A large-scale botnet named Eleven11bot is alarming cybersecurity experts as it controls over 30,000 devices to carry out unprecedented large-scale Distributed Denial of Service (DDoS) attacks. According to security researchers at Nokia, this botnet primarily exploits surveillance cameras and Shenzhen DVRs, causing attacks that last for days and disrupting the operations of many critical systems.
While there is no evidence yet that Eleven11bot is backed by a state-sponsored organization, its impact is significant, with some attacks reaching 6.5 terabits per second (Tbps), breaking the previous record of 5.6 Tbps recorded in January this year.
Eleven11bot Botnet: A Global-Scale Cyber Threat
Experts from the Nokia Deepfield Emergency Response Team first detected Eleven11bot in late February when a large number of compromised IP addresses simultaneously launched attacks with massive data traffic. Unlike typical DDoS attacks that target server resources, Eleven11bot focuses on overwhelming network bandwidth, severely impacting systems.
This botnet has targeted telecommunications service providers, online gaming hosting systems, and many other critical infrastructures. Some victims experienced disruptions for several days due to their inability to withstand the massive volume of data generated by Eleven11bot.
According to Nokia’s report, 24.4% of infected devices are from the United States, making it the most heavily affected region. However, Eleven11bot has a widespread global reach and could continue to spread.
Jérôme Meyer, a security expert at Nokia, stated:
“This botnet is much larger in scale than typical DDoS attacks. The attack intensity ranges from hundreds of thousands to hundreds of millions of packets per second.”
Initially, Nokia estimated that Eleven11bot had about 30,000 devices participating. However, the Shadowserver Foundation suggests the actual number could reach up to 86,000 devices. Conversely, security firm Greynoise provided a much lower figure, only about 5,000 devices, with most activity originating from Iran (61%).
Meyer dismissed the estimates from Shadowserver, arguing that the figure is inflated due to errors in the infected device identification method. However, he still maintained that the actual number of controlled devices fluctuates between 20,000 to 30,000 IPs.
Origins and Prevention Measures for Eleven11bot
Security researchers believe that Eleven11bot is a new variant of Mirai—a notorious malware that first appeared in 2016, specializing in exploiting Internet of Things (IoT) devices such as security cameras, routers, and DVR recorders. This botnet can infiltrate devices by exploiting default passwords or unpatched software vulnerabilities.
According to Greynoise, Eleven11bot has exploited security vulnerabilities on Shenzhen TVT-NVMS 9000 DVRs, which use HiSilicon chips, to turn these devices into DDoS attack tools.
Measures to Protect Devices from Eleven11bot
Experts recommend the following measures to protect IoT devices from the risk of botnet attacks:
- Disable remote access if it is not strictly necessary.
- Set strong and unique passwords instead of using default passwords.
- Update firmware regularly to patch security vulnerabilities.
- Use a firewall to restrict unauthorized access.
- Monitor network traffic to detect abnormal signs such as sudden bandwidth spikes.
Botnet attacks are becoming increasingly sophisticated and larger in scale. Protecting IoT devices from botnets like Eleven11bot is essential to prevent large-scale DDoS attacks, helping to protect network infrastructure and online systems globally.


