# UK NCSC warns ECDs create exploitable enterprise gateways

Published: 2022-05-10 · Severity: high · Sectors: government-national, defense, education, financial-services, healthcare, manufacturing, energy, retail, telecommunications
Canonical: https://vorant.io/reports/df8a1333-5768-5d5e-b165-dce5e5f47e42/uk-ncsc-warns-ecds-create-exploitable-enterprise-gateways

> The UK's National Cyber Security Centre assesses that the proliferation of poorly secured Enterprise Connected Devices presents an expanding attack surface exploited by nation-state and criminal actors for espionage, disruption, and financial gain.

The UK National Cyber Security Centre (NCSC), in collaboration with the Department for Digital, Culture, Media and Sport (DCMS), has released a comprehensive threat assessment on Enterprise Connected Devices (ECDs)—any devices that interact with, hold, or process organisational data. The report concludes it is highly likely that the growing adoption of ECDs, including IoT devices, printers, VoIP systems, cameras, and BYOD endpoints, presents an expanding attack surface. Many of these devices are accessible over the public internet with cyber security frequently treated as an afterthought by vendors. Following initial compromise, ECDs are highly likely to serve as pivot points for lateral movement into corporate networks, enabling espionage, disruption, or ransomware deployment.

The assessment details multiple threat actor groups exploiting ECD weaknesses. Nation-state actors, including Russian APT28 (STRONTIUM/Fancy Bear), have targeted IoT devices such as VoIP phones, printers, and video decoders for espionage across government, defence, and critical sectors. Cyber criminals leverage ECD vulnerabilities to build botnets for DDoS attacks—the 2016 Mirai malware infected IP cameras and routers to take down DNS provider Dyn, and variants now specifically target enterprise IoT with higher bandwidth for stronger attacks. The NCSC highlights that unpatched devices, insecure defaults, outdated protocols, and supply-chain compromises (exemplified by the Ripple20 vulnerabilities affecting millions of devices) exacerbate risk. With remote working accelerated by COVID-19, the threat landscape has expanded further, making ECDs an attractive and accessible target for both espionage-driven nation-states and financially motivated criminals.

The report emphasises that IoT botnets pose the greatest threat to ECDs and the wider enterprise, with the majority used for coordinated DDoS attacks, though some variants can exfiltrate sensitive data. Case studies include a 2017 casino data breach via a compromised internet-connected fish tank, ransomware targeting LG smart TVs, and the exploitation of unpatched Sangoma/Asterisk VoIP systems (CVE-2019-19006) affecting over 1,200 organisations in 20+ countries. The NCSC warns that a single exposed ECD can enable network-wide compromise, putting supply chains at risk. All sectors deploying ECDs face elevated risk, particularly those relying on common enterprise devices with poor baseline security. The agency has launched Device Security Principles (Beta) as a framework to drive improved security standards in this expanding threat domain.

## Mentioned in this report

- Vulnerabilities: CVE-2019-19006 (KEV)
- Threat actors: APT28, Digital Revolution
- Malware: Cyber.Police, FLocker, Mirai, NotPetya, Torri, VPNFilter
- Campaigns: Ripple20, SolarWinds compromise

Source reporting: https://www.ncsc.gov.uk/report/organisational-use-of-enterprise-connected-devices

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/df8a1333-5768-5d5e-b165-dce5e5f47e42/uk-ncsc-warns-ecds-create-exploitable-enterprise-gateways.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
