TSUBAME Report Overflow (Apr-Jun 2026)
Brief
This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the JPCERT/CC Quarterly Report. This article covers monitoring results from April to June 2026.
Note: Starting in FY2026, the JPCERT/CC Internet Threat Monitoring Report has been integrated into the JPCERT/CC Quarterly Report.
Sharp Increase in Mirai-like Packets Targeting 23/TCP Observed in Early May 2026 In early May 2026, TSUBAME observed a sharp increase in packets targeting 23/TCP that exhibited Mirai-like characteristics (Figure 1). The number of packets surged on April 30, 2026, before gradually declining.
Figure 1: Trend in the number of Mirai-like packets targeting 23/TCP observed by sensors in Japan Analysis of the source IP addresses found that many were assigned to several hosting providers.
