Skip to main navigation Skip to search Skip to main content

Turbulence: Ransomware Proof of Concept for Resource-Constrained IoT Devices

Calvin Brierley, Yuxiang Huang, Yichao Wang, James Pope, George Oikonomou, Budi Arief

Research output: Chapter in Book/Report/Conference proceedingConference Contribution (Conference Proceeding)

Abstract

The ``Internet of Things'' (IoT) is a term used to describe smart devices that are capable of connecting to a network. IoT devices can take many forms, such as cameras, televisions, or home assistants, and are often designed to perform specific tasks. While they only require limited processing power to achieve their intended purpose, their connected nature means they are still vulnerable to attack. Most IoT-based malware is designed to infect devices using General Purpose Operating Systems, such as Linux. Malware targeting ``constrained'' IoT devices, which have lower hardware specifications and implement bare-metal firmware or a Real Time Operating System, are significantly less common, as they present a number of challenges that can hinder malware development. In this work, we identify these challenges and assess the viability of implementing functional ransomware that targets constrained IoT devices. We then test our findings by developing a ransomware Proof of Concept capable of locking a target system and spreading throughout a network. Finally, we analyse the ransomware's performance against an intentionally vulnerable testbed to identify the requirements and limitations of -- as well as potential countermeasures against -- ransomware targeting constrained IoT devices.
Original languageEnglish
Title of host publication2026 23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment
Subtitle of host publicationDIMVA 2026
PublisherSpringer
Publication statusAccepted/In press - 16 Feb 2026
Event23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment - Chania, Greece
Duration: 1 Jul 20263 Jul 2026
Conference number: 23rd
https://www.dimva.org/dimva2026/

Publication series

NameDIMVA: International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment
PublisherSpringer
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment
Abbreviated titleDIVMA 2026
Country/TerritoryGreece
CityChania
Period1/07/263/07/26
Internet address

Research Groups and Themes

  • Intelligent Systems Laboratory
  • Communication Systems and Networks

Fingerprint

Dive into the research topics of 'Turbulence: Ransomware Proof of Concept for Resource-Constrained IoT Devices'. Together they form a unique fingerprint.

Cite this