Skip to content