Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mirai and Gafgyt blocked IoT threat activity

Malware Activity
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

Mirai and Gafgyt dominated blocked IoT threat traffic, concentrating defender detections on two long-running malware families across June 2024 to May 2025. 40% of blocked IoT requests were tied to Mirai, and 35% to Gafgyt. The volume shows sustained targeting of connected devices rather than isolated bursts. Manufacturing and transportation were the most frequently targeted verticals, adding operational risk for environments that depend on always-on device connectivity.

Related Happenings

AI-driven attack surge against customer-facing mobile apps in 2026

Trend
H score43 First: 19.05.2026 15:00 Last: 19.05.2026 15:00 Sources 1

About this happening: Customer-facing mobile apps faced a sharp rise in attacks in 2026, with 87% of monitored apps hit versus 55% in 2022. The trend matters because agentic AI is l...

China-nexus threat-Flax Typhoon-Volt Typhoon alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score33 First: 23.04.2026 23:52 Last: 23.04.2026 23:52 Sources 1

About this happening: China-nexus threat actors are industrializing covert botnet infrastructure, expanding deniable reconnaissance, malware delivery, and data exfiltration against US...

NCSC-UK joint advisory on covert botnets and proxy networks

Public Sector Action
H score66 First: 23.04.2026 15:28 Last: 23.04.2026 15:28 Sources 1

About this happening: NCSC-UK and partner agencies issued a joint advisory warning that China-nexus hackers are using hijacked consumer devices as covert proxy networks to hide maliciou...

Keenadu Android backdoor embedded in firmware and app delivery paths

Malware Activity
H score27 First: 17.02.2026 16:05 Last: 17.02.2026 16:05 Sources 1

About this happening: The Keenadu Android backdoor was found embedded in firmware from multiple device brands, putting infected devices and their installed apps at risk of full compromise. The...

2025 DDoS surge targets telecommunications, service providers, and carriers

Trend
H score34 First: 05.02.2026 19:25 Last: 05.02.2026 19:25 Sources 1

About this happening: Cloudflare reports that the 2025 DDoS surge has continued into Q3 2025, with the Aisuru botnet driving more than 1,300 attacks in three months and a record pea...

Timeline

  1. 05.11.2025 11:30 2 articles · 8mo ago

    Initial report: Mirai and Gafgyt blocked IoT threat activity

    Initial Disclosure

    Mirai and Gafgyt were the dominant families in blocked IoT threat requests over June 2024 to May 2025. The split shows sustained malware pressure on connected devices and a need for stronger traffic filtering.

    Show sources