In early May 2026, Mirai-like botnet activity significantly increased following an attack on hosting servers running cPanel and WHM software This article explores mirai like botnet. . The incident was reported by JPCERT/CC, which noted a spike in malicious packets targeting Telnet services via TCP on TSUBAME Internet threat-monitoring sensors.

Mirai is well-known for infecting exposed Internet-connected devices and using them as bots for various malicious activities, including scanning, brute-force attacks, and distributed denial-of-service operations. The United States accounted for the largest share of observed source addresses, with Germany, France, Canada, and Japan also experiencing significant increases around May 1. Attackers typically scan 23/TCP to identify systems with exposed remote-management services, which they may then attempt to log into using weak, default, or reused credentials.

TSUBAME sensor data revealed that 23/TCP was the most frequently targeted port across most monitored networks in Japan, North America, Europe, and other regions. Other commonly scanned services include HTTPS on port 443/TCP, HTTP on port 80/TCP, SSH on port 22/TCP, alternate web services on port 8080/TCP, and Remote Desktop Protocol on port 3389/TCP. An interface that appears to be running cPanel (Source: jpcert) highlights the necessity for hosting providers and server administrators to swiftly implement security updates, particularly for Internet-facing management platforms such as cPanel/WHM.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.