Botnets are continuing to target default username/password combinations seen in the Mirai source code. Arbor Networks found at least 1,005 new ones targeted by botnets in September. The biggest source of the IoT-targeting botnet attacks it saw in September was Russia, followed by China, Brazil, the U.S. and South Korea. Attackers have been creating customized lists of default or common credentials to target since Mirai’s code became public in September 2016 (see: Free Source Code Hacks IoT Devices to Build DDoS Army)”]
Source: https://www.govinfosecurity.com/botnets-keep-brute-forcing-internet-things-devices-a-11637

