
Torch Light System Uncovers Real-World Attacks on IoT Devices via Tor Network Traffic Analysis
Researchers from Southeast University and collaborating institutions presented Torch Light, a system designed to analyze Tor network traffic and uncover real-world attacks on cloudless IoT devices. Over 12 months, they deployed three Tor exit routers in Las Vegas, New York, and Miami, collecting 26 terabytes of traffic and identifying 45 vulnerabilities, including 29 zero-day exploits with 25 assigned CVEs, affecting approximately 12 million devices globally. The system leveraged an ARM-based traffic analyzer with a five-step 'chainsaw' process to filter IoT-specific protocols (HTTP, RTSP, FTP, Telnet), detect malicious payloads, and classify attacks like command injection, password traversal, and information disclosure. Findings revealed that 90% of targeted devices were DVRs and cameras, with Asia hosting 53% of vulnerable devices and attackers using device-specific credentials and reconnaissance tactics. The research triggered vendor responses, including firmware patches and CISA listings for three vulnerabilities, while also exposing a malware operation (Marie Vind) exploiting these flaws to build a DDoS botnet. Ethical considerations were addressed, including anonymized data handling and consultation with a Tor research safety board. The team released their methodology, prompts, and code for further research.