Abandoned IoT apps keep sending sensitive data to broken servers
UMass Amherst researchers found 61,500 abandoned Android IoT apps send sensitive data to unreachable, blocklisted, or re-registered domains.
Researchers at the University of Massachusetts Amherst built a dataset of 61,500 abandoned IoT companion apps from AndroZoo and found 73.6% bundled dependencies with vulnerabilities listed in the National Vulnerability Database. About a quarter of extracted domains no longer resolved, roughly one in nine URLs matched threat-intelligence blocklists for phishing, scam, spyware, or malware links, and domains affecting over 2,000 apps had changed ownership since the apps' last update. 38.4% of unique data-flow sources and sinks in abandoned apps were tied to unreachable, blocklisted, or ownership-changed domains, versus under 1% in 500 actively maintained comparison apps. Disclosure emails prompted some app removals and fixes, including a Tuya SDK issue patched on the vendor's cloud platform.