Global security desk · updated coverage of threats, exploits & breaches

IoT Botnet Drives Unprecedented Distributed Denial-of-Service Attacks

A newly identified botnet comprising hundreds of thousands of compromised internet-of-things devices has been blamed for a series of record-breaking distributed denial-of-service incidents over the past month. Security researchers tracking the operation say the malware spreads primarily through unpatched routers, security cameras, and smart-home hubs, enrolling them into a coordinated flood network capable of generating traffic volumes exceeding four terabits per second. The campaign has already disrupted online services in multiple regions, with Australian infrastructure operators confirming they absorbed significant portions of the attack traffic.

The botnet leverages a variant of the Mirai code family, but researchers warn its command-and-control infrastructure is more resilient than earlier incarnations. Analysts at several threat-intelligence firms have observed rapid recruitment of devices exposed to the public internet without authentication or with default credentials still in place. Australian internet service providers including Telstra and Optus have notified customers whose modems and routers appear to have been co-opted, and the Australian Cyber Security Centre has issued an advisory urging households and small businesses to audit connected equipment.

For Australian organisations, the timing is particularly concerning. Retailers preparing for end-of-financial-year promotions, logistics firms managing peak shipping volumes, and financial services handling tax-time transactions all face heightened exposure to volumetric attacks. The ACSC estimates that more than 70,000 Australian devices may already be participating in the network, many of them unwittingly. As the ransomware-group-claims-attack-on-industrial-control-system-manufacturer incident earlier this year demonstrated, attackers are increasingly chaining multiple vectors to maximise pressure on victims, and this botnet fits squarely within that escalating playbook.

Inside the Malware Family Reshaping IoT Exploitation

The latest strain spreads through a combination of credential brute-forcing and exploitation of known firmware vulnerabilities, particularly in devices more than three years old. Once infected, the malware modifies firewall rules and DNS settings, then reaches out to a distributed set of control nodes hosted across multiple jurisdictions. Researchers note that the operators appear to favour bulletproof hosting services in regions with limited law-enforcement cooperation, complicating takedown efforts.

A distinctive feature of this campaign is its use of multiple protocols simultaneously. Rather than relying solely on UDP amplification or SYN floods, the botnet can pivot between DNS query floods, HTTP/2 rapid reset attacks, and direct-path floods using GRE and IPIP encapsulation. The result is a more flexible weapon that defenders cannot easily filter with simple rate-limiting rules. Australian mitigation providers, including those scrubbing traffic for Sydney and Melbourne data centres, report that single-vector defences are proving insufficient.

The operators also appear to be experimenting with peer-to-peer command channels, making the botnet harder to decapitate. Even if a handful of control servers are seized, infected nodes can fall back to encrypted gossip protocols to receive updated target lists. This resilience mirrors the design philosophy of decentralised cryptocurrencies and represents a meaningful step up from the centrally controlled Mirai variants that dominated headlines between 2016 and 2022.

Australian Networks Bear the Brunt of Volumetric Floods

Local telcos and content delivery providers confirm that Australian IP ranges have featured prominently in the botnet's target list over recent weeks. Melbourne-based gaming platforms, Adelaide government portals, and Brisbane e-commerce sites have all experienced intermittent outages, with some attacks lasting more than twelve hours. NBN Co has acknowledged that a small number of its customer-premises equipment models were among those actively recruited, and has begun pushing automatic firmware updates to affected lines.

The Australian Signals Directorate, working with the ACSC, has been coordinating with international partners to disrupt the control infrastructure. Under Australia's Criminal Code Act 1995, participation in a botnet — knowingly or recklessly — can attract significant penalties, and authorities have signalled they are prepared to prosecute individuals whose devices are used to launch attacks. Households are being urged to check router admin interfaces for unfamiliar DNS settings and to replace equipment that no longer receives security patches.

Beyond the technical response, the episode highlights a behavioural pattern that security teams across Sydney, Perth, and Canberra have flagged repeatedly: Australian consumers tend to retain networking gear far longer than the recommended lifecycle. ISP-supplied modems often remain in service for five to seven years, well past the point at which manufacturers cease issuing updates. This longevity, while cost-effective for households, creates a vast reservoir of vulnerable equipment that attackers can readily exploit.

Tracking the Evolution of IoT-Powered Botnets

Over the past decade, several distinct botnets have leveraged compromised connected devices to launch record-scale attacks. The comparison below summarises the most notable campaigns, illustrating how each generation has built upon the techniques of its predecessors while introducing new methods of propagation and resilience.

Botnet Peak Estimated Size Peak Attack Volume Primary Devices Targeted Notable Innovation
Mirai (2016) ~600,000 devices ~1.2 Tbps Routers, IP cameras, DVRs Source code release
Satori ~300,000 devices ~700 Gbps Home gateways Zero-day exploitation
Meris (2021) ~250,000 devices ~2.1 Tbps MikroTik routers HTTP/2 rapid reset
Mantis (2022) ~1,000 instances ~1.5 Tbps VPS and IoT hybrid Proxy-based architecture
Current campaign ~750,000 devices ~4.0+ Tbps Mixed IoT and small office gear Multi-protocol, P2P fallback

The progression shows a clear pattern: each wave adopts the most effective techniques from earlier operations while adding new layers of obfuscation. The current campaign's blend of volumetric scale and decentralised control represents the most challenging combination defenders have yet faced.

Recognising a Compromised Device on Your Network

For households and small businesses, identifying infected equipment before it causes further damage remains the first line of defence. The following indicators often appear on networks hosting compromised IoT devices, and security teams in Brisbane and Melbourne report they are the most reliable early-warning signals.

When these signs are observed, the affected device should be disconnected from the network immediately and reset to factory settings. Australian users can also report suspected infections to the ACSC's ReportCyber portal, which helps build a national picture of botnet activity and supports takedown coordination with international partners.

Building Organisational Resilience Against the Next Wave

For larger Australian organisations — particularly those running customer-facing portals, financial services platforms, or critical infrastructure — the current campaign underscores the need for layered defences that assume volumetric attacks will succeed at some point. The following practices have proven effective across recent incidents observed in Sydney and Perth.

For smaller operators and franchise businesses — including cafés, retail outlets, and clinic networks — the practical reality is that enterprise-grade scrubbing may be unaffordable. In these cases, working with managed security providers who offer shared mitigation pools is often the most cost-effective path. Many owners also begin by securing endpoint protection through services such as security activation, which now commonly bundle IoT security modules alongside traditional malware defence.

Australia's broader regulatory environment reinforces these defensive priorities. The Security of Critical Infrastructure Act imposes enhanced obligations on operators of systems deemed nationally significant, while the Notifiable Data Breaches scheme under the Privacy Act ensures that organisations suffering outages affecting personal information must notify affected individuals and the Office of the Australian Information Commissioner. Together, these frameworks create both carrots and sticks that push operators toward the kind of layered resilience this latest botnet campaign demands.

Researchers tracking the operators behind this network say the infrastructure continues to evolve. Already, samples suggest experimentation with encrypted firmware payloads and stealthier persistence mechanisms that survive factory resets. Australian defenders, supported by the ACSC and industry partners, will need to match that pace. The cost of complacency, as recent outages have shown, is measured not just in downtime but in customer trust.