JPCERT/CC reported that 23/TCP remained the most frequently targeted destination in TSUBAME internet monitoring data, but the share of traffic with Mirai-like characteristics fell from about 70% at the start of FY2025 to roughly 30% by the end of the fiscal year. The organization said overseas sensors received more packets than domestic sensors, while some sensors recorded heavier activity on 443/TCP, indicating attackers were not limited to traditional Telnet-focused probing.
From June 2025 onward, JPCERT/CC observed increased non-Mirai-like scanning from compromised IoT devices including surveillance cameras, DVRs, NAS devices, broadband routers, Korean-made DVRs, and Chinese-made routers. It also found that Mirai-like sources were communicating over ports beyond 23/TCP, suggesting attempts to reach internet-exposed services and exploit known product vulnerabilities; JPCERT/CC said it shared the trend data with domestic product developers and telecommunications operators and urged firmware updates, secure configuration, and exposure checks such as port scans or SHODAN searches.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-03, JPCERT/CC published its TSUBAME Report Overflow for January to March 2026, summarizing FY2025 Japan-related monitoring trends. The report said scans targeting 23/TCP remained most common, Mirai-like traffic from Japan declined over FY2025, and some Mirai-like sources were communicating over ports beyond 23/TCP.
From June 2025 onward, JPCERT/CC observed increased scanning from compromised IoT devices whose traffic did not match Mirai-like characteristics. The devices included surveillance cameras, DVRs, NAS devices, broadband routers, Korean-made DVRs, and Chinese-made routers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceblogs.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.