JPCERT tracks shifting Mirai-like IoT scanning
JPCERT/CC's TSUBAME sensors show Mirai-like Telnet scanning from Japan declining while non-Mirai botnet traffic from compromised DVRs, NAS and routers rises.
JPCERT/CC's quarterly TSUBAME Internet threat monitoring report for January–March 2026 reviews FY2025 scanning trends observed from sensors in Japan and overseas. The dominant traffic remains scans on 23/TCP (Telnet), long associated with Mirai-family botnets, but the proportion of classic Mirai-like packets fell from roughly 70% at the start of FY2025 to around 30% by year end. In its place, JPCERT/CC observed a rising share of scanning traffic from compromised devices that lack Mirai's characteristic signatures, originating from surveillance cameras, DVRs, NAS devices and broadband routers made by both Japanese and overseas (Korean, Chinese) vendors, with overseas DVR products dominating from October 2025 onward.
The report notes that Mirai-associated source IPs were also seen communicating over non-23/TCP ports, suggesting attackers are pivoting to target specific internet-facing services and known vulnerabilities in particular products rather than relying solely on default Telnet credential brute-forcing. JPCERT/CC shared these findings with domestic device manufacturers and telecom operators to support mitigation and recommends operators harden internet-facing IoT devices, keep firmware updated, and use scanning tools like Shodan to verify no unnecessary services are exposed.
Overall this is a routine quarterly monitoring update rather than a report of new attacks or incidents; JPCERT/CC states no anomaly warranting a special alert was observed this quarter, and 23/TCP and 443/TCP scanning remains widespread across sensors in Japan, North America and Europe.
Mentioned in this report
Source reporting: https://blogs.jpcert.or.jp/en/2026/07/tsubame_overflow_2026-01-03.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free