TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
Yumingzhi Pan (Southeast University)
34th USENIX Security Symposium (USENIX Security '25) · Day 1 · System Security 2: Trusted and Robust Computing
Overview
The internet of things (IoT) has rapidly expanded, bringing convenience but also a vast attack surface. While many IoT devices rely on cloud services, a significant category, termed cloudless IoT devices such as network video recorders (NVRs) and digital video recorders (DVRs), are directly exposed to the internet. This direct exposure, intended to give users more control and reduce privacy concerns associated with cloud providers, inadvertently makes them prime targets for cyberattacks. This talk, presented by Yumingzhi Pan from Southeast University, delves into a particularly concerning aspect of this threat landscape: the use of the Tor network by malicious actors to anonymize their exploitation attempts against these vulnerable cloudless IoT devices.

Key moments
- 0:00 Cloudless IoT and Tor: The problem statement
- 2:00 Real-world examples of zero-day IoT attacks
- 3:00 Ethical considerations: The "Tory problem" in research
- 3:28 Introducing Torchlight: Their system for attack analysis
- 5:36 ARM-based IoT Traffic Analyzer: 5-step attack detection
- 7:00 Command Injection Detection: Example and detailed analysis
- 7:50 Evaluation results: Targeted devices and attack types
TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
Speakers: Yumingzhi Pan
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=LKMBS1-CCkg
Overview
The internet of things (IoT) has rapidly expanded, bringing convenience but also a vast attack surface. While many IoT devices rely on cloud services, a significant category, termed cloudless IoT devices such as network video recorders (NVRs) and digital video recorders (DVRs), are directly exposed to the internet. This direct exposure, intended to give users more control and reduce privacy concerns associated with cloud providers, inadvertently makes them prime targets for cyberattacks. This talk, presented by Yumingzhi Pan from Southeast University, delves into a particularly concerning aspect of this threat landscape: the use of the Tor network by malicious actors to anonymize their exploitation attempts against these vulnerable cloudless IoT devices.
The research uncovers a critical, previously underexplored dimension of IoT security. By strategically monitoring Tor exit nodes, the TORCHLIGHT project has provided the first concrete evidence that attackers are systematically leveraging Tor's anonymity to launch sophisticated attacks, including the exploitation of zero-day vulnerabilities. This not only highlights a significant gap in current IoT defense strategies but also raises complex ethical considerations regarding the monitoring of anonymous networks for public safety. The findings are a stark warning to device manufacturers, users, and security professionals about the active and clandestine nature of these threats, emphasizing the urgent need for proactive defense mechanisms.
Background
▶ Watch: Cloudless IoT and Tor: The problem statement (0:00)
To appreciate the gravity of the TORCHLIGHT research, it's essential to understand the architectural distinctions of IoT devices and the operational principles of the Tor network. Traditionally, many IoT devices, often with limited processing capabilities and situated behind network address translation (NAT) firewalls, are cloud-centric. They depend on cloud servers for communication, data processing, and remote access. In contrast, cloudless IoT devices—such as IP cameras, NVRs, and DVRs—are designed to be directly accessible from the internet. This architecture offers users greater autonomy and bypasses potential privacy issues associated with third-party cloud providers, but it simultaneously exposes these devices to the full spectrum of internet-borne threats.
The Tor network (The Onion Router) is a globally distributed system designed for anonymous communication. It operates by routing internet traffic through a series of volunteer-operated relays, encrypting it at each step (the "onion" layers) to conceal the user's IP address and location. Tor traffic is broadly categorized into two types: internal traffic, which flows between Tor relays and is fully encrypted, and external traffic, which originates from a Tor exit router and travels to its final destination server. Crucially, this external traffic is no longer protected by Tor's encryption, making it visible to the exit node operator. The initial observation that sparked this research was the detection of unusual IoT-related traffic traversing Tor exit routers. The fundamental question was: Why would a legitimate user require the anonymity of Tor to access their own IoT devices?
Further investigation into this traffic revealed a disturbing reality: attackers were actively exploiting Tor's anonymity to launch targeted attacks, often leveraging zero-day vulnerabilities, against cloudless IoT devices. The researchers provided real-world examples from their monitored exit routers. One instance showed a request exploiting a zero-day information disclosure vulnerability, exposing credentials in plaintext along with the device model. Another example involved an attacker attempting to exploit a zero-day command injection vulnerability to deploy a PHP backdoor. These findings underscored the potential for Tor exit nodes to serve as invaluable vantage points for uncovering actively exploited vulnerabilities.
The ethical considerations of this research were carefully addressed. While the Institutional Review Board (IRB) deemed the study not human subject research, the team took extensive precautions given the analysis of real-world data. Data was kept confidential and secure, and Tor's inherent anonymity mechanisms ensured that no personal identifying information (PII) was analyzed or compromised. However, the researchers acknowledge the inherent "Troy problem" – while analyzing Tor traffic offers significant security benefits (responsible disclosure, intrusion detection), it requires careful navigation of a system designed for privacy. They recommend that future researchers consult a Tor research safety board when planning similar studies to ensure ethical guidelines are rigorously met.
Key Findings
▶ Watch: Ethical considerations: The "Tory problem" in research (3:00)
The TORCHLIGHT research provides unprecedented insights into the landscape of IoT attacks facilitated by the Tor network, revealing a highly active and sophisticated threat environment.
Firstly, the study presents the first clear evidence that attackers are systematically leveraging Tor's anonymity to exploit cloudless IoT devices. Over a 12-month period, the researchers deployed three Tor exit routers and collected over 26 terabytes of traffic, which was subsequently analyzed by their custom-built system.
A staggering 45 distinct vulnerabilities were identified within this traffic. Of these, 29 were previously unknown or "zero-day" exploitations, leading to the assignment of 25 new CVEs (Common Vulnerabilities and Exposures). The severity of these findings is underscored by the fact that 14 of these vulnerabilities were rated as critical severity, posing immediate and severe risks to affected devices. Based on the widely recognized exploit valuation algorithms (like those used in vulnerability markets), the estimated market price for these newly discovered exploits was calculated to be over $300,000 USD. More alarmingly, the researchers estimate that these vulnerabilities collectively expose approximately 12 million devices currently accessible on the internet to severe risks.
The most prevalent vulnerability type identified was access control vulnerabilities, often allowing privileged access to devices like DAVRs. A concerning trend observed was the clear targeting of legacy and end-of-life (EOL) products, which no longer receive security updates, making them perpetual targets for attackers.
In terms of scale, the TORCHLIGHT system detected over 90,000 exploitation attempts targeting the identified vulnerabilities during the 12-month observation period. The activity exhibited peaks, demonstrating concentrated efforts by attackers at certain times, such as a significant surge related to a path traversal vulnerability. The ability of the ARM-based IoT traffic analyzer to identify even low-volume exploitation attempts (as few as two occurrences over 12 months) highlights its effectiveness.
The study also mapped the global reach of these attacks, identifying traffic from over 50,000 unique IoT devices across 148 countries. The distribution of targeted vendors and device types followed a long-tail pattern, indicating that while many different devices are targeted, a few manufacturers and device categories bear the brunt of the attacks. Specifically, devices from manufacturers like Dahua (often branded as "Core Vision") and device types such as DVRs and cameras were disproportionately targeted.
Beyond direct exploitation, the research found that a significant portion of the traffic involved brute-force login attempts. By analyzing credentials used in failed login attempts, the team discovered that the top 10 non-default passwords were often related to specific device brands, such as RealLink and TP-Link. This indicates that attackers are not merely guessing randomly but are conducting reconnaissance to identify and leverage device-specific credentials, demonstrating a methodical approach to their attacks. This pattern, combined with the observed exploitation of multiple vulnerabilities in sequence, points to a strategy of dependency-linked exploitation, where attackers chain together different vulnerabilities for reconnaissance, initial access, and persistent control.
Technical Deep Dive
▶ Watch: Introducing Torchlight: Their system for attack analysis (3:28)
The core of this research is TORCHLIGHT, a sophisticated system designed to collect, discover, and analyze IoT attacks originating from Tor exit points. Developed to operate efficiently on resource-limited virtual private servers (VPSs), TORCHLIGHT comprises three primary components: the Tor Exit Traffic Collector, the Deployment Planner, and the ARM-based IoT Traffic Analyzer.
The Tor Exit Traffic Collector is optimized for efficiency. Recognizing that only external traffic exiting the Tor network is unencrypted and relevant for analysis, the collector is configured to capture only this specific type of traffic, which significantly reduces storage requirements by approximately 50%. It distinguishes between internal and external traffic by checking whether both the source and destination IP addresses belong to the Tor network. Given that there are over 7,000 distinct Tor IP addresses, this check is performed efficiently in the operating system kernel using the IP set IP extension, which leverages specialized data structures for fast lookups. The process involves fetching the latest Tor consensus file (which lists active Tor relays and exit nodes), adding corresponding rules to IPtables with an FQ (Fast Queue) target for traffic marking, and then sniffing the marked data. This collected data is then securely transmitted to a local Network Attached Storage (NAS) via an encrypted SSH channel. Further filtering is applied to remove irrelevant "noise" data. This includes filtering by common IoT protocols such as HTTP, RTSP, FTP, and Telnet, and empirically excluding traffic to top 1 million websites, known hosting providers, and common error responses, thereby focusing the analysis on potentially malicious IoT-related activity.
The Deployment Planner addresses a strategic challenge in monitoring Tor. Tor's exit router selection algorithm favors relays with higher bandwidth, meaning that low-bandwidth VPS relays (which are more cost-effective for researchers) naturally have a lower probability of being selected and thus observing attacks. The planner's goal is to maximize the likelihood of observing attacks within a fixed budget by identifying and deploying the most cost-effective nodes that collectively offer the highest potential bandwidth, thereby increasing the chances of capturing relevant traffic.
The most innovative component is the ARM-based IoT Traffic Analyzer. This analyzer tackles an "open-world problem" – the attackers, their methods, and their targets are largely unknown beforehand. To address this, it employs a five-step, chain-of-thought process leveraging Large Language Models (LLMs) for both IoT traffic identification and attack detection:
- Preliminary IoT Entity Identification: The LLM first attempts to identify the IoT vendor, type, and model information from responses found within the captured traffic, using in-context learning.
- Hallucination Verification: To mitigate the common problem of LLM "hallucination," the LLM is prompted to re-verify the IoT entity it previously recognized, ensuring accuracy.
- Missing Information Retrieval (RAG): If critical information like the vendor or type is missing (e.g., only a device model like "IPC HFW" is identified), the system employs Retrieval-Augmented Generation (RAG). It harvests latent documents (like titles and snippets) from search engines using the partial information and feeds this back to the LLM, prompting it to complete the missing vendor and type details.
- Contextual Judgment: A critical step involves determining if the identified entity truly represents traffic from an IoT device, or merely a webpage discussing an IoT device (e.g., a blog post mentioning a Sony camera). The LLM is prompted to make a nuanced judgment: "Does this response originate from an IoT device itself, or is it just a webpage discussing the device?"
- Attack Analysis: Once the traffic is confirmed to originate from an IoT device, the LLM performs a binary classification to identify attack types. The input to the LLM varies depending on the attack type being sought (e.g., command injection, information disclosure, path traversal). For instance, when detecting command injection, the LLM is prompted to identify evidence of such an attack. In a compelling example, the LLM not only identified a command injection but also correctly recognized a Base64 encoded command and inferred its meaning, showcasing its deep analytical capabilities. This same methodology is applied to detect other attack types with high accuracy; for example, injection detection achieved 99% accuracy.
