Botnet accidentally overwhelmed the I2P anonymity network

The encrypted, decentralised I2P network has seen widespread disruption over the past week, coinciding with a surge in activity from the Kimwolf IoT botnet. The botnet's operators began routing large volumes of traffic through I2P to keep their command-and-control infrastructure out of reach of takedown efforts. When users reported outages and speculated about an attack on the network itself, the operators acknowledged on their own Discord server that they had loaded 700,000 bots to connect over it. The influx overwhelmed I2P and produced an effect resembling a Sybil attack, in which a single actor controls a disproportionate share of the nodes.

What this means for your organisation

The story says little about I2P and a great deal about how many unsecured devices a single actor can command. Cameras, routers and other connected equipment on your own premises can be part of such botnets without anyone noticing. The direct consequence for you is rarely dramatic, but it is equipment on your network taking orders from someone else.

Berigo recommends

  • Build an inventory of connected devices that are not PCs, servers or phones, including equipment installed by suppliers.
  • Segment that equipment away from the office network and limit what it is allowed to reach.
  • Change factory-set passwords and disable remote administration that is not in use.
  • Monitor outbound traffic from these devices; abnormal volume is often the first sign.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch