JPCERT/CC Reports Surge in Mirai-Like Telnet Traffic Amid cPanel Exploitation

· Original article ↗

Summary

JPCERT/CC’s April–June 2026 monitoring found a sharp global surge in Mirai-like traffic to port 23/TCP. The increase may have been linked to Mirai infections exploiting a cPanel/WHM authentication-bypass vulnerability.

Key points

  • TSUBAME sensors recorded a sharp increase in Mirai-like packets targeting 23/TCP beginning April 30, 2026, followed by a gradual decline.
  • The source IPs included hosts at several hosting providers, many showing cPanel administration interfaces.
  • JPCERT/CC said the surge may have been associated with Mirai or variant infections exploiting cPanel/WHM vulnerability CVE-2026-41940, which can enable authentication bypass and system compromise; monitoring data alone could not establish the cause.
  • Traffic from Japan followed a similar pattern and peaked at about 15 times its pre-surge level; observations indicated infections were broadly distributed rather than concentrated in one region.
  • Port 23/TCP ranked among the most frequently observed destinations, while scanning of ports 80, 8080, and 22/TCP appeared across most monitored networks.
  • Recommended defenses include promptly patching vulnerabilities, restricting remote access, replacing weak passwords, and checking processes and network communications if infection is suspected.
  • JPCERT/CC reported no unusual activity requiring a special alert during the quarter.

Article Details

Publisher
JPCERT/CC
Report Period
2026-04-01 to 2026-06-30
Scope
TSUBAME sensor observations in Japan and overseas
Sample Size
Total sensor count not disclosed; eight sensors appear in the destination-port comparison.
Key Statistics
  • Mirai-like packets targeting 23/TCP surged on 2026-04-30 before gradually declining.
  • During the surge, Mirai-like traffic originating from Japan and targeting 23/TCP reached approximately 15 times its pre-surge level.
  • 23/TCP was the most frequently observed destination port on most of the eight sensors in the comparison.
  • Overseas sensors received more packets per sensor per day than sensors in Japan during the reporting period.
Recommendations
  • Promptly address vulnerabilities, restrict remote access, and replace weak passwords to reduce the risk of Mirai and variant infections.
  • If infection is suspected, review running processes and network communications to check whether the system is operating as intended.

CVE

Malware

Products

Tools

Countries

Related Articles