Overall, the IoT device traffic detection achieved over 93% accuracy, demonstrating the robust performance of the ARM-based analyzer in discerning legitimate IoT traffic from other network noise and then accurately identifying attack attempts.
Demo / Proof of Concept
▶ Watch: Command Injection Detection: Example and detailed analysis (7:00)
While the presentation did not feature a live demonstration of the TORCHLIGHT system in action, the entire research project and its findings serve as a powerful proof of concept for its methodology and effectiveness. The detailed technical deep dive into TORCHLIGHT's components — the traffic collector, deployment planner, and ARM-based analyzer — illustrates how the system functions to identify and categorize real-world attacks.
The most compelling demonstration of TORCHLIGHT's capabilities comes from the case study on the infiltration process of a D-Link NAS device by an attacker, meticulously reconstructed from the captured Tor exit traffic. This case study vividly illustrates the multi-stage nature of these sophisticated attacks:
- Reconnaissance: The attacker's initial requests exploited an information disclosure vulnerability to gather crucial device and firmware information. This step is vital for tailoring subsequent exploits.
- Exploitation: Following reconnaissance, the attacker tested for known weaknesses. This involved attempting to exploit a hardcoded credential vulnerability and a command injection vulnerability. The use of a randomized unique string during the command injection attempt was a clever tactic to confirm successful code execution and distinguish their activity.
- Post-Exploitation and Backdoor Deployment: Once exploitation was confirmed, the infiltration phase began. The attacker leveraged the vulnerabilities to deploy persistent backdoors and additional tools, such as BusyBox, to gain full and persistent control over the device. A striking example was a real-world, highly simplified backdoor found in a CGI file. This backdoor consisted of only three lines of code, designed to execute a command specified within the
Content-TypeHTTP header of an incoming request and return the execution result. This highlights how attackers prioritize stealth and simplicity for persistence.
This D-Link NAS case study is a concrete example of dependency-linked exploitation, where attackers chain together multiple vulnerabilities and techniques – from information gathering to credential testing to command execution – to achieve their objectives. The ability of TORCHLIGHT to reconstruct such intricate attack sequences from anonymous Tor traffic underscores its efficacy in shedding light on real-world, clandestine IoT threats.
Defensive Implications
▶ Watch: Evaluation results: Targeted devices and attack types (7:50)
The findings from the TORCHLIGHT project carry significant defensive implications for users, manufacturers, and security professionals dealing with cloudless IoT devices. The active exploitation of zero-day and legacy vulnerabilities through the Tor network demands a multi-layered and proactive defense strategy.
- Aggressive Patching and Updating: The prevalence of attacks targeting end-of-life (EOL) products and unpatched vulnerabilities underscores the critical need for users to keep their IoT device firmware updated. Manufacturers must prioritize issuing security updates and providing clear guidance on the lifecycle of their devices. For devices that have reached EOL, the strongest recommendation is to disconnect them from the internet entirely or replace them with supported alternatives.
- Strong and Unique Credentials: The discovery of attackers leveraging device-specific credentials and brute-force attempts highlights the inadequacy of default or easily guessable passwords. Users must be educated and enforced to use strong, unique passwords for all IoT devices, ideally with multi-factor authentication where available.
- Network Segmentation: Isolating IoT devices from critical networks is paramount. Implementing network segmentation (e.g., placing IoT devices on a separate VLAN or guest network) can limit the lateral movement of attackers even if an IoT device is compromised, preventing them from accessing sensitive data or systems.
- Strict Firewall Rules: Configure firewalls to enforce the principle of least privilege. IoT devices should only be allowed to communicate with absolutely necessary external services and internal systems. Restrict inbound connections to only essential ports and IP addresses, and monitor outbound connections for anomalous behavior that might indicate a compromise (e.g., C2 traffic).
