Skip to content

Mirai

Mirai is a self-propagating Linux-based IoT botnet malware created by Paras Jha, Josiah White, and Dalton Norman.

Profile source: Mallory opens in a new tab

Mirai

Family profile

Mirai is a self-propagating Linux-based IoT botnet malware created by Paras Jha, Josiah White, and Dalton Norman. It compromises internet-exposed embedded devices, principally IP cameras, DVRs, routers, and other network-connected systems, then enrolls them into a centrally controlled botnet for distributed denial-of-service operations. Mirai originally propagated by scanning for Telnet services and attempting a hard-coded set of factory-default or commonly used credentials. Successful logins were reported to loader infrastructure, which selected and executed an architecture-appropriate payload. Later variants and Mirai-derived families have also adopted exploitation of vulnerabilities affecting routers, IoT products, and internet-facing application servers, including Log4Shell and Spring4Shell. Mirai uses process-name randomization, removal of its on-disk binary, and termination of competing processes to reduce detection and maintain control of infected devices. Infections are generally non-persistent and can commonly be removed by rebooting the affected device unless a descendant adds persistence. The botnet became prominent in 2016 through exceptionally large DDoS attacks against gaming services, OVH, KrebsOnSecurity, and Dyn; the Dyn attack disrupted DNS resolution for major online services. Its source code was subsequently released publicly, enabling extensive reuse and the development of numerous variants and descendants. The original operators were identified, arrested, and sentenced in the United States.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
73 IP / 23 hostnames

Leading locations

  • NL23
  • DE15
  • US11
  • CN4
  • FI3
  • FR2
  • HK2
  • IE2
  • MX2
  • RU2
  • SG2
  • AT1

Leading providers

  • Storm Industries LLC10
  • TechTies Inc.5
  • HostPapa4
  • Alsycon B.V.3
  • CHINA UNICOM China169 Backbone3
  • DigitalOcean, LLC3

Infrastructure traits

  • Hosting 73
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

12 named in public reporting
Lazarus

Observed commodity malware: Agent Tesla and Mirai bot.

Keksec

All the samples are classified as Gafgyt or Mirai by most detection engines.

Paras Jha

Satori, also known as “Masuta,” is a variant of the Mirai botnet, a powerful IoT malware strain that first came online in July 2016.

BestBuy

The publication of proof-of-concept (PoC) exploit code in a public vulnerabilities database has lead to increased activity from Mirai-based IoT botnets... Attackers are using the above PoC to break into exposed devices and infect them with Mirai.

Popopret

The publication of proof-of-concept (PoC) exploit code in a public vulnerabilities database has lead to increased activity from Mirai-based IoT botnets... Attackers are using the above PoC to break into exposed devices and infect them with Mirai.

Killnet

Even Killnet relies on volunteer cyber partisans, but its structure also includes dedicated sub-groups leveraging IoT botnet infrastructures such as Mirai.

Flax Typhoon

FBI Director Chris Wray last Wednesday disclosed an operation to disrupt a Mirai-variant botnet that has exploited more than 260,000 IoT devices globally.

angelalk21

The operator -- a Chinese-speaking actor using the handle angelalk21 (QQ: 597118859, Telegram: @Kuru_x86) -- runs a Mirai-fork botnet with a novel DNS byte-swap anti-analysis technique that causes passive DNS researchers to track decoy IPs in Japan and the US while the real C2 sits in Germany.

Matrix

...ultimately deploying the Mirai botnet malware and other DDoS-related programs on compromised devices and servers.

InfectedSlurs

Hackers are exploiting vulnerabilities in end-of-life GeoVision IoT devices and Samsung’s MagicINFO server to expand the Mirai botnet... Akamai observed attacks in April targeting GeoVision devices... to download and run an ARM variant of Mirai dubbed LZRD.

Bloody Wolf

All of these files belong to the infamous IoT malware named Mirai.

Exploited software

Vulnerabilities linked to Mirai

109 CVEs
CVE-2018-10562 Dasan GPON Router Diagnostic Ping Command Injection CVE-2018-10561 Dasan GPON Router Authentication Bypass CVE-2022-22965 Spring4Shell CVE-2021-44228 Log4Shell CVE-2025-55182 React2Shell CVE-2017-17215 Authenticated Command Injection in Huawei HG532 CVE-2024-7029 Unauthenticated Command Injection in AVTECH AVM1203 IP Cameras CVE-2023-26802 RCE in DCN DCBI-Netlog-LAB nsg_masq.cgi CVE-2016-10372 Remote Command Execution in Eir D1000 TR-064 Service CVE-2023-26801 Command Injection in LB-LINK /goform/set_LimitClient_cfg CVE-2023-27076 Command Injection in Tenda G103 (language parameter) CVE-2026-41940 cPanel & WHM Login Flow Authentication Bypass CVE-2014-8361 Realtek SDK miniigd NewInternalClient Remote Code Execution CVE-2020-10987 Tenda AC15 AC1900 OS Command Injection CVE-2021-36260 Unauthenticated Command Injection in Hikvision Web Server CVE-2018-14558 Tenda AC7/AC9/AC10 setUsbUnload Command Injection CVE-2019-15107 Webmin password_change.cgi Command Injection RCE CVE-2021-32305 Command Injection in WebSVN search parameter CVE-2019-14927 Unauthenticated Configuration Download in Mitsubishi Electric/INEA ME-RTU CVE-2018-11510 Unauthenticated RCE in ASUSTOR ADM 3.1.0.RFQ3 portal/apis/aggrecate_js.cgi CVE-2018-7841 Unauthenticated RCE in Schneider Electric U.motion Builder track_import_export CVE-2018-6961 Command Injection in VMware NSX SD-WAN Edge Local Web UI CVE-2015-2051 D-Link DIR-645 HNAP SOAPAction Command Injection CVE-2022-28958 Non-existent Command Injection in D-Link DIR-816L (Disputed CVE-2022-28958) CVE-2017-5174 Authentication Bypass in Geutebruck G-Cam/EFD-2250 1.11.0.12 CVE-2018-6530 OS Command Injection in D-Link DIR Series Routers soap.cgi CVE-2019-2725 Oracle WebLogic Server AsyncResponseService Deserialization RCE CVE-2022-26258 Remote Command Execution in D-Link DIR-820L /lan.asp DeviceName Parameter CVE-2019-3929 Unauthenticated Command Injection in AWIND OEM Wireless Presentation Platforms CVE-2018-17173 Remote Code Execution in LG SuperSign EZ CMS CVE-2019-19356 Authenticated RCE in Netis WF2419 tracert diagnostic tool CVE-2018-20062 ThinkPHP filter Parameter Remote Code Execution CVE-2021-27561 Unauthenticated Command Injection in Yealink Device Management 3.6.0.20 CVE-2021-27562 Improper NSPE handler-mode access control in Arm Trusted Firmware-M CVE-2021-22502 Remote Code Execution in Micro Focus Operation Bridge Reporter 10.40 CVE-2020-9054 Zyxel NAS and Firewall Pre-Authentication OS Command Injection CVE-2020-25506 Command Injection RCE in D-Link DNS-320 system_mgr.cgi CVE-2020-26919 Unauthenticated RCE in NETGEAR ProSAFE Plus JGS516PE and GS116Ev2 CVE-2020-9020 OS Command Injection in Iteris Vantage Velocity Field Unit timeconfig.py CVE-2016-10401 Hardcoded super-user password in ZyXEL PK5001Z CVE-2021-38647 OMIGOD unauthenticated RCE in Open Management Infrastructure CVE-2024-6047 OS Command Injection in GeoVision EOL Devices CVE-2017-6884 Command Injection in Zyxel EMG2926 nslookup Diagnostic Function CVE-2017-5638 Apache Struts Jakarta Multipart Parser Remote Code Execution CVE-2024-11120 Unauthenticated OS Command Injection in GeoVision EOL Devices CVE-2017-18377 Command Injection in WIFICAM set_ftp.cgi CVE-2020-8515 Unauthenticated RCE in DrayTek Vigor mainfunction.cgi CVE-2020-5722 Unauthenticated SQL Injection in Grandstream UCM6200 HTTP Interface CVE-2016-6277 Remote Command Injection in NETGEAR Multiple Routers CVE-2019-7276 Remote Root Code Execution in Optergy Proton/Enterprise Backdoor Console CVE-2018-19276 Unauthenticated Insecure Deserialization RCE in OpenMRS CVE-2019-16920 D-Link PingTest Unauthenticated Command Injection CVE-2011-3587 Command Execution in Zope OFS/misc_.py p_ Class CVE-2018-13023 Command Injection in Xiaomi Mi Router 3 wifi_access CVE-2019-10655 Unauthenticated RCE in Grandstream Devices via Authentication Bypass and Command Injection CVE-2015-1187 Command Injection in D-Link and TRENDnet ping.ccp CVE-2020-1956 Command Injection in Apache Kylin RESTful APIs CVE-2020-10173 Authenticated Command Injection in Comtrend VR-3033 Diagnostics CVE-2019-14931 Remote OS Command Injection in Mitsubishi Electric and INEA ME-RTU CVE-2013-2251 Apache Struts 2 OGNL Injection RCE via action/redirect/redirectAction Prefixes CVE-2019-16057 Command Injection in D-Link DNS-320 login_mgr.cgi CVE-2022-26134 Atlassian Confluence OGNL Injection Remote Code Execution CVE-2022-37055 Buffer Overflow in D-Link Go-RT-AC750 hnap_main CVE-2024-10914 OS Command Injection in D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi CVE-2024-10915 OS Command Injection in D-Link account_mgr.cgi cgi_user_add CVE-2024-40891 Telnet Command Injection in Zyxel VMG4325-B10A CVE-2025-1316 OS Command Injection in Edimax IC-7100 IP Camera CVE-2025-29635 Command Injection in D-Link DIR-823X /goform/set_prohibiting CVE-2026-34908 Improper Access Control in Ubiquiti UniFi OS CVE-2026-34909 Path Traversal in Ubiquiti UniFi OS CVE-2026-34910 Command Injection in Ubiquiti UniFi OS CVE-2020-17483 Improper Access Control in Uffizio GPS Tracker CVE-2026-48172 LiteSpeed User-End cPanel Plugin Redis Privilege Escalation CVE-2022-22954 Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2023-33538 Authenticated command injection in TP-Link /userRpm/WlanNetworkRpm CVE-2023-1389 Unauthenticated Command Injection in TP-Link Archer AX21 Locale API CVE-2014-9222 Misfortune Cookie in AllegroSoft RomPager CVE-2022-36553 Command Injection in Hytec Inter HWL-2511-SS popen.cgi CVE-2025-9528 OS Command Injection in Linksys E1700 systemCommand CVE-2024-3721 OS Command Injection in TBK DVR-4104 and DVR-4216 CVE-2025-4008 Command Injection in Smartbedded Meteobridge /public/template.cgi CVE-2025-34043 Unauthenticated Command Injection in Vacron NVR board.cgi CVE-2014-3206 Remote Code Execution in Seagate BlackArmor NAS CVE-2023-41011 Command Execution in China Mobile Intelligent Home Gateway HG6543C4 shortcut_telnet.cg CVE-2013-1599 Command Injection in D-Link IP Camera rtpd.cgi CVE-2023-23333 CVE-2023-23333 CVE-2022-40619 Unauthenticated Command Injection in NETGEAR/Orbi FunJSQ CVE-2024-21887 Command Injection in Ivanti Connect Secure and Ivanti Policy Secure Web Components CVE-2018-5999 Authentication Bypass in AsusWRT handle_request POST Processing CVE-2024-41710 Command Injection in Mitel 6800/6900/6900w Series SIP Phones CVE-2024-7399 Path Traversal in Samsung MagicINFO 9 Server CVE-2026-24061 Authentication Bypass in GNU Inetutils telnetd via USER Argument Injection CVE-2021-22986 F5 BIG-IP and BIG-IQ iControl REST Unauthenticated Remote Command Execution CVE-2021-3129 Ignition Remote Code Execution in Laravel Debug Mode CVE-2017-9841 PHPUnit eval-stdin.php Remote Code Execution CVE-2022-47945 ThinkPHP lang parameter LFI to RCE CVE-2022-22947 Spring Cloud Gateway Actuator Code Injection RCE CVE-2022-29303 Command Injection in SolarView Compact 6.00 conf_mail.php CVE-2017-18368 Unauthenticated Command Injection in ZyXEL P660HN-T1A Remote System Log CVE-2024-32113 Path Traversal in Apache OFBiz CVE-2021-35394 Unauthenticated Command Injection in Realtek Jungle SDK UDPServer (MP Daemon) CVE-2025-24016 Unsafe Deserialization RCE in Wazuh DistributedAPI CVE-2020-5902 F5 BIG-IP TMUI Directory Traversal Remote Code Execution CVE-2020-8193 Unauthenticated Access to Certain URL Endpoints in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP CVE-2020-8195 Path Traversal / LFI in Citrix ADC, Gateway, and SD-WAN WANOP CVE-2020-8196 Improper access control in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP CVE-2024-12856 OS Command Injection in Four-Faith F3x24/F3x36 apply.cgi CVE-2021-20090 Authentication Bypass via Path Traversal in Arcadyan-based Router Web Interfaces CVE-2025-4632 Arbitrary File Write in Samsung MagicINFO 9 Server

MITRE ATT&CK

Mirai in ATT&CK

70 distinct techniques

Techniques

70 techniques
T1078.001 Default Accounts T1190 Exploit Public-Facing Application T1071 Application Layer Protocol T1498 Network Denial of Service T1046 Network Service Discovery T1059.004 Unix Shell T1105 Ingress Tool Transfer T1070 Indicator Removal T1078 Valid Accounts T1110 Brute Force T1036 Masquerading T1562 Impair Defenses T1219 Remote Access Tools T1204.002 Malicious File T1595 Active Scanning T1059 Command and Scripting Interpreter T1203 Exploitation for Client Execution T1027 Obfuscated Files or Information T1140 Deobfuscate/Decode Files or Information T1499 Endpoint Denial of Service T1021.004 SSH T1070.004 File Deletion T1222 File and Directory Permissions Modification T1497.001 System Checks T1210 Exploitation of Remote Services T1218 System Binary Proxy Execution T1001 Data Obfuscation T1057 Process Discovery T1584.005 Botnet T1021 Remote Services T1083 File and Directory Discovery T1082 System Information Discovery T1059.005 Visual Basic T1498.001 Direct Network Flood T1568.001 Fast Flux DNS T1090 Proxy T1001.003 Protocol or Service Impersonation T1110.001 Password Guessing T1027.002 Software Packing T1561.001 Disk Content Wipe T1005 Data from Local System T1047 Windows Management Instrumentation T1499.001 OS Exhaustion Flood T1553.002 Code Signing T1112 Modify Registry T1053 Scheduled Task/Job T1059.003 Windows Command Shell T1027.003 Steganography T1496 Resource Hijacking T1003 OS Credential Dumping T1021.002 SMB/Windows Admin Shares T1021.001 Remote Desktop Protocol T1547 Boot or Logon Autostart Execution T1570 Lateral Tool Transfer T1068 Exploitation for Privilege Escalation T1657 Financial Theft T1204 User Execution T1552 Unsecured Credentials T1568 Dynamic Resolution T1008 Fallback Channels T1037 Boot or Logon Initialization Scripts T1543 Create or Modify System Process T1133 External Remote Services T1584 Compromise Infrastructure T1090.003 Multi-hop Proxy T1499.003 Application Exhaustion Flood T1499.002 Service Exhaustion Flood T1584.008 Network Devices T1592 Gather Victim Host Information T1095 Non-Application Layer Protocol

Reporting

Research mentioning Mirai

Aug 14
Cyber Security News

Dysphoria Botnet Turns Compromised Routers and Cameras Into DDoS Bots and C2 Relay Nodes

The Dysphoria botnet has compromised about 296,000 internet-connected devices, largely routers, cameras, gateways, and other embedded Linux or IoT systems, and is being used to launch distributed denial-of-service (DDoS) attacks while also relaying attacker traffic through infected hosts. Reporting citing Shadowserver says the botnet has expanded beyond disruption to include residential proxy functionality, allowing malicious traffic and command-and-control relay activity to appear as if it originates from ordinary home or small-business internet connections. The exposed population reflects devices that are already compromised, rather than victims of a single confirmed exploit chain, and prior reporting linked Dysphoria infections to Telnet and SSH password attacks alongside exploitation of known vulnerabilities. Defenders are being urged to investigate exposed management services, update firmware, replace weak or reused credentials, disable unnecessary remote administration, segment IoT devices from critical networks, and retire unsupported hardware that can no longer be secured.

Aug 14
Cryptika

Dysphoria Botnet Turns Compromised Routers and Cameras Into DDoS Bots and C2 Relay Nodes | Cryptika Cybersecurity

Aug 13
The Record Media

New Mirai variant adds stealth capabilities to notorious botnet code | The Record from Recorded Future News

FortiGuard Labs disclosed a previously undocumented Linux botnet, Evooo1Bot, a Mirai-derived malware family that has been actively targeting Internet-facing devices since at least July 2026. The botnet exploits known vulnerabilities in routers, firewalls, IP cameras, and other edge hardware from vendors including Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare, then deploys architecture-specific binaries from a shared loader at 91.92.40[.]118. Researchers said the malware clears bash history after infection, performs anti-analysis and anti-sandbox checks, and communicates with its command-and-control infrastructure over encrypted channels on port 443. Evooo1Bot expands on typical Mirai behavior with SSH brute-force scanning, credential sniffing for default or exposed access credentials, persistence mechanisms, and an integrated exploit module for multiple known flaws. Researchers highlighted its reverse SOCKS proxy capability as the most consequential feature because compromised edge devices can be repurposed as long-lived relay nodes to conceal attacker origin, support lateral movement, and enable follow-on intrusions into internal networks. Reported activity has been concentrated across North America, South America, Europe, India, China, and Japan, underscoring broad exposure for organizations running unpatched perimeter devices.

Aug 13
Fortinet Threat Research

Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs

Aug 12
Trendai Security

CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation | TrendAI (US)

A critical pre-authentication remote code execution flaw, tracked as CVE-2025-55182 and dubbed React2Shell, was disclosed in React Server Components and related React Flight server-side deserialization logic used by React.js, Next.js, and similar frameworks. The vulnerability affects React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 in the packages react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, where unsafe deserialization of HTTP request payloads sent to Server Function endpoints can lead to arbitrary code execution in Node.js before authentication. Public reporting said the flaw was fixed in the React repository through pull request #35277, and vendor advisories and CISA tracking indicate the issue drew urgent attention. Security researchers later reported active in-the-wild exploitation beginning almost immediately after disclosure, with mass scanning followed by deployment of Cobalt Strike, Sliver, cryptominers, reverse proxies, a Go backdoor, botnet activity, and a Node.js Secret-Hunter payload aimed at stealing credentials and secrets. Observed campaigns targeted both Linux and Windows systems, and analysis tied the root cause to improper property ownership checks in React's reviveModel function that allowed attacker-controlled serialized payloads to traverse prototype properties. The official patch replaced unsafe ownership checks with Object.prototype.hasOwnProperty.call(...), added explicit handling for __proto__, and prompted guidance to upgrade affected React and Next.js deployments and monitor exposed Server Function endpoints for exploitation attempts.

Jul 31
Sysdig

Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig

TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

Jul 22
Cyber Security News

New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies

Researchers analyzed NULLZEREPTOOL, a Python-based attack framework exposed in Pastebin posts, and found a Telegram-controlled platform focused primarily on distributed denial-of-service operations. The tool links two source-code variants through shared credentials and core logic: an earlier build centered on DDoS and proxy management, and a later version that retained the same attack engine while expanding into additional modules. Analysis showed support for 20 DDoS methods, Telegram-based command and control, proxy harvesting and validation, a Flask API, key management, and logging tied to payment-card data, with evidence that the framework was tested against several websites. The newer code also introduced wireless attack functions, credential-related features, and a hierarchical botnet tasking model, but researchers said many of those additions appear incomplete or unproven. Flare found that the DDoS engine, Telegram C2, and proxy pipeline were implemented in source, while the WiFi, Bluetooth, credential-theft, and broader botnet capabilities appeared to depend on missing client artifacts or external tooling. The assessment concludes that NULLZEREPTOOL is best understood as a low-tier, Telegram-managed DDoS panel showing signs of malware-as-a-service feature expansion rather than a confirmed advanced botnet or wireless exploitation platform.

Jul 21
Flareio

Inside NULLZEREPTOOL - Flare

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.