Skip to content
Mirai Botnets Surge as Major DDoS and Proxy Abuse Threats

Mirai Botnets Surge as Major DDoS and Proxy Abuse Threats

First seen 25 Mar 2026, 21:48 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 26, 2026 at 21:17 UTC
  • •Mirai botnets have evolved into platforms for large-scale DDoS and proxy abuse.
  • •Over 21,000 C2 servers were detected from July to December 2025.
  • •The use of Mirai bots as residential proxies enhances their stealth in cyber operations.

Mirai-based botnets have significantly evolved, transitioning from basic IoT malware to sophisticated platforms for large-scale DDoS attacks and proxy abuse. Over 21,000 command-and-control (C2) servers were identified between July and December 2025, indicating a substantial increase in their operational capacity. The botnets are now being utilized not only for traditional DDoS attacks but also as residential proxies, enhancing their stealth and effectiveness in cybercrime. This evolution poses a serious threat to various sectors, particularly those relying on IoT devices. The rise in activity has been linked to a broader trend of botnet-driven threats that have surged over the past year. As of now, the situation remains critical, with ongoing monitoring of Mirai's developments necessary for effective defense strategies.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 198d ago How this analysis works

Timeline

2025-07-01
Detection of over 21,000 C2 servers begins
2025-12-31
C2 server count reaches over 21,000
2026-03-25
Articles published detailing Mirai's evolution

More articles in this cluster (2)

Following this threat?

Track Mirai in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed