Ballooning botnet suspected to be a cyberespionage op
A rapidly swelling botnet capturing internet of things devices across the globe may be a front for foreign cyberespionage operations.
Infected equipment show signs of malware that researchers codenamed PolarEdge, software that targets many different types of enterprise-class edge devices and consumer-grade IoT gear.
Attackers appeared to begin wielding PowerEdge in June 2023, with around 150 devices worldwide initially falling victim. That number snowballed to nearly 40,000 devices – 52% in South Korea and 21% in the United States – as of Aug. 5, says threat intelligence firm Censys. The geographic concentrations may be a function of attackers targeting device types commonly used by internet service providers in those regions.
Read more at Gov Info Security