Your network is getting hit from three directions at once right now. North Korean hackers just wrapped a $12 million crypto theft campaign using malware planted on personal devices. A fresh Mirai botnet variant is actively recruiting end-of-life D-Link routers through a critical RCE flaw. And ICE quietly admitted it uses Graphite spyware from an Israeli vendor. These aren’t isolated incidents — they’re a coordinated pressure test on every edge you’re responsible for. IPBan and automated IP-level blocking aren’t a silver bullet, but they’re the fastest-responding layer you actually control when attackers are moving at machine speed.

Three Threats, One Exposed Edge
The North Korean campaign — attributed to a group researchers are tracking actively — didn’t rely on nation-state-grade zero-days. It used malware delivered to personal devices, harvesting credentials and session tokens from crypto users over roughly three months. That’s patient, disciplined, and effective. When attackers have that kind of access, they’re making authenticated-looking connections from compromised endpoints. Behavioral IP banning — blocking addresses that exhibit rapid authentication attempts, unusual access patterns, or connections from known hostile ranges — catches what signature-based tools miss.
The Mirai angle is more blunt. CVE-2025-29635 is a command-injection flaw in D-Link DIR-823X routers that are officially end-of-life. No patch is coming. The botnet is already recruiting. If any of those devices sit on your network perimeter — or belong to remote workers — they’re being turned into attack infrastructure right now. Mirai campaigns don’t just stop at the device; they pivot. Recruited bots probe adjacent targets, spray credentials, and flood services. Blocking known botnet egress IPs and C2 ranges the moment they appear in threat intel feeds is exactly the kind of reactive-but-fast control that buys your team time to remediate.
Then there’s Graphite. ICE’s acknowledgment that it purchases and deploys commercial spyware raises a distinct concern: if a domestic law enforcement agency is running device-level surveillance tooling, the operational security of devices connecting to your infrastructure matters more than ever. Spyware-compromised endpoints can silently exfiltrate authentication material. That traffic looks legitimate right up until it doesn’t. Geo-IP filtering and rate-limiting unusual login sources won’t stop a sophisticated implant, but they raise the cost of exploitation significantly.
Stop Assuming Your Perimeter Is Clean
Here’s the uncomfortable truth: your perimeter almost certainly includes devices you didn’t harden and connections you didn’t vet. Remote work normalized BYOD. End-of-life routers linger because replacing them costs money and causes downtime. Spyware runs silently by design. Every one of these threat stories this week exploits that assumption gap.
Concrete steps that actually move the needle:
- Audit every internet-facing device on your network against vendor EoL timelines. D-Link DIR-823X is just the latest. There are hundreds of others in the wild.
- Implement aggressive rate-limiting on all authentication endpoints — SSH, RDP, API login pages, VPN portals. Brute-force protection isn’t optional when Mirai variants are spraying credentials by default.
- Subscribe to a live threat intel feed and automate IP block-list updates. Manual list management is a losing game at botnet scale.
- Segment remote-worker traffic so that a compromised home router or personal device can’t directly reach production systems without hitting an inspection point.
- Log and alert on geographic anomalies in authentication traffic. A finance user logging in from Seoul at 3 a.m. local time is worth a second look, every time.
The common thread across all of these controls is speed. The Mirai botnet isn’t waiting for your next patch cycle. The North Korean crew ran their campaign for three months before researchers caught it. You need automated responses that fire in seconds, not tickets that get triaged in days.

IPBan Pro automates exactly this kind of edge enforcement — failed login detection, dynamic IP banning, geo-blocking, and real-time threat-feed integration — without requiring you to babysit firewall rules manually. When a Mirai node starts hammering your RDP port at 400 attempts per minute, the response needs to be automatic and immediate. That’s what it’s built for.
AI Is Already in the Fight on Both Sides
Microsoft’s latest security blog makes the point that AI-accelerated threat discovery is now table stakes — for defenders and attackers alike. The North Korean crypto campaign used malware that adapted based on the target’s device profile. The fake TradingView site pushing browser-hijacking malware this week used convincing AI-generated content to lure victims. Supply chain attacks are hitting at what SentinelOne calls “hypersonic” speed — zero-day payloads that no signature database has seen yet.
This isn’t a reason to despair. It’s a reason to be precise about what each defensive layer actually does. AI-powered detection tools are getting better at catching novel malware behavior inside the endpoint. But they don’t replace edge controls. A brute-force attack blocked at the firewall never reaches your endpoint detection stack. An IP banned after ten failed SSH attempts doesn’t get twenty more chances to find a weak credential. These aren’t competing philosophies — they’re complementary layers, and the edge layer is the cheapest one to run at scale.
The real mistake is treating IP banning as legacy technology because the threats got smarter. Botnets recruit dumb IoT devices for a reason: volume is cheap and effective. The counter to volume is automated, edge-level rejection. That math hasn’t changed, even when everything else has.
Sources
- North Korean hackers siphon more than $12 million from crypto users in sprawling campaign — The Record
- New Mirai campaign exploits RCE flaw in EoL D-Link routers — BleepingComputer
- ICE Uses Graphite Spyware — Schneier on Security
- AI-powered defense for an AI-accelerated threat landscape — Microsoft Security Blog
- Hypersonic Supply Chain Attacks — SentinelOne
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
