Telnet Is Still Open: Why the IoT Botnet Notices Keep Describing the Same Reachable Population
In August 2026, China's National Network and Information Security Notification Center named five cross-border botnet families — Mirai, CondiBot, Gafgyt, TBot and SoftBot. They gain initial access through Telnet and SSH brute force using factory passwords and exploitation of old vulnerabilities.
- Five families named: Mirai, CondiBot, Gafgyt, TBot and SoftBot
- Entry is via Telnet/SSH brute force using unchanged factory passwords
- Attack methods unchanged since 2016, but entry still works
- Botnet Dysphoria uses blockchain services to hide infrastructure
Read next
Security