CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New DDoS Botnet Discovered: Over 30,000 Hacked Devices, Majority of Observed Activity Traced to Iran

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1917

As cited

Copy frozen at (site build).

threat intel

New DDoS Botnet Discovered: Over 30,000 Hacked Devices, Majority of Observed Activity Traced to Iran

Security researchers at Nokia Deepfield have identified a botnet called Eleven11bot that has compromised over 30,000 devices, primarily security cameras and network video recorders, with the majority of observed activity traced to Iran. The botnet is being used to launch distributed denial-of-service attacks at scale. The threat continues to expand globally across internet-connected devices.

Why it matters: Organizations operating security cameras, NVRs, and other IoT devices face immediate risk of compromise and should audit their device inventory, apply firmware patches, and isolate these systems on network segments to prevent botnet recruitment and DDoS participation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New DDoS Botnet Discovered: Over 30,000 Hacked Devices, Majority of Observed Activity Traced to Iran

Nokia Deepfield's Emergency Response Team identified Eleven11bot, a botnet that has compromised over 30,000 devices, chiefly security cameras and network video recorders. The botnet is being used to launch distributed denial-of-service attacks, with the majority of observed activity attributed to Iran. The threat is actively spreading across global internet-connected infrastructure.

Why it matters: Organizations relying on internet-facing security cameras and NVRs face immediate compromise risk and should audit these devices for unauthorized access, update firmware, and isolate them from critical networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary