IoT Botnets Still Exploit Open Telnet and Default Passwords a Decade After Mirai
China's National Network and Information Security Notification Centre issued a notice in August 2026 identifying five active cross-border botnet families — Mirai, CondiBot, Gafgyt, TBot, and SoftBot — all gaining initial access through Telnet or SSH brute force against factory-default credentials and unpatched older vulnerabilities. Internet scanning tools like ZoomEye show that a significant number of devices continue to expose Telnet on port 23 to the open internet, forming the recruitment pool these botnets rely on. Analysts note that raw counts of reachable Telnet services overstate actual vulnerable devices, as the figures include honeypots, reconfigured network equipment, and lab systems hosted in cloud environments. Three structural factors keep the problem persistent: devices outlive vendor support cycles, ownership and maintenance responsibilities are often unclear in small organisations, and remote-access interfaces enabled for convenience are rarely disabled post-setup. While newer botnets like Dysphoria have adopted advanced techniques such as blockchain-based command infrastructure to resist takedowns, the initial entry method has remained unchanged since the original Mirai outbreak in 2016.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in