Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 38 IP / 35 hostnames
Mirai is a Linux-based IoT botnet malware family best known for compromising internet-exposed embedded devices such as routers, cameras, and similar appliances and conscripting them into distributed denial-of-service botnets.
Profile source: Mallory opens in a new tabMirai
Mirai is a Linux-based IoT botnet malware family best known for compromising internet-exposed embedded devices such as routers, cameras, and similar appliances and conscripting them into distributed denial-of-service botnets. It became a foundational codebase in the IoT threat ecosystem, and numerous later botnets have reused or adapted Mirai-derived components and tradecraft.
Mirai-class activity is characterized by large-scale scanning for exposed services, opportunistic compromise of poorly secured devices, and use of infected hosts to launch DDoS attacks. The family is strongly associated with abuse of weak or default credentials on internet-facing devices, and Mirai-style variants have also incorporated exploitation of known remote code execution and command-injection vulnerabilities in edge and IoT products. Compromised devices are typically Linux-based embedded systems spanning consumer and small-office hardware.
Mirai has had enduring influence well beyond the original botnet. Multiple later frameworks and botnets have been assessed as borrowing code or design lineage from Mirai, including newer IoT botnet families in the broader DDoS ecosystem. Public reporting has also documented Mirai variants being distributed through other malicious infrastructures and proxy ecosystems, underscoring its continued operational relevance years after its emergence.
The malwareโs primary operational purpose is botnet formation for DDoS, but Miraiโs broader significance lies in establishing a reusable template for rapidly building IoT attack infrastructure. Its continued reuse reflects the persistence of exposed embedded devices, weak credential hygiene, and slow patching across the IoT landscape.
C2 tracking
Derp observations, rolling seven-day window
Samples
9650b84c44403decb656beab529c70fc1ec02bafa9d70f7694c381998bbea22d f76ea26f6031ebd63e849b1c41bf6a6255d8291e47482617557fd73154ce445f 3e94cbf359f2bef4c8ef6dd71108455108c00c3b917aadb2015c176d60bbdd9d 40df91b940eea28d176edccda20a8e2e4e281eb531254486d4c69af08dd29842 847866fd99c7898e27069e3f0dce04c6e5e39ba51bb2a86ccc086d51b4320b95 8e5fe294c314bb1c2dbfa2ff6225b79380a5494fa70ecb1b8f1e6cf725a61427 90ac8ec4e015343f2f175d29a2e147109a76fd65582dfa9cad80144826336872 17d1b0c433da78f9a1de8e1ebb04e3174961f8b97aa5d489b21f28dec1c2ac15 3f509b8445f1b263397f3d531f478aeb9b046e0ab7582549a622e912a7161fda 9354ba8758ad0702251b2ea6dfa82cb7ba34c0e7f32e5cfc83aed0baebb3c456 Reported operators
Even Killnet relies on volunteer cyber partisans, but its structure also includes dedicated sub-groups leveraging IoT botnet infrastructures such as Mirai.
FBI Director Chris Wray last Wednesday disclosed an operation to disrupt a Mirai-variant botnet that has exploited more than 260,000 IoT devices globally.
The operator -- a Chinese-speaking actor using the handle angelalk21 (QQ: 597118859, Telegram: @Kuru_x86) -- runs a Mirai-fork botnet with a novel DNS byte-swap anti-analysis technique that causes passive DNS researchers to track decoy IPs in Japan and the US while the real C2 sits in Germany.
...ultimately deploying the Mirai botnet malware and other DDoS-related programs on compromised devices and servers.
Hackers are exploiting vulnerabilities in end-of-life GeoVision IoT devices and Samsungโs MagicINFO server to expand the Mirai botnet... Akamai observed attacks in April targeting GeoVision devices... to download and run an ARM variant of Mirai dubbed LZRD.
All of these files belong to the infamous IoT malware named Mirai.
They have employed botnets such as those based on DieNet or Mirai variants for DDoS attacks...
Exploited software
MITRE ATT&CK
Reporting
Malware / Outils # Mycelium Framework (botnet) Mirai (botnet) DorkBot (botnet) RageBot (botnet) Phorpiex (botnet) IRCBot.HI (botnet)
Tracing its lineage to botnets like Mirai and AISURU, TuxBot v3 Evolution also incorporates code from the MHDDoS Python toolkit.
That reuse follows a familiar pattern in the IoT threat landscape, where Mirai-derived DDoS botnets continue to give attackers a quick foundation for building new attack tools.
Researchers traced the botnet's origins to code borrowed from multiple malware families, including Mirai, AISURU, and Wuhan...
The modular framework's lineage has been traced back to three different botnets, like Mirai, AISURU, and Wuhan...
The source tree contains approximately 92 individual method implementations across three lineages: 30 from the traditional Mirai codebase.
Mirai5
...resulting in a far more heterogeneous population of compromised hosts than botnets such as Mirai.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.