, the likelihood would increase.
Very often, these vulnerable devices can end up as parts of a botnet – a network of devices turned into zombies under a hacker’s command to do their bidding.
One person’s trash is another’s treasure.
A good example of a botnet exploiting outdated and vulnerable IoT devices was Mozi. This botnet was infamous for having hijacked hundreds of thousands of internet-connected devices each year. Once compromised, these devices were used for various malicious activities, including data theft and delivering malware payloads.
Exploitation of vulnerabilities in a device like an IoT video camera could enable an attacker to use it as a surveillance tool and snoop on you and your family. Remote attackers could take over vulnerable, internet-connected cameras, once their IP addresses are discovered, without having had previous access to the camera or knowing its login credentials.
Why would someone use an out-of-date device that even the manufacturer deems unsupported? Be it either lack of awareness or unwillingness to purchase an up-to-date product, the reasons can be many and understandable. However, that does not mean that these devices should be kept in use — especially when they stop receiving security updates.
Alternatively, why not give them a new purpose?
Old device, new purpose
A new trend has emerged due to the abundance of IoT devices in our midst: the reuse of old devices for new purposes. For example, turning your old iPad into a smart home controller, or using an old phone as a digital photo frame or as a car’s GPS. The possibilities are numerous, but security should still be kept in mind – these electronics should not be connected to the internet due to their vulnerable nature.