- Intrusion Detection/Prevention Systems (IDPS): Deploying IDPS solutions capable of monitoring network traffic for known attack signatures, especially those targeting common IoT protocols like HTTP, RTSP, FTP, and Telnet, is crucial. The insights from TORCHLIGHT can inform the development of new signatures for the identified zero-day and prevalent vulnerabilities.
- Threat Intelligence Integration: Security teams should actively consume and integrate threat intelligence feeds that include information on emerging IoT vulnerabilities, exploit kits, and attack campaigns. The 25 new CVEs identified by TORCHLIGHT should be immediately incorporated into vulnerability management programs.
- Supply Chain Security and Responsible Disclosure: Device manufacturers have a responsibility to design secure products, provide timely updates, and respond proactively to discovered vulnerabilities. The research highlights the critical need for a robust responsible disclosure program to ensure that security researchers can report vulnerabilities without fear, leading to improved product security for all.
- Ethical Monitoring (for Network Operators): While challenging due to privacy concerns, network operators and ISPs could potentially leverage insights from such research to identify patterns of malicious traffic originating from Tor exit nodes. This does not imply monitoring individual Tor users but rather understanding the characteristics of attack traffic to enhance broader network defenses.
In essence, the TORCHLIGHT findings serve as a critical call to action, demanding a shift towards more proactive, informed, and robust security practices for the vast and vulnerable landscape of cloudless IoT devices.
Key Takeaways
- Tor as an Attack Vector: The Tor network is actively being leveraged by malicious actors to anonymously launch sophisticated attacks, including zero-day exploits, against directly exposed (cloudless) IoT devices.
- TORCHLIGHT's Efficacy: The TORCHLIGHT system effectively identifies and analyzes IoT traffic and attack attempts originating from Tor exit nodes, successfully uncovering 45 vulnerabilities, including 29 zero-day exploits (25 CVEs assigned), with high accuracy.
- Widespread Vulnerability and Risk: Millions of IoT devices, particularly legacy and end-of-life models, are at severe risk from critical vulnerabilities such as authentication bypass, command injection, and information disclosure, with an estimated $300,000 USD market value for the identified exploits.
- Sophisticated Attack Techniques: Attackers employ methodical and multi-stage exploitation techniques, including reconnaissance, targeting device-specific credentials, and chaining vulnerabilities (dependency-linked exploitation) to gain persistent control.
- Urgent Call for Proactive Defense: Robust defensive measures are critically needed, encompassing diligent patching, strong unique passwords, network segmentation, strict firewall rules, and proactive threat intelligence to protect against these clandestine threats.
- Ethical Research Imperative: Research involving anonymous networks like Tor, while crucial for public safety and security, must navigate complex ethical considerations, balancing security benefits with user privacy and advocating for consultation with Tor research safety boards.
About the Speaker(s)
The research presented on TORCHLIGHT was primarily led by Yumingzhi Pan from Southeast University. This significant work was a collaborative effort, conducted jointly with researchers from Straxo University and UMass Lo, highlighting a multi-institutional approach to tackling complex cybersecurity challenges.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Legitimate empirical research with a clever observation at its core: Tor exit nodes as passive honeypots for IoT zero-day discovery. Twenty-nine previously unknown exploitation patterns, 25 CVEs, and 26TB of real attack traffic give this weight that most IoT talks completely lack. The LLM-based traffic analyzer is the methodological wildcard — it either earns its place or it's a gimmick, and the 93%+ accuracy numbers suggest it earns it.
Heather Calloway (CISO) — WEAK
Technically credible research that surfaces real attacker behavior — Tor-anonymized IoT exploitation, 29 zero-days, 12 million exposed devices — but it never crosses the line from observation to operational relevance. The findings are significant; the translation to any actionable institutional posture is not.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)