Many of the IoT-based botnets we have seen in the past few years use telnet to spread. These botnets often attempt a dictionary attack against the telnet service, opened on either TCP port 23 or port 2323. Disabling the telnet service and closing these ports will mitigate a substantial attack vector and force botnets and other attackers to attempt access via other means. A list of additional ports to lock down is provided here. In some cases, such as HTTP, it is not practical to close the ports so monitor for signs of malicious activity:
Port | Use | Malware type | Reference |
21 | Dictionary attacks on FTP service | Various | |
23 | Dictionary attacks on telnet service | Mirai, others | https://isc.sans.edu/forums/diary/What+is+happening+on+2323TCP/21563/ ... |