JPCERT/CC Reports Surge in Mirai-Like Telnet Traffic Amid cPanel Exploitation

Summary
JPCERT/CC’s April–June 2026 monitoring found a sharp global surge in Mirai-like traffic to port 23/TCP. The increase may have been linked to Mirai infections exploiting a cPanel/WHM authentication-bypass vulnerability.
Key points
- TSUBAME sensors recorded a sharp increase in Mirai-like packets targeting 23/TCP beginning April 30, 2026, followed by a gradual decline.
- The source IPs included hosts at several hosting providers, many showing cPanel administration interfaces.
- JPCERT/CC said the surge may have been associated with Mirai or variant infections exploiting cPanel/WHM vulnerability CVE-2026-41940, which can enable authentication bypass and system compromise; monitoring data alone could not establish the cause.
- Traffic from Japan followed a similar pattern and peaked at about 15 times its pre-surge level; observations indicated infections were broadly distributed rather than concentrated in one region.
- Port 23/TCP ranked among the most frequently observed destinations, while scanning of ports 80, 8080, and 22/TCP appeared across most monitored networks.
- Recommended defenses include promptly patching vulnerabilities, restricting remote access, replacing weak passwords, and checking processes and network communications if infection is suspected.
- JPCERT/CC reported no unusual activity requiring a special alert during the quarter.
Article Details
- Publisher
- JPCERT/CC
- Report Period
- 2026-04-01 to 2026-06-30
- Scope
- TSUBAME sensor observations in Japan and overseas
- Sample Size
- Total sensor count not disclosed; eight sensors appear in the destination-port comparison.
- Key Statistics
- Mirai-like packets targeting 23/TCP surged on 2026-04-30 before gradually declining.
- During the surge, Mirai-like traffic originating from Japan and targeting 23/TCP reached approximately 15 times its pre-surge level.
- 23/TCP was the most frequently observed destination port on most of the eight sensors in the comparison.
- Overseas sensors received more packets per sensor per day than sensors in Japan during the reporting period.
- Recommendations
- Promptly address vulnerabilities, restrict remote access, and replace weak passwords to reduce the risk of Mirai and variant infections.
- If infection is suspected, review running processes and network communications to check whether the system is operating as intended.
CVE
Malware
Products
Tools
Countries
CanadaSharp increases were also observed around May 1 in several other regions, including Germany, France, and Canada (Figure 3).FranceSharp increases were also observed around May 1 in several other regions, including Germany, France, and Canada (Figure 3).GermanySharp increases were also observed around May 1 in several other regions, including Germany, France, and Canada (Figure 3).JapanThis TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the JPCERT/CC Quarterly Report. This article covers monitoringUnited StatesWhen the packets were aggregated by source region, the United States accounted for the largest share.