The device population behind the botnets filed at 26-0302, 26-0325 and 26-0528 is the same one in every case: consumer routers, IP cameras and digital video recorders, connected continuously, running firmware that stopped receiving updates years ago.
Three Properties, Each Individually Reasonable
These devices are cheap, because consumers buy on price. They are long-lived, because a router that works is not replaced. And they are unmanaged, because the owner is not a systems administrator and was never told they had become one.
Each property is a rational outcome of how the market works. Together they produce a permanent, growing population of internet-connected computers that nobody patches, nobody monitors and nobody is responsible for.
Enterprise Security Has No Equivalent Problem
It is worth noticing how strange this is. In a corporate environment, a device with no owner, no update path and no monitoring would be a finding. At national scale it is the default condition for the majority of connected hardware.
The mismatch matters because the consequences are not confined to consumers. The record DDoS filed at 26-0302 targeted telecommunications companies. The proxy traffic in 26-0320 lands on enterprise login pages. The estate is consumer-owned and the harm is systemic.
The Interventions That Would Work Are Not Security Products
Mandated minimum support periods with disclosure at point of sale. Automatic updates that continue past commercial end-of-life. Provider-level detection and notification when customer equipment is compromised. Liability that attaches to shipping a device that will be abandoned.
All four are regulatory and commercial choices. None of them can be bought by a security team, which is why this problem has persisted through every takedown this desk has filed.
This is an analysis file built on published research, listed below, read against the botnet files previously published by this desk. The policy conclusions are ours and labelled as such. Corrections: corrections@forensicpost.com.