Security researchers offer proof-of-concept of first ransomware for a thermostat

Posted on Monday, August 08 2016 @ 13:55 CEST by Thomas De Maesschalck
One of the dangers of the Internet of Things is that we're going to see a big rise in security issues as many devices do not have good security. Last weekend, security researchers Andrew Tierney and Ken Munro demonstrated what could go wrong by creating the first piece of ransomware that targets "smart" thermostats.

The hackers found a vulnerability in the thermostat and exploited it to install a piece of software that locks the thermostat and demands money to hand back control to the user. The attack wasn't very advanced, it requires the user to download a file to the thermostat, but it's not unthinkable that more advanced attacks on smart devices will start showing up in the near future.
The thermostat in question has a large LCD display, runs the operating system Linux, and has an SD card that allows users to load custom settings or wallpapers. The researchers found that the thermostat didn’t really check what kind of files it was running and executing. In theory, this would allow a malicious hacker to hide malware into an application or what looks like a picture and trick users to transfer it on the thermostat, making it run automatically. At that point, an evil hacker would have full control of the thermostat, the researchers said.
Full details at Vice.

Thermostat hacking


About the Author

Thomas De Maesschalck

Thomas has been messing with computer since early childhood and firmly believes the Internet is the best thing since sliced bread. Enjoys playing with new tech, is fascinated by science, and passionate about financial markets. When not behind a computer, he can be found with running shoes on or lifting heavy weights in the weight room.



Loading Comments