Malware Campaign Infects 40K+ Servers and IoT Devices - RTInsights

Malware Campaign Infects 40K+ Servers and IoT Devices

Malware Campaign Infects 40K+ Servers and IoT Devices

Researchers at Guardicore Labs have dubbed this malware attack as Operation Prowli.

Written By
Sue Walsh
Sue Walsh
Jun 22, 2018
2 minute read

Guardicore Labs researchers have discovered a new malicious campaign focused on monetizing rather than hacking has been discovered. The malware campaign, dubbed Operation Prowli, has infected over 40,000 IoT devices and servers.

It targets IoT devices, DSL modems, backup servers running HP Data Protector, and WordPress sites and forces them to conduct profit-making tasks like crypto mining and traffic-hijacking.

Cyber attackers guessed credentials and took advantage of known vulnerabilities. They used a variety of methods to monetize victims’ machines, employing digital currencies and traffic redirection.

Researchers say that these all too common traffic monetization frauds redirect website visitors from legitimate destinations to websites that advertise:

  • Malicious browser extensions
  • Tech support scam services
  • Fake services
  • Other phishing services

See also: Ixia sees malware clouds in the cloud in 2018

The researchers first discovered the campaign in April when they detected SSH attacks contacting a command and control server set up as a honeypot. They believe the campaign has been live since early 2018. The attacks apparently share identical behavior, connecting to the same C&C server and downloading the same attack tools and a cryptocurrency miner. They’ve detected attacks across several networks in multiple countries.

“Over a period of three weeks, we captured dozens of such attacks per day coming from over 180 IPs from a variety of countries and organizations,” researchers say. “These attacks led us to investigate the attackers’ infrastructure and discover a wide-ranging operation attacking multiple services.”

Researchers urge IoT device owners and those who use modems and servers to keep their firmware or software up to date and use strong passwords that they changed regularly.

Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

Smart Manufacturing Trends 2026: How AI, IoT, and Automation Are Driving Efficiency and Resilience
Is AI Compute Becoming the Next Bottleneck?
Akhil Verghese
Apr 20, 2026
Powering Smart Cities: Designing Rugged PoE for Outdoor and Industrial Edge Deployments
Jordan Smith
Apr 2, 2026
Securing Time Synchronization: The Overlooked Control in Modern Cybersecurity
Liz Ticong
Apr 2, 2026

Featured Resources from Cloud Data Insights

From “Stage” to “Screen”: The Real AI Opportunity Most Companies are Missing
Elliott Parker
May 1, 2026
Why AI Underperforms at Scale and What CIOs Must Fix First
Mike Meyer
Apr 30, 2026
The Next Phase of Drone Workflow Innovation is Happening After They Land
Dacoda Bartels
Apr 29, 2026
AI Agents Need More Than Models to Work in the Real World
Uri Knorovich
Apr 28, 2026
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.