logo

Mirai Botnets Evolve Into Major DDoS and Proxy Abuse Threats

ID: f5c3f4e1-2fdf-5876-ac12-31eccabd4520

STIX ID: report--f5c3f4e1-2fdf-5876-ac12-31eccabd4520

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Mirai-based botnets have evolved from simple IoT malware into highly scalable DDoS and residential-proxy abuse platforms: between July and December 2025 over 21,000 C2 servers were observed and Cloudflare attribution links the Aisuru‑Kimwolf family to a 31.4 Tbps hyper‑volumetric attack. Variants (e.g., Satori, Kimwolf) expand targets and evasion, operators repurpose infected devices as rentable residential proxies, and infrastructure recycling enables quick rebuilds after takedowns. Defenders are advised to prioritize basic edge-device hygiene, monitor unusual outbound traffic, and track Mirai-derived indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.