The Ransomware That Beat EDR by Hiding in a Webcam

Endpoint protection only covers the devices that can run an agent. In a 2024 ransomware attack documented by the incident response firm S-RM, that gap is the reason the attackers succeeded.

The victim had EDR deployed, and it worked: the tool caught and quarantined the ransomware group Akira’s encryptor on a Windows server. The attackers then found a vulnerable webcam on the same network with no agent and no monitoring, and encrypted the organization’s file shares from it. Below is the full attack chain, followed by where Asimily’s IoT visibility and segmentation would have stopped the attack.

The Breakdown: How The Attacker Pivoted Their Attack Vector

Detailed in a report from incident response firm S-RM, Akira gained initial access to the network through an externally facing remote access solution. From there, the group deployed a legitimate remote monitoring tool to maintain access and began exfiltrating data, a standard practice for the group. Later in the attack, Akira moved laterally to a Windows server via RDP, blending in with legitimate system-administrator traffic, and attempted to deploy their ransomware binary as a password-protected zip file.

The organization’s EDR tool caught it immediately. The malicious archive was identified and quarantined before it could be unzipped and executed. By most measures, the defense worked exactly as intended.

Akira did not stop there. Before the failed deployment, the group had already run an internal network scan and found several IoT assets on the network, including webcams and a fingerprint scanner. One webcam in particular stood out as a target that carried critical vulnerabilities, including remote shell access and unauthorized remote viewing. This webcam ran a lightweight Linux operating system that could execute commands like any standard Linux host, and it had no EDR installed, as is common for IoT assets that often cannot be scanned by traditional EDR tools. Given its limited onboard storage, it likely could not have run EDR at all.

Akira compromised the webcam, deployed its Linux ransomware variant from it, and used Server Message Block (SMB) traffic from the camera to reach the same server the EDR tool had just defended. Because nobody was monitoring traffic from the webcam, the surge in SMB activity went unnoticed. Files across the network were encrypted from a device nobody was watching.

The Uncomfortable Takeaway

The EDR tool did its job. The attacker simply moved laterally to a device that could never support EDR scanning. Every dollar spent hardening the endpoint layer was real money spent on real protection, and it was still not enough, because the attacker only needed one asset the organization was not monitoring.

Why the Camera Was the Perfect Target

Three things made the webcam a better ransomware launchpad than any laptop on the network.

  • It was vulnerable: Remote shell access and unauthorized remote viewing were both present and unaddressed, almost certainly running default or weak credentials.
  • It could run the attacker’s tools: A lightweight embedded Linux OS meant Akira’s Linux ransomware variant ran on it exactly as it would on any Linux server.
  • It was invisible: No EDR, no agent, no monitoring, and functionally no way to install any of them given the device’s hardware constraints.

None of this is unique to one camera or one incident. This describes the default state of most IoT, OT, and IoMT assets on organizations’ networks today, and it is exactly the gap Asimily exists to close.

With Asimily, the organization could have:

  • Identified any asset using Remote Desktop Protocol (RDP): Asimily can identify and prioritize for remediation any devices using RDP based on exposure likelihood – which would have blocked the attack path Akira used to compromise the device.
  • Monitored RDP: Asimily can monitor RDP or any protocol for behaviors that show a potential breach and mitigate risk before the bad actor executes their ransomware.
  • Patch and Change Passwords for IoT Devices: Asimily supports IoT patching for security cameras via manufacturer-released and validated patches,  and manages device passwords to ensure default credentials are not used.

Where Asimily Closes Each Gap

Asset Inventory & Visibility that finds the camera before an attacker does. Asimily discovers and profiles every connected asset across IoT, OT, IoMT, and IT through passive monitoring and active safe scanning where appropriate. The webcam and the fingerprint scanner in this incident would have appeared in Asimily’s inventory from day one, with their manufacturer, firmware version, open ports, and known vulnerabilities documented automatically, not discovered by an attacker’s network scan first.

ATT&CK Analysis flags exactly this kind of device as high risk and potential high impact. A camera with remote shell access, unauthorized remote viewing, and no way to run an agent is precisely the profile Asimily’s ATT&CK Analysis is built to catch. It determines whether a vulnerability is actually exploitable on a specific device given its firmware and its place in the network, and a device with confirmed remote code execution capability and zero endpoint protection would sit at the very top of that ranked list, not buried in a severity score that treats it the same as any other asset.

IoT Patching and password management close the door before it opens. For supported device types, Asimily’s IoT Patching capability directly remediates firmware vulnerabilities and default or weak credentials, the exact combination that made this camera exploitable in the first place. Default and outdated credentials on IoT devices are one of the most common findings across connected device fleets, and they are also one of the most fixable, once a platform can see the device and act on it.

Behavioral monitoring would have caught the SMB surge. Asimily continuously baselines normal communication behavior for every device type and flags deviations in real time. A webcam suddenly generating SMB traffic to a production server is exactly the kind of anomaly that should never go unnoticed, and in this incident, it was the one thing nobody was watching.

Segmentation Orchestration removes the path entirely. Even if the camera had been compromised, Segmentation Orchestration would have restricted lateral movement. Policy Auto-Recommendation generates policy from how a device actually behaves; a camera has no legitimate reason to communicate with a file server over SMB, and Policy Simulation proves that restriction is safe before it is ever enforced. Continuous Segmentation keeps that boundary current as the network changes. The attacker’s path from camera to server simply would not have existed.

What This Says About the Need for a Proactive Cyber Asset Defense Platform

Most connected device security conversations focus on visibility, and visibility matters. But this incident shows why visibility alone is not the finish line. The organization in this story almost certainly had some form of asset inventory, but they lacked a way to determine if that one specific camera was exploitable, fix the credentials and firmware that made it exploitable, watch its behavior for anomalies, or contain it if all of that failed. Asimily is built to do all four, not as separate tools but as one continuous chain from discovery to enforcement – for the devices EDR cannot reach.

See This on Your Own Network

Every organization has cameras, badge readers, and building systems that look exactly like this webcam did: functional, forgotten, and never assessed. See what Asimily finds on your network in a custom demo, and discover what it would take to close the same gap Akira found here.

Secure Every IoT Device.
Automatically.

Cyber threats move fast — so should you. Asimily gives instant inventory and smart, prioritized risk mitigation insights for every IoT, OT, and IoMT device — so you can take action before threats strike.