Failing IoT Security Means Old Malware Makes IoT Comeback

The News: Failing IoT security means that old malware is making an IoT comeback. Conficker, a computer worm that first emerged in 2008 by proliferating Windows XP and older Microsoft operating systems and spread itself to vulnerable machines to rope them into a botnet, is making a comeback on IoT devices, and is specifically a threat to the healthcare industry via IoT connected medical devices. Even though it’s been 12 years, the Conficker malware remains an active threat as the new Unit 42 IoT Threat Report from Palo Alto Networks confirms.

Failing IoT Security Means Old Malware Makes IoT Comeback, Targets Healthcare

Analyst Take: There’s been a resurgence in Conficker infections, determined to be largely the fault of failing IoT security. Researchers have confirmed some 500,000 IoT connected machines and devices are infected, up 100,000 since 2015. The most attractive target for the Conficker malware? The healthcare field in general, and medical devices in particular. For instance, at one hospital mammography machines were discovered to be infected with the Conficker malware, which then migrated to other medical devices on the same network, which included a digital imaging unit, a radiology machine, and others. As reported by ZDNet, the IT team’s attempt to remove the infections amounted to rebooting the machines which was, not surprisingly, ineffective. Wondering why I titled the article “failing IoT security” … well, that’s it right there. ZDNet further reported that it took the hospital an entire week to take all the devices offline, install the latest security patches, and then reconnect the devices to the network.

The Problem Extends Beyond IoT Connected Devices, to the Healthcare Vertical Itself

With so much emphasis on cybersecurity today, it’s a bit alarming that a 12-year-old malware is becoming an issue again — but that’s part of the problem with IoT connected devices. Add to the complexity of the situation the fact that we’re dealing with COVID-19, and it’s even more alarming that the healthcare vertical is generally the primary target of cyberattackers — especially when having certain medical equipment up and running will be crucial for hospitals that may become overrun with patients.

As the ZDNet author points out, [and I agree] the main issue is that many of these IoT connected devices aren’t monitored like computers on a network, which in turn is making them a gateway for attacks. As mentioned in my previous post, IoT Cybersecurity Regulations Kick in With the Start of 2020, IoT-specific botnets like Mirai are an excellent example of this as they were penetrating IoT devices like DVRs and IP cameras.

Healthcare IT security leaders have their work cut out for them. In the 2019 Global State of Cybersecurity in Small and Medium-Sized Businesses from Keeper Security and conducted by the Ponemon Institute, more than half of healthcare organizations surveyed reported experiencing a cyberattack in the last year. More importantly, 87 percent of healthcare organizations report a lack of security personnel (and budget) for more effective security operations and 90 percent devote less than 20 percent of their IT budget to cypbersecurity.

That’s Why Network Slicing Capabilities Will Be Key

This is why the promise of network slicing capabilities will be key to IoT security, in the healthcare space and beyond. IoT devices can be segmented on a separate network than desktops and laptops and prevent the spread of malware. This creates traffic isolation and IoT devices can have its own resource (slice) with their own security mechanisms and policies. Each slice can have customized security functionality, such as firewall configurations, access policies, and packet inspection, for example. With network slicing, if attackers gain access to the IoT device from outside, they won’t be able to exploit it for moving onto the rest of an enterprise’s network.

Wrap up – Failing IoT Security Measures Aren’t Going to Cut It

The lesson here is that failing IoT security measures aren’t going to cut it in today’s internet-driven, everything connected world. IoT devices, in the healthcare world and elsewhere, must treated just as carefully as employee computers, servers, and other devices. They must be connected to network security, continuously monitored and scanned, maintained by way of security patches, and updated on a regular basis. That’s also where Security Information and Event Management (SIEM) software providers like Splunk, LogRhythm, Dell Technologies (RSA), Rapid7, Securonix, Exabeam, and IBM play a big role in helping enterprises develop their Security Operations Center (SOC). Security technology that augments your human workforce and helps them do their jobs more effectively can go a long way toward keeping companies safe—from malware like Conflicker and others to any number of cyber incidents that endanger the business. There should be no halfway measures here, in the healthcare industry or otherwise — security of IoT connected devices is too important to business operations and business continuity.

Futurum Research provides industry research and analysis. These columns are for educational purposes only and should not be considered in any way investment advice.

Read more Analysis from Futurum Research:

Cloudera Builds Momentum Into New Year With Solid Q4 Earnings 

Xerox Makes Another Run at Taking Over HP

NVIDIA Acquisition of SwiftStack Facilitates Cloud-to-Edge Data Management for AI and HPC

Image Credit: Forbes

Author Information

Sarah most recently served as the head of industry research for Oracle. Her experience working as a research director and analyst extends across multiple focus areas including AI, big data and analytics, cloud infrastructure and operations, OSS/BSS, customer experience, IoT, SDN/NFV, mobile enterprise, cable/MSO issues, and managed services. Sarah has also conducted primary research of the retail, banking, financial services, healthcare, higher ed, manufacturing, and insurance industries and her research has been cited by media such as Forbes, U.S. News & World Report, VentureBeat, ReCode, and various trade publications, such as eMarketer and The Financial Brand.

Related Insights
Exprivia Bets on Deepfake Detection to Win AI-Security Deals
September 16, 2026

Exprivia Bets on Deepfake Detection to Win AI-Security Deals

Exprivia's alliance with identifAI brings specialized deepfake detection capabilities to high-stakes verticals including banking, healthcare, and public administration, capitalizing on explosive growth in AI software and cybersecurity channels....
Rubrik's MCP Launch Bets on Agentic AI as Cyber Resilience's Next Layer
September 16, 2026

Rubrik's MCP Launch Bets on Agentic AI as Cyber Resilience's Next Layer

Rubrik announced MCP support powered by Claude, enabling enterprise AI agents secure access to Rubrik Security Cloud for machine-speed incident response....
Scalian Completes Skills & Affinity Integration to Build Sovereign-Engineering Scale
September 16, 2026

Scalian Completes Skills & Affinity Integration to Build Sovereign-Engineering Scale

Scalian has completed the brand integration of Skills & Affinity, finalizing a 2025 acquisition sequence that positions the company as a reference actor in sovereign engineering with €550M revenue and...
Thales Embeds Cyber Defense Into Vietnam's Aviation Growth Story
September 15, 2026

Thales Embeds Cyber Defense Into Vietnam's Aviation Growth Story

Thales elevates its role from component supplier to strategic digital transformation partner in Vietnam's aviation sector through dual agreements with Vietjet covering MRO services, cybersecurity, and AI capabilities....
CISA and G7 Make PQC Transition an Immediate Imperative
September 11, 2026

CISA and G7 Make PQC Transition an Immediate Imperative

CISA and the G7 prioritize post-quantum cryptography now, not later. Red River's Quantum Cryptography Accelerator directly addresses their five key areas and counters the "harvest now, decrypt later" threat....
Exprivia Bets on Risk Management as Cybersecurity's Next Frontier
September 10, 2026

Exprivia Bets on Risk Management as Cybersecurity’s Next Frontier

Exprivia pivots from reactive cyberattack response to proactive risk management, positioning itself to capture significant market share as 62.4% of channel partners cite cybersecurity as a top 2026 growth driver....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.