The Botnet of Things: A Threat Report on Malware Affecting Routers, Cameras, and Smart Devices

Surprising fact: A single family of compromised devices once knocked major sites offline with attacks topping 1 Tbps, proving millions of connected gadgets can be weaponized fast.

Table of contents

An expert take by Ethan Cross, HakTechs.com Lead Analyst

This report explains why the “Botnet of Things” matters now. Connected devices widen the attack surface and let attackers assemble vast armies quickly.

At its core, a botnet is a coordinated set of compromised devices controlled remotely to run automated attacks without owners’ knowledge. Mirai, first found in August 2016, showed how default credentials and exposed services turn cameras and routers into powerful DDoS sources.

When Mirai’s source code leaked, copycats multiplied. High-profile hits — on KrebsOnSecurity, OVH, and Dyn — exposed how fragile Internet-facing infrastructure can be under sustained load.

This section previews what follows: who’s attacking, how infections spread, command-and-control patterns, the most active families, and which sectors face the highest risk. We also outline defensive steps based on Zero Trust, better network hygiene, and DDoS mitigation to help teams act quickly.

Key Takeaways

  • Connected devices expand risk: default passwords and open interfaces let attackers recruit gear fast.
  • Mirai was a turning point: its leaks industrialized copycat campaigns still active today.
  • High impact: large-scale DDoS and service outages affect both consumers and enterprises.
  • Defenses work: Zero Trust, patching, and monitoring reduce exposure.
  • Actionable focus: we’ll provide indicators, ports, and triage steps to speed incident response.
  • Top threats of the 2024 botnet show how families evolved and where to prioritize defenses.

Executive summary: Why IoT botnet malware still matters right now

Botnets-for-hire and poor device hygiene keep large-scale attacks cheap, fast, and effective. Defenders win when they pair Zero Trust controls with live threat intelligence and automated mitigation.

Cheap access to rented attack capacity has turned everyday devices into powerful tools for rapid disruption. Attack-for-hire markets let amateurs and professionals launch volumetric and protocol floods with minimal effort.

Default credentials, slow patch cycles, and always-on connections keep consumer and enterprise devices exposed. Mirai-era code and later variants continue to fuel high-volume ddos cases, including reflected amplification that produced record traffic spikes.

What this means: expect repeated attacks that target services and network chokepoints, not just single systems. Threat actors pivot compromised gear into credential abuse, phishing distribution, and cryptomining, widening the impact beyond outages.

A sinister-looking cloud of binary code and glowing data streams, cascading over a cityscape silhouette. In the foreground, a towering pillar of circuit boards and electronic components, casting a menacing shadow. Ominous red warning lights flash, highlighting the threat of malicious IoT botnets infiltrating homes and businesses. Harsh, directional lighting casts dramatic shadows, heightening the sense of impending cyber-attack. The overall atmosphere is one of foreboding and technological vulnerability, reflecting the gravity of the "Executive summary: Why IoT botnet malware still matters right now".

Vector Primary impact Immediate defense Long-term control
Default credentials Mass recruitment of devices for ddos Change passwords, disable remote access Enforce strong provisioning and firmware updates
Reflected amplification High-throughput traffic spikes Rate-limit and filter inbound traffic Harden services and close open resolvers
Botnets-for-hire Frequent, opportunistic attacks Use DDoS protection and traffic validation Adopt Zero Trust, threat intel feeds

Bottom line: prioritize device hardening, validate traffic, and prepare playbooks. That strategy reduces blast radius when attacks hit critical apps and services.

IoT botnet malware in the wild: present-day threat landscape and actors

Today’s threat landscape shows an industry-grade market: groups offer rented attack capacity and updated variants that scan, exploit, and monetize compromised gear.

What began as hobby DDoS has matured into a service economy that weaponizes everyday devices at scale.

Operators advertise reliability, throughput, and features. They sell time and control over large fleets to buyers who want fast, effective attacks.

Who’s running these operations?

Known actors range from lone coders to organized groups. Families like Mirai, Gafgyt/BASHLITE, and Elknot/BillGates keep resurfacing with new exploits and modified code.

Mirai variants scan the internet with stateless SYN probes on Telnet ports 23/2323 and brute-force default credentials. Others exploit vulnerabilities such as Log4j to gain remote execution.

A dark, moody scene of various internet-connected devices gathered together, surrounded by a looming, ominous presence. In the foreground, a collection of smart home gadgets - a security camera, a wireless router, a voice assistant, and a smart lightbulb - all cast in a sinister, low-key lighting. In the middle ground, shadowy silhouettes of other connected devices loom, their purpose unclear. The background is a hazy, uncertain space, suggesting a larger network of compromised systems. The overall atmosphere evokes a sense of dread and the unseen dangers of an IoT botnet.

“Real-world incidents show the scale: attacks on KrebsOnSecurity, OVH, and Dyn reached hundreds of Gbps to 1 Tbps.”

Targets, tactics, and monetization

Targets now include routers, IP cameras, smart TVs, NAS, and home gateways. Operators probe addresses for Telnet, SSH, and web admin endpoints to gain a foothold.

Family Primary method Common targets Monetization
Mirai and variants Telnet SYN scans, credential brute-force Routers, cameras, gateways Rent DDoS capacity
Gafgyt / BASHLITE Brute-force, protocol floods Embedded Linux devices, NAS Service-for-hire attacks
Elknot / BillGates Exploit chains (e.g., Log4j) for RCE Smart TVs, gateways, servers Mixed: DDoS, cryptomining, phishing infra

Quick takeaway: defenders must monitor unusual outbound flows, patch vulnerable services, and harden credentials to reduce the available surface for attack.

How IoT botnets form: infection vectors, command, and control

Most takeovers start with simple mistakes: exposed admin ports and unchanged factory credentials let attackers move from scan to control quickly.

Attackers begin by scanning networks for open services—Telnet, SSH, and web admin panels. They probe common ports and attempt brute-force logins against default credentials. When access succeeds, they drop a compact binary to gain persistent control.

A dark, ominous landscape of various IoT devices, each representing an infection vector for a botnet. In the foreground, a tangle of wires and cables snakes across the scene, connecting routers, security cameras, and smart home hubs. Their screens flicker with corrupted data, signaling a sinister command and control network. In the middle ground, a shadowy figure manipulates the devices, their face obscured by a digital glitch. The background is shrouded in a hazy, techno-dystopian atmosphere, with the distant silhouettes of skyscrapers and towers evoking a sense of vulnerability and the pervasive threat of the "Internet of Threats." The overall scene conveys the ominous, interconnected nature of IoT device vulnerabilities and the ease with which they can be exploited to form a dangerous botnet.

How do infections escalate?

Web interface flaws or weak update paths enable remote code execution. Third-party components create additional vulnerabilities. Once installed, the code often kills competing processes, hides, and locks management access.

What models run command and control?

Centralized C2 uses a single server for fast commands, but is easier to take down. Tiered designs add redirectors for resiliency. Decentralized peer-to-peer meshes share instructions across many nodes, making disruption harder.

  • Watch for unusual outbound connection attempts to known C2 addresses.
  • Enforce unique device credentials and disable external admin interfaces.
  • Minimize exposed services and apply timely firmware fixes to reduce attack surface.

For a detailed primer on what these threats look like in practice, see what is an IoT botnet.

Mirai to many: the blueprint that scaled IoT attacks

Mirai’s core design—fast scanning, simple brute force, and lightweight persistence—became a repeatable template. Researchers tracked how that pattern allowed rapid recruitment of vulnerable devices across broad address ranges.

How did it work in practice?

What scanning looked like

Mirai continuously probed the IPv4 space with stateless TCP SYN probes to Telnet ports 23 and 2323. It excluded some ranges but still covered enough addresses to map weak targets quickly.

Post-compromise behavior

After gaining shell access, the code cycled credential lists to authenticate, ran commands to install itself, killed competing processes, and applied firewall rules to lock out other actors.

A hacker's terminal interface, the screen aglow with a grid of colorful port numbers as Mirai, the infamous IoT botnet, scans relentlessly for vulnerable devices. The ambient lighting casts a somber, ominous tone, while the angular, minimalist design of the user interface evokes a sense of technological prowess and precision. The foreground is dominated by the terminal window, with lines of code cascading down the screen, while the background features a stark, distorted cityscape - a subtle nod to the global reach and impact of this malware. The overall scene conveys the power and scale of Mirai, a blueprint for IoT attacks that have transformed the landscape of cybersecurity.

Impact and evolution

Headline cases include the KrebsOnSecurity blog (≈620 Gbit/s), OVH (~1 Tbit/s), and the Dyn DNS outages that disrupted major sites. The released source spurred many variants—Satori, Okiru, Masuta, OMG, Wicked, Miori, Hakai, Yowai, SpeakUp—and active 2024–2025 campaigns.

Lesson: enforce unique credentials, disable Telnet, and monitor for SYN bursts to Telnet ports to spot Mirai-style reconnaissance before an attack.

Attack playbook: DDoS, credential stuffing, phishing, cryptomining, and more

Modern campaigns mix high-volume outages with credential fraud and covert resource theft. Defenders should expect fleets of compromised devices to pivot between DDoS, account abuse, spam, and cryptomining under automated command-and-control.

A chaotic network of interconnected nodes, pulsing with a frenetic rhythm of data packets. In the foreground, a tangled web of lines and curves representing the ebb and flow of DDoS traffic, with bursts of color denoting the intensity of the assault. The middle ground is dominated by a shadowy silhouette of a malicious entity, its sinister presence looming over the scene. The background is a swirling, abstract landscape of digital noise, with glitching and distortion adding to the sense of digital mayhem. The overall image conveys a sense of urgency, threat, and the relentless nature of modern cyber attacks.

How do volumetric and amplification attacks work?

Volumetric DDoS floods bandwidth to overwhelm a target network or server. Protocol-layer attacks exhaust connection state on routers and firewalls.

Reflected amplification leverages misconfigured services to multiply outbound traffic. Microsoft reported multi-terabit events, showing how small requests can become massive floods.

How does credential stuffing and abuse scale?

Automated tools replay breached username/password lists across many services. Distributed devices rotate source IPs and bypass simple rate limits, increasing account takeover risk.

Enforce strong passwords, multi-factor authentication, and rate-based anomalies to blunt these attacks.

Why do attackers run cryptomining and spam from devices?

Cryptojacking steals CPU cycles and raises costs for owners while providing steady revenue to operators. Spam and phishing use distributed endpoints to evade filters and reach more users.

  • Watch: unusual outbound DNS/NTP queries and persistent C2 connections.
  • Defend: baseline traffic, deploy layered DDoS protection, and require MFA.

Exploits and exposures: where remote code execution meets IoT

Short answer: A few common exposures — embedded web admin pages and outdated third‑party libraries such as Log4j — create clear paths for remote code execution. When attackers find these gaps, they quickly drop payloads and gain persistent access to the system.

A single unpatched component can turn a quiet device into an unexpected entry point for remote code.

How breaches usually start

  • Embedded web interfaces left reachable from the internet are prime targets. Attackers probe for form errors, odd headers, and misconfigurations.
  • Third‑party libraries can carry hidden vulnerabilities. Log4j (disclosed Dec 2021) is a high‑profile example where exploit code allowed wide remote code execution.
  • Once an exploit runs, attackers gain access and can install persistent code without user interaction, enrolling the device into larger attacks.

Detection and containment

  • Watch for unusual web error patterns and anomalous headers that indicate exploit attempts.
  • Limit external access to admin panels. Require strong auth, use IP allowlists, and prefer VPN‑only management.
  • Keep an inventory of third‑party components so you can prioritize patches when a CVE drops.

A dimly lit, industrial setting with exposed wiring and circuit boards. In the foreground, a shadowy figure appears to be manipulating a keyboard, their hands moving swiftly across the keys. The background is hazy, with a sense of unease and the faint glow of digital screens. Subtle beams of light intersect, casting an eerie, ominous atmosphere. The scene conveys a sense of vulnerability and the threat of remote code execution, a critical security vulnerability in the IoT landscape.

“Preventing early exploitation stops many downstream attacks like DDoS, cryptojacking, or data theft.”

For technical teams, review patch guidance and mitigation to shrink the window between disclosure and defense. Rapid patching, tight admin controls, and focused monitoring convert vulnerability information into meaningful protection.

Which sectors are at risk: business, critical services, and consumers

Across hospitals, factories, and homes, ordinary networked gear can become the weak link in critical operations. This section maps who faces the biggest exposure and why rapid mitigation matters.

Healthcare: Clinical workflows now depend on connected monitors, imaging, and networks. An availability loss delays care and endangers patients.

Financial services: Banks and payment systems require high uptime. Distributed credentials abuse and volumetric attacks threaten transactions and customer trust.

Manufacturing: Plants use sensors and controllers that tie into production lines. Disruption can halt output and create supply‑chain bottlenecks.

Energy and transportation: These sectors operate with tight safety margins. Control‑plane saturation or service outages can cascade into public impact.

