Malware infections on IoT devices surged 100% in a year, with these internet-connected devices now comprising about 33% of infected devices compared to about 16% in 2019, according to Nokia’s 2020 Threat Intelligence Report.
The annual report monitors malware activity in mobile and fixed networks globally based on service providers’ networks that deployed Nokia’s NetGuard Endpoint Security product. Nokia says this product monitors network traffic from more than 150 million devices.
The 2020 report, which monitored traffic from October 2019 through June 2020, found the average monthly infection rate in mobile networks was 0.23%. It peaked in February and March, with infected devices increasing by almost 30% as attackers launched COVID-19-themed campaigns.
Nokia Tracks COVID-19 Malware StrainsSome of the COVID-19-specific malware strains include CoViper, which looks like a coronavirus-relate file but it’s actually a wiper, which breaks an infected device’s boot operation by rewriting the master boot record. There’s also Trojan malware disguised as a coronavirus map that targets Windows platforms, and COVIDLock Android app that claims to track positive cases but in reality is ransomware.
Despite the COVID-19 boost, the overall 2020 infection percentage in mobile networks decreased compared to previous years. Nokia attributes this to better security in official mobile app stores. And, perhaps self-servingly, to a growing number of service providers networks using its endpoint security product.
While mobile networks saw a COVID-19 malware spike in February and March, fixed broadband networks, however, felt the impact later in May and June. The average monthly infection rate in these fixed networks was 2.16%, which is also down overall compared to 2019.
Android Devices Still Biggest TargetsAs more IoT devices connect to mobile networks, Nokia reports that infections in those devices is becoming increasingly common. Similar to previous years, Android devices remain the most common malware targets responsible for about 27% of all infections. However, this is down from 47% last year. Nokia attributes this drop in part to improved security in these devices, adding “it is mostly the result of the increase in IoT-related infections.”
The 2020 report also found that Windows/PCs are responsible for about 39% of all infections, which is up from 36% in 2019.
Nokia expects this trend to continue in 2021 as network operators deploy more 5G networks globally and more IoT devices connect to these networks. “The sweeping changes that are taking place in the 5G ecosystem, with even more 5G networks being deployed around the world as we move to 2021, open ample opportunities for malicious actors to take advantage of vulnerabilities in IoT devices,” said Bhaskar Gorti, Nokia software president and chief digital officer, said in a statement. “This report reinforces not only the critical need for consumers and enterprises to step up their own cyber protection practices, but for IoT device producers to do the same.”
Also to this end, Nokia last year opened a security testing and verification lab and launched a program to address 5G WAN security needs.
Comments