Unit 42

@unit42_intel · Twitter ·

Since March 2026, we have tracked ENIBot, a rapidly expanding Mirai-derived IoT botnet, capturing 7,504 unique bot IPs globally. The campaign escalated brute-force and ADB exploitation attacks through June and July. Details at https://bit.ly/3UepRJh

This is a line graph titled "ENIBot/HuntBot Campaign — Daily Scanning Attempts." It charts the activity level over time, from March 16 to July 20, 2026. The graph shows a significant increase in activity, with a sharp peak around early June followed by fluctuations. The background is dark, and the line is a bright blue. A detailed diagram illustrating a botnet attack process. The flow includes several stages. The diagram shows infection, propagation, and attack paths, involving known entities. Components include bot devices, C2 server, and the final target. Various arrows depict the flow and interactions between these components. Code snippet illustrating a Python script dropped by a C2 server for malicious activities. The script includes functions to generate random cloud IPs, scan IPs to propagate. Annotations indicate actions like generating random cloud IP addresses and scanning. A comment notes that the bot supports four DDoS methods via C2 commands.