A dimly lit, industrial-style scene showcasing an array of interconnected IoT devices. In the foreground, a variety of smart home sensors and appliances, such as security cameras, smart thermostats, and voice assistants, are arranged on a cluttered desk. The middle ground features a cluster of routers, modems, and networking equipment, their LED indicators blinking in a chaotic rhythm. In the background, a large display shows a network diagram with numerous nodes representing connected devices, highlighting the scale and complexity of the IoT ecosystem. The overall atmosphere is one of subtle unease, hinting at the potential vulnerabilities and security risks that could lurk within this interconnected world of smart devices.

What about consumers and small businesses?

Home networks often lack monitoring. Many smart devices run with default settings, making them easy to recruit for wider attacks.

Even organizations with few connected gadgets can suffer collateral damage from upstream outages or targeted application‑layer attacks.

  • SMBs are especially exposed; managed DDoS protection and patch services close gaps.
  • Regulatory and contractual penalties raise the cost of downtime—so prioritize inventory and hardening.
  • Cross-sector information sharing helps defenders tune controls before attacks scale.

“Sector-specific risk assessments — inventory devices, map dependencies, and remove single points of failure — reduce blast radius.”

Defensive posture: Zero Trust, network hygiene, and DDoS protection

Defenders win when systems assume no implicit trust and enforce continuous verification across all edge devices. Apply micro‑segmentation, strict authentication, and continuous telemetry so a compromised device cannot reach critical systems.

How should you harden devices and exposure?

Inventory and harden: give each device unique credentials, apply firmware updates promptly, and disable remote admin. Prefer allowlists and VPN‑only management to limit access.

How do threat feeds and automation help?

Ingest curated threat intelligence—IPs, amplification servers, and signatures—and automate blocking with dynamic rules at the edge. Use AI/ML for anomaly detection but keep humans in the loop for high‑impact blocking.

How do you stay operationally ready?

Baseline network traffic to define normal behavior. Practice playbooks: scrubbing activation, BGP steering, and stakeholder communications. Instrument routers, firewalls, and proxies so logs reveal devices under external command.

“Apply Zero Trust: authenticate every access, authorize least privilege, and segment networks so attacks cannot pivot to critical systems.”

  • Combine on‑prem and cloud DDoS protection to absorb volumetric floods.
  • Measure mean time to detect and respond; shorten feedback loops after each event.
  • Test with tabletop and red‑team drills to validate rules, command, and control actions under pressure.

Measuring impact: indicators, traffic patterns, and ports of interest

Watch network signals early — they show where compromises start and how far they spread. Focus on clear, repeatable indicators that map to specific defensive steps.

Key signs: outbound SYN bursts to Telnet ports 23 and 2323, spikes to amplification-prone services, or many short flows to random addresses. These often precede larger attacks.

  • Persistent connections to suspicious hosts — IRC, HTTP beacons, or P2P chatter — indicate active command-and-control and repeated command polling.
  • Server and service telemetry showing error floods, malformed requests, or oversized message patterns point to reflection or misuse.
  • Track attempted logins and unexpected config changes on edge devices; post‑compromise code often blocks remote admin ports to lock access.
  • Monitor Android ADB at TCP/5555 and other open management endpoints; they are frequent probe targets.

“Map source and destination addresses for spikes; many short-lived flows across subnets usually mean scanning or propagation.”

Correlate these indicators with payloads and known signatures, validate scrubbing/rate limits during volumetric events, and feed confirmed IOCs back into detection tools. For practical detection steps, see detect malware in network traffic.

Conclusion

Resilience starts when teams treat every connected gadget as a potential vector and act before an incident escalates.

Mirai’s legacy and the 2016 cases (Krebs, OVH, Dyn) prove that old code and fresh exploits keep fueling large attacks. Variants continue into 2024–2025, and threats now include credential abuse and cryptomining, not just DDoS.

Defenders win by pairing Zero Trust, live threat intelligence, and layered DDoS protection. Track and harden every device, keep playbooks current, and rehearse escalation paths so response is fast and coordinated.

Measure progress with clear metrics—patch timelines, exposure counts, and mitigation activation time—to make security outcomes visible. Share indicators with peers and providers to improve collective defense against botnet-driven attacks.

FAQ

What kinds of devices are most commonly compromised in these attacks?

Consumer routers, network-attached storage (NAS), IP cameras, smart TVs, and home gateways are the primary targets. Attackers focus on devices with exposed management ports, outdated firmware, or weak credentials because they offer persistent network access and can generate substantial traffic for denial-of-service campaigns.

How do attackers typically gain initial access to these devices?

Compromise usually begins with exposed services and weak or default credentials. Threat actors scan the internet for open ports such as Telnet (23/2323), SSH, and HTTP management interfaces, then attempt credential stuffing or brute-force logins. Exploitable software flaws and remote code execution (RCE) vulnerabilities in embedded web interfaces or third-party components are also common entry points.

What is the role of remote code execution in these infections?

Remote code execution lets attackers run arbitrary commands on a device, enabling full takeover. Once RCE is achieved, adversaries install persistence mechanisms, disable competing malware, alter firewall rules, and connect the device to command-and-control infrastructure to receive attack instructions.

How do command-and-control (C2) models differ across campaigns?

Attackers use several C2 architectures: centralized servers that issue direct commands, tiered setups where relays distribute instructions, and peer-to-peer (P2P) networks that increase resilience. Centralized C2 is easier to disrupt, while P2P and tiered models reduce single points of failure and complicate takedowns.

Which historical incidents show the potential impact of these networks?

High-profile events like the attacks on KrebsOnSecurity, OVH, and the Dyn DNS outage demonstrate how compromised devices can generate massive volumetric and protocol-based traffic. Those incidents show how widespread device compromise can disrupt major online services and critical infrastructure.

What attack types do compromised devices enable besides DDoS?

Beyond distributed denial-of-service (DDoS), compromised devices are used for credential stuffing, proxying phishing traffic, cryptomining, data exfiltration, and as relays for more advanced intrusions. They can also host command channels for ransomware or fraud campaigns.

How can organizations detect indicators of compromise on their networks?

Look for unusual outbound connections to unfamiliar IP addresses, persistent connections on nonstandard ports, sudden spikes in traffic from specific device classes, and unexpected processes or services on embedded systems. Logging, traffic baselining, and IDS/IPS alerts help surface these signals.

What immediate steps should a small business take if a device is compromised?

Isolate the infected device from the network, change credentials on all affected systems, update firmware to the latest vendor release, and scan for additional infected hosts. If possible, factory-reset the device and reconfigure it securely. Engage managed security or incident response if the infection persists or affects critical services.

Which defenses provide the best return on effort for protecting devices?

Prioritize strong unique passwords, firmware updates, network segmentation, and limiting management interfaces to internal networks or VPN access. Implement rate-limiting and DDoS protection at the perimeter. Use threat intelligence feeds and automated patching where feasible to reduce exposure windows.

Are there reliable mitigation services for large-scale attacks?

Yes. DDoS mitigation providers offer scrubbing services, traffic filtering, and rate-limiting that absorb volumetric attacks. Content delivery networks (CDNs) and upstream ISPs can also reroute or filter malicious traffic. For persistent C2 activity, coordinated takedowns involving vendors and law enforcement are often necessary.

How do variant families change over time and why does that matter?

Malware families evolve by adding new scanning methods, expanding credential lists, exploiting fresh vulnerabilities, and improving persistence. This constant change increases attack success and complicates signature-based detection. Staying current with vendor advisories and CVE (Common Vulnerabilities and Exposures) notices is essential.

What role do default credentials play, and how effective is credential hygiene?

Default credentials remain one of the most exploited weaknesses. Enforcing unique, strong passwords and disabling unused accounts greatly reduces risk. Credential hygiene paired with multi-factor authentication for management systems where supported provides layered protection against automated account abuse.

How can defenders prioritize which devices to harden first?

Start with devices that face the internet, support critical business functions, or sit in sensitive network segments—routers, firewalls, VPN gateways, and NAS. Prioritize firmware updates and access controls for those nodes, then extend hardening to cameras, smart endpoints, and user-managed devices.

When should organizations involve external incident response or law enforcement?

Engage external responders when compromise affects business continuity, data confidentiality, or when attacks are large-scale or persistent. Law enforcement should be notified for criminal activity or when attribution and coordinated takedowns are required. External experts can also help preserve evidence and navigate disclosure responsibilities.

What are practical long-term strategies to reduce exposure at scale?

Adopt a Zero Trust approach that enforces least privilege and microsegmentation, maintain an asset inventory, automate patch management, and use continuous monitoring with ML-assisted anomaly detection. Combine these with vendor vulnerability programs and supplier risk assessments to reduce systemic exposure.

Ethan Cross

Ethan Cross is a cybersecurity analyst and tech journalist with over a decade of experience in ethical hacking, malware analysis, and digital forensics. At HakTechs.com, he delivers in-depth reports, security tips, and expert analysis to help readers stay ahead of emerging cyber threats.