Also available in Persian — نسخه فارسی EN فا
🟠 Important ❓ Unknown

Cyber Attack Likely Originating from the Islamic Republic; Hacking of 30,000 Devices with Botnet

Jun 28, 2026 June 28, 2026 5 min read 📰 VOA Persian
📋 Key Takeaway

A new botnet named Yazd11Bot has infected over 30,000 devices, primarily in Iran, posing a significant threat to online services. Analysts speculate potential links to Iranian hackers or government-backed groups, highlighting the need for improved cybersecurity measures. The extensive DDoS attacks executed by this botnet underscore the vulnerabilities in IoT devices and the importance of international cooperation in cybersecurity.

🔍 Quick Context Guide
💡 Bottom Line: The Yazd11Bot poses a significant threat to global cybersecurity.

👥 Key Players

Yazd11Bot ACTOR
Botnet
"Yazd11Bot has become a serious threat to telecommunications service providers and online platforms."
Iran (ایران) ACCUSED
Country
"About 61% of the 1,042 IP addresses associated with this botnet are linked to Iran."
GreyNoise QUOTED
Security Research Company
"According to data provided by the company GreyNoise..."
Nokia Deepfield QUOTED
Network Analysis Company
"These attacks, also analyzed by Nokia Deepfield..."
Iranian hackers ACCUSED
Hacking Group
"Some analysts have suggested that these attacks may have been executed by Iranian hackers..."

⚡ Actions

Yazd11Bot ATTACK telecommunications service providers, online platforms
"Yazd11Bot has become a serious threat to telecommunications service providers and online platforms."
Confidence: 90%
Yazd11Bot EXECUTE critical servers, networks
"The primary goal of this botnet is to conduct DDoS attacks against critical servers and networks."
Confidence: 90%
Iran LINK Yazd11Bot
"About 61% of the 1,042 IP addresses associated with this botnet are linked to Iran."
Confidence: 70%

📰 What Happened

Iran-linked Yazd11Bot infects 30,000 devices, executing large-scale DDoS attacks.

  • Yazd11Bot attack telecommunications service providers, online platforms
  • Yazd11Bot execute critical servers, networks
  • Iran link Yazd11Bot

💡 Why It Matters

🇮🇷 For Iran: Because it highlights vulnerabilities in Iranian internet infrastructure.
🌍 Regional: Because it raises concerns about regional cyber security.
🌐 International: Because it indicates potential Iranian state-sponsored cyber activities.

📚 Background

The Yazd11Bot poses a significant threat to global cybersecurity.

📝 Key Evidence

"About 61% of the 1,042 IP addresses associated with this botnet are linked to Iran."
→ Indicates potential Iranian involvement in the botnet.
"The primary goal of this botnet is to conduct DDoS attacks against critical servers and networks."
→ Highlights the intent and capability of Yazd11Bot.
📡 Source: NEUTRAL
📊 Confidence: 80%
VOA Persian is generally considered a reliable source for news.

In today's world, where dependence on the internet and connected devices has significantly increased, cyber threats have also become increasingly complex and widespread. One of the latest identified threats in this area is the botnet 'Yazd11Bot', discovered by security researchers, which has the capability to execute distributed denial-of-service (DDoS) attacks on a large scale. This botnet, by infecting over 30,000 internet-connected devices, primarily security cameras and network video recorders (NVRs), has become a serious threat to telecommunications service providers and online platforms. Yazd11Bot operates as a malicious network of infected devices, using these devices to carry out cyber attacks. Initial analyses indicate that this botnet primarily targets devices with weak or default passwords and can be infiltrated through insecure protocols such as Telnet and SSH. This method is one of the most common ways to infect Internet of Things (IoT) devices, which are always targeted by hackers due to security vulnerabilities. According to data provided by the company GreyNoise, about 61% of the 1,042 IP addresses associated with this botnet are linked to Iran. This statistic indicates that a significant portion of the infrastructure of this botnet is located in Iran, although it is unclear whether these activities are organized or the result of security negligence by users and IoT equipment providers in the region. Yazd11Bot employs several methods to infect victim devices: using weak and default passwords: This method is one of the most important ways to penetrate IoT devices. Many users and companies do not change the default passwords after setting up their devices, which allows attackers to gain access. Brute-force attacks: This type of attack involves automatically testing a large number of password combinations until the correct password is identified. Scanning networks for open ports: Yazd11Bot continuously searches the internet for devices with open Telnet and SSH ports that can be easily vulnerable to attacks. Executing distributed denial-of-service (DDoS) attacks: The primary goal of this botnet is to conduct DDoS attacks against critical servers and networks. These attacks involve sending millions of fake requests to targeted servers to take them offline. The extensive scale of DDoS attacks carried out by this botnet is among the largest cyber attack campaigns since Russia's attack on Ukraine in February 2022. These attacks, also analyzed by Nokia Deepfield, indicate that the intensity of malicious traffic generated by this botnet has varied from several hundred thousand to several hundred million packets per second. Such a massive volume of malicious traffic can cause widespread disruption in telecommunications and internet networks. According to security experts, DDoS attacks can target online gaming platforms, financial services, banks, internet providers, and even government infrastructures. This highlights the urgent need to strengthen cyber defense infrastructures. The potential role of the Islamic Republic in the development of the botnet is a contentious point regarding Yazd11Bot, as a large portion of the IP addresses associated with it are located in Iran. Some analysts have suggested that these attacks may have been executed by Iranian hackers or groups supported by the Islamic Republic. However, others believe that this botnet has merely expanded due to existing security weaknesses in internet infrastructures in Iran. In recent years, some government-backed hacking groups of the Islamic Republic have been accused of conducting cyber attacks on an international level. Multiple reports indicate that some of these groups have participated in DDoS attacks and cyber sabotage operations against Western organizations. However, no definitive evidence has yet been published linking the Islamic Republic directly to this specific botnet. To prevent the spread and impact of this botnet, security experts recommend that users and companies implement the following security measures: changing default passwords of IoT devices: Users should change the default passwords of their devices as soon as possible and use strong and complex passwords. Closing insecure ports and using firewalls: Many infected devices have open Telnet and SSH ports. It is recommended that users close these ports or use a firewall to restrict unauthorized access. Updating operating systems and software: Many botnet attacks exploit security vulnerabilities in older versions of operating systems. Regularly updating software can prevent many of these attacks. Using intrusion detection and prevention systems (IDS/IPS): These systems can identify suspicious activities on the network and prevent the spread of threats. Monitoring and reviewing network logs: Network administrators should regularly review network activity logs and identify any unusual activities. Yazd11Bot is an example of new threats in the world of cybersecurity, demonstrating that IoT devices remain a primary target for attackers. This botnet has managed to infect tens of thousands of devices and execute extensive attacks against internet service providers. In this context, users and companies must strengthen security measures and implement stricter protocols to prevent the infiltration of such botnets. The digital world faces increasing threats, and combating these attacks requires international cooperation and enhanced security awareness at both individual and organizational levels.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →