A few days ago, a hacker published a list of Telnet credentials for approximately 515,000 servers, routers home devices.
The hacker posted the list on one of the most popular hacking forums. The exposed information is the IP address of each device, along with a username and password for the Telnet service (a remote access protocol that allows a device to be controlled over the internet).
According to security and a statement from the hacker himself, the data was collected after scanning the internet for devices that exposed the Telnet port. The hacker exploited default credentials and easy passwords.
These lists, also known as “bot lists,” are typically part of an IoT botnet operation. Attackers scan the internet, create bot lists, and use them to connect to devices and install malware.

Typically, these lists are not published. However, there are some exceptions, as in this case. Also, about two years ago, a list of Telnet credentials for 33,000 home routers was leaked.
The data was leaked by a DDoS service
According to the data, the list was published by a service operator DDoS-for-hire (DDoS booter).
The leaked lists contain data collected between October-November 2019. Therefore, some of these devices may now be running on a different IP address. Also, different credentials may be used.
Using IoT search engines such as BinaryEdge and Shodan, we identified devices around the world. Some devices were found on the networks of well-known internet service providers (mainly home routers and IoT devices). Other devices were found on the networks of major cloud service providers.
The risk remains
A security expert who works primarily with IoT devices said that the risk remains even if some entries on the list are no longer valid (e.g. due to IP or password changes). The devices remain exposed and these lists can be extremely useful to a skilled hacker.
An attacker could use the IP addresses included in the lists, find the internet service provider, and rescan the ISP's network to find the new IP addresses.
