HomeCyber SoapboxWhy legacy systems are a goldmine for botnet attacks

Why legacy systems are a goldmine for botnet attacks

NetworkTigers examines how legacy systems provide a low-effort, high-reward opportunity for botnet operators to compromise networks using outdated, under-monitored devices.

Ransomware, malware, phishing scams, and identity theft may capture the most headlines among cybersecurity news outlets, but botnets remain an ever-present and silent threat due to the ease with which hackers can create them using legacy systems, old devices, and Internet-of-Things (IoT) components.

Imperva’s annual Bad Bot Report indicates that almost half of all Internet traffic is botnet-generated, with one-third of global traffic associated with malicious programs. 

What are botnets?

Palo Alto Networks defines a botnet as “a network of computers infected by malware that is under the control of a single attacking party, known as the ‘bot herder.’ Each machine controlled by the bot herder or botmaster is known as a bot.”

An attacker can then carry out large-scale activities by commanding all of the devices under their control to generate Distributed Denial of Service (DDoS) attacks, deliver vast amounts of spam email or phishing messages, steal user data, or mine cryptocurrency without the knowledge or consent of the device’s owner. 

Botnets can evolve, change their purpose, and grow or shrink based on the desires of the entity operating them. This malleability means they remain dangerous and effective even as security protocols and attack objectives change. 

Why do botnets favor legacy systems?

For a botnet to be effective, it must control many devices that can operate simultaneously and are easily compromised. Modern technology is rarely targeted because improved security features and advanced malware detection make newer systems harder to breach. On the other hand, older devices often lack these protections, making them prime candidates for exploitation.

Outdated security patches

Administrators often neglect legacy systems when it comes to updating their software or firmware. This can be due to budget issues, a lack of expertise, or the false perception that a small network is unlikely to catch the eye of a criminal operation. Small businesses are often guilty of not keeping up with security standards. 

These networks are ideal for botnet attackers, who can exploit poor security hygiene to quietly pull inadequately protected devices into their botnets without the user ever knowing.

Readily available exploits

The internet is full of data related to legacy equipment users can tap into to troubleshoot, modify, or otherwise use for legitimate purposes. However, there are also platforms and forums that criminals frequent to share well-documented exploits, hacking instructions, and guides that make it simple for them to carry out illegal activities. 

The longer a piece of hardware is on the market, the easier for attackers to find out how to manipulate it with a simple Google search.

End-of-Life hardware and software

Legacy systems may have components no longer supported by their manufacturers, meaning that they are no longer updated for the future or patched if an exploit becomes known. End-of-Life (EOL) devices used by organizations result in a generous platform that attackers can use to build their botnets, mainly since companies utilize large numbers of identical units.

For example, Edimax IC-7100 network cameras were recently identified as vectors for the notorious Mirai botnet. These cameras are no longer supported by the manufacturer, having been discontinued over a decade ago, but their continued implementation makes them prime targets for botnets.

End-of-life routers are also often abused because, much like the cameras, routers are often installed and neglected as long as they function adequately. Many organizations may not even be aware that the devices they depend on are due for total replacement. 

This danger is not exclusive to hardware. Old operating systems are also prone to attack, and there is a thriving online community more than willing to share the details and instructions needed to infect them with malware or exploit bugs that could be years old. 

Poor network segmentation

The low processing power of legacy systems might make some users feel that they aren’t valuable to cybercriminals in the first place. However, they are often still connected to the network as a whole without proper segmentation. Attackers know this and can use the successful breach of a legacy system to then move within an organization’s broader network to ensnare more devices that may be vulnerable or otherwise cause harm.

Lack of monitoring

Legacy systems generally do not have the monitoring capabilities that newer ones do, and therefore tend to work in the background with little supervision.

This opens the door for criminals who take advantage of this lack of insight to set up shop. Devices that don’t get a lot of attention from administrators are sure to get it from attackers who can scan for opportunities to use them as part of a botnet.

How to protect your network from botnets

While the use of legacy systems will always open networks to exploits that can’t be updated or patched away, the reality is that not every organization or user has the funds, expertise, or desire to keep every facet of their network up to modern standards.

Change default passwords

Many devices, particularly routers, come from the factory with a pre-installed password used for setup. Hackers maintain and curate lists of these manufacturer passwords, knowing many users will use them indefinitely.

An old piece of hardware that is no longer updated and still uses a default password is highly vulnerable to attack.

Replace old hardware with newer gear

The most effective way to protect a network from legacy exploits is to simply replace the old hardware with equipment that is still receiving updates. However, this doesn’t mean spending vast sums on the latest and greatest gear. 

Used and refurbished routers, firewalls, switches, and any network equipment still supported with updates and patches can be purchased at deep discounts.

Segment legacy systems

Ideally, legacy systems should be replaced. If that is not possible, they should be isolated from the rest of the network via firewalls to contain potential infections. These systems should also have their internet and external network connections limited.

Monitor traffic

Don’t turn your back on a legacy system’s traffic. Monitor its activity as you would your primary network, so you can act swiftly if anything suspicious is detected.

Decommission hardware that is no longer needed

Some networks and systems are rife with old hardware that is still connected but no longer needed. Streamline your infrastructure by identifying devices that are no longer supported and might no longer be functionally required. See if a more current hardware option can perform tasks previously undertaken by multiple legacy devices and take potentially hazardous routers, cameras, servers, and computers out of the equation.

Be sure to delete old accounts that are no longer in use, and be sure that devices such as company phones and computers that are not in use cannot connect to your network, should they be stolen.

About NetworkTigers

NetworkTigers logo

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, which built and re-architected data centers for Fortune 500 firms, NetworkTigers provides consulting and network equipment to global governmental agencies, Fortune 2000, and healthcare companies. www.networktigers.com.

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles