IoT and Botnets: The Invisible Threat of Connected Devices
Mirai legacy, IP cameras, routers, record DDoS botnets 2025, unpatched firmware, Cyber Resilience Act, network segmentation, and defenses.
In 2025, Cloudflare reported mitigating DDoS attacks exceeding 5.6 Tbps, a record fueled by botnets composed of compromised IoT devices. IP cameras, home routers, NAS devices, network printers: these devices that nobody updates have become the favorite weapon of botnet operators.
The Mirai legacy: still alive
Mirai, the botnet discovered in 2016 that paralyzed Dyn DNS and rendered parts of the Internet inaccessible (Twitter, Netflix, Reddit), has not disappeared. Its source code, published by its creator, has spawned dozens of variants still active today: Mozi, Gafgyt, Kaiten, BotenaGo. These variants target the same fundamental weaknesses: default credentials, open Telnet/SSH ports, unupdated firmware.
According to Nozomi Networks researchers, over 30% of IoT attacks observed in 2025 still use techniques directly derived from Mirai.
Most vulnerable devices
-
IP cameras: default credentials (admin/admin), rarely updated firmware, exposed RTSP protocols. Manufacturers like Hikvision and Dahua have been regularly cited in CERT-FR security advisories
-
Home and SMB routers: UPnP vulnerabilities, administration interfaces exposed to the Internet, end-of-support firmware. TP-Link, Netgear, and D-Link routers are among the most targeted
-
NAS (Synology, QNAP): directly exposed to the Internet for remote access, targets of specialized ransomware (Deadbolt on QNAP in 2022, continuous attacks since)
-
Network printers: unsecured printing protocols, web administration interfaces with default credentials
-
Medical devices: infusion pumps, patient monitors, MRI machines: the healthcare sector combines obsolete devices with life-critical importance
DDoS botnets: 2025 records
2025 saw an unprecedented escalation in DDoS attacks:
-
5.6 Tbps mitigated by Cloudflare, the largest publicly documented DDoS attack
-
IoT botnets now comprise hundreds of thousands of compromised devices
-
Attacks combine volumetric (UDP flood) and application-layer (HTTP/2 Rapid Reset, exploiting CVE-2023-44487)
-
The cost of a 100,000-device DDoS botnet on the black market: approximately $500 per hour of attack
Cyber Resilience Act: manufacturer obligations
The European Cyber Resilience Act (CRA), adopted in 2024 with progressive enforcement through 2027, imposes for the first time cybersecurity obligations on manufacturers of digital products:
-
Security by design: no default passwords, encrypted communications, secure update mechanism
-
Mandatory security updates: throughout the product lifecycle (minimum 5 years)
-
Vulnerability notification: manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours
-
Mandatory SBOM: a Software Bill of Materials must document all software components
-
Penalties: up to 15 million euros or 2.5% of global revenue for non-compliance
How to protect yourself
While waiting for the CRA to take effect, here are measures to implement now:
-
Network segmentation: isolate IoT devices in a dedicated VLAN without access to the corporate network. A firewall between the IoT VLAN and the rest of the network is essential
-
IoT asset inventory: you cannot protect what you do not know about. ThreatClaw's ASM with Shodan detects IoT devices exposed on your IP ranges
-
Change default credentials: systematic, documented, verified
-
Disable unused services: Telnet, UPnP, web administration if not in use
-
Traffic monitoring: an IoT device communicating with IPs in Russia or China at 3 AM is not normal. ThreatClaw detects these anomalies
FAQ
How do I know if my IoT devices are compromised?
Signs include: abnormal network traffic (volume, destinations), high CPU/bandwidth consumption, unexplained reboots, inability to connect to the administration interface. An Nmap scan of your internal IP ranges can reveal unexpected open services. ThreatClaw monitors these indicators continuously.
Will the CRA solve the problem?
The CRA is a major step but not a complete solution. It does not cover already deployed devices (billions), and its effective implementation will depend on enforcement by national authorities. It will take years before the existing IoT fleet is replaced by compliant devices.
Is my company affected by IoT botnets?
Yes, in two ways: your own IoT devices can be compromised and used in a botnet (potential liability), and you can be the target of DDoS attacks by IoT botnets. Check our plans for an exposure assessment.
How to segment a network with IoT devices?
The standard solution is a dedicated VLAN with an inter-VLAN firewall. For SMBs, a router with VLAN support (Ubiquiti, MikroTik) suffices. For larger environments, a NAC (Network Access Control) solution like Cisco ISE or FortiNAC automates segmentation. The key is that IoT devices must not be able to initiate connections to workstations and servers.
Related articles
Manufacturer obligations, SBOM, 5-year security updates, and CE marking: everything the CRA changes for connected products.
We detonated a live Phobos sample. Here is what it does, deleting shadow copies, killing the firewall, and the Sigma rule that catches it, validated across multiple samples with zero false positives.
Emotet, a notorious botnet and malware loader, remains a critical threat to SMBs. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this persistent adversary.
Drokbk, a remote access trojan, evades defenses with keylogging and screen capture. ThreatClaw now detects it with zero false positives—protect SMBs and MSSP clients.