type: incident ยท created: 2026-08-13 ยท updated: 2026-08-18 ยท tags: [incident, mirai, botnet, iot, ddos, stealth] ยท confidence: high ยท affected_sectors: [technology, telecommunications, iot] ยท au_impact: false
New Mirai Variant Adds Stealth Capabilities to Notorious Botnet Code
Researchers documented a new Mirai variant that extends the notorious DDoS botnet code with hardened stealth: encrypted communications with command-and-control servers and a built-in sniffer that scans for default access credentials. The additions reflect modern botnet operators shifting towards evading detection and harvesting credentials as they build and extend IoT botnets.
Summary
Mirai remains the foundational code for large-scale IoT-driven DDoS botnets. This variant's encrypted C2 communications and credential-sniffing capability represent an evolution toward evasion and post-compromise credential harvesting, indicating more resilient and harder-to-disrupt botnets.
Impact
- More resilient DDoS botnet infrastructure (encrypted C2 hardens detection)
- Credential harvesting of default IoT access credentials expands botnet recruitment
- Sustained DDoS risk to internet-facing services and IoT fleets
Sector
Global (Macro)
Sources
- The Record โ New Mirai Variant Adds Stealth to Botnet Code
- raw/digests/Cyber-Digest-2026-08-14