Mirai and Its Heirs: A Decade of Structural Neglect in IoT Security
ID: 81869a67-4a28-5079-af53-04dc9bbb1f2d
STIX ID: report--81869a67-4a28-5079-af53-04dc9bbb1f2d
Feed Name: Censys Blog
Nearly ten years after Mirai's source leak, Mirai-derived botnets (e.g., Aisuru, Kimwolf) continue to exploit default credentials, exposed services (ADB, GPON interfaces), and outdated SDK components (such as Boa) in consumer IoT devices to build large DDoS-capable botnets; 2026 law-enforcement takedowns materially disrupted C2 infrastructure but did not eliminate the threat, with infrastructure regenerating or fragmenting and millions of exposed endpoints remaining — a persistence driven by supply-chain SDK issues, manufacturer neglect, and poor consumer hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
