logo

A sneak peek into recent IoT attacks

ID: 67cc1abe-3aeb-5160-a59d-284808ec5816

STIX ID: report--67cc1abe-3aeb-5160-a59d-284808ec5816

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents active Mirai-derived IoT botnet campaigns (RIFT, Shaolin) observed in Dec 2018–Jan 2019 that exploit web-framework and device RCEs (ThinkPHP, Realtek Miniigd, D-Link, Netgear) to deliver multi-architecture payloads, recruit devices into botnets (and sometimes crypto-miners), and provides exploitation examples, post-exploitation steps, user-agents and a large set of IOCs for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.