Mirai Botnet Activity Surges After Hackers Compromise cPanel Hosting Servers
Brief
Mirai-like botnet activity sharply increased in early May 2026 after attackers apparently compromised hosting servers running cPanel and WHM administration software.
Japan’s JPCERT/CC reported that its TSUBAME Internet threat-monitoring sensors detected a major rise in malicious packets targeting Telnet services over TCP port 23.
The surge began on April 30 and continued into early May before gradually declining. The traffic showed characteristics associated with Mirai and related variants.
Mirai is widely known for infecting exposed Internet-connected devices and using them as bots for scanning, brute-force attacks, and distributed denial-of-service operations.
However, the latest activity highlights that servers, not only consumer IoT devices , can also become part of botnet infrastructure.
