MilikMilik

AI-Powered IoT Devices Are Becoming Prime Botnet Targets—Here’s How to Protect Yours

AI-Powered IoT Devices Are Becoming Prime Botnet Targets—Here’s How to Protect Yours
Interest|Home Networking Setup

What AI-Powered IoT Devices Are—and Why Botnets Want Them

AI-powered IoT devices are connected gadgets, such as routers, cameras, and smart sensors, that use artificial intelligence locally to analyze data, make decisions, and interact with other systems without constant cloud access, which also makes them attractive and valuable targets for cybercriminal botnets seeking processing power and deep network visibility. As IoT hardware gains neural processing units and runs edge AI or TinyML, each device becomes closer to a small server than a simple sensor. This extra power lets it process video, audio, and operational data in real time, improving convenience and automation at home and in small offices. The same capabilities give attackers more CPU, bandwidth, and storage to work with after compromise. Combined with the fact that many IoT products ship with weak default security and rarely updated firmware, AI IoT security is quickly becoming one of the most important parts of smart device ownership.

AI-Powered IoT Devices Are Becoming Prime Botnet Targets—Here’s How to Protect Yours

From 650 to 1,500 Devices: What Expanding Botnets Reveal

Recent botnet campaigns show how fast attackers can compromise connected hardware. The JDY botnet, linked to state-sponsored operators, grew from about 650 bots in early January 2024 to more than 1,500 compromised SOHO and IoT devices in a short time. Security researchers describe JDY as a centrally controlled, high-performance scanner that discovers and fingerprints exposed services at scale, then feeds structured reconnaissance data into a larger scanning and exploitation ecosystem. Devices from brands like Araknis, Ubiquiti, Hikvision, and Linksys have all appeared in its population. JDY is used for targeted scanning instead of noisy, indiscriminate sweeps, helping it evade geofencing, IP blocklists, and reputation filters. In parallel, the Aisuru botnet enlisted about 500,000 compromised IoT devices for a massive DDoS attack and used AI for reconnaissance, showing how botnet IoT devices can adapt and grow faster than traditional defenses.

How AI Models on IoT Devices Can Be Twisted Against You

AI models running inside smart cameras, thermostats, and gateways create new smart device security risks that go beyond basic malware. Instead of only joining a botnet, a compromised AI-enabled endpoint can map your network, identify valuable systems, and automate the early stages of an intrusion. Attackers can tamper with local models so that video analytics ignore certain motion, or safety systems misclassify faults, changing real-world decisions. Since many edge nodes sit in exposed locations, they are easier to probe for physical access, adversarial AI attacks, and firmware extraction. The large volumes of data they collect—especially in sectors like healthcare, manufacturing, and energy—are attractive for theft or extortion. When an attacker can both read the data stream and influence the model’s outputs, AI IoT security failures turn into a mix of data exfiltration, quiet surveillance, and subtle sabotage that is hard for owners to spot.

Why Traditional IoT Vulnerabilities Make AI Devices Even Riskier

Many classic weaknesses in IoT vulnerability protection remain unsolved, and they amplify the impact when AI is added on top. Large studies estimate that 98% of IoT device traffic is still unencrypted, making it easy for attackers to monitor or brute-force weak services. Enterprises have seen around 820,000 attacks on IoT devices per day, with visibility gaps across tens of thousands of managed and unmanaged endpoints. Poor network segmentation is common; more than three-quarters of networks lack proper separation, so low-security devices like thermostats often sit on the same flat network as business systems. When these poorly protected devices also run local AI workloads, a single breach can expose sensitive data and give an intruder a powerful foothold. The expansion of advanced botnets such as JDY and Aisuru shows that attackers are already exploiting these long-standing IoT flaws at large scale.

Practical Steps Consumers Can Take to Secure AI IoT Devices

Consumers can sharply reduce botnet and smart device security risks with a few clear steps. First, change default passwords on every router, camera, and smart hub; use long, unique passphrases and turn on multi-factor authentication when the device or cloud account supports it. Second, enable automatic firmware updates so critical security patches arrive quickly, and remove devices that no longer receive updates. Third, segment your home or small office network: place IoT gadgets on a separate guest or IoT VLAN so they cannot directly reach laptops or workstations if compromised. Fourth, disable unused remote access features and UPnP, and close ports you do not need. Finally, monitor your router for unknown devices and unusual outbound traffic. Treat each AI-enabled endpoint as a full computer on your network, not an appliance, and your AI IoT security posture will be far stronger.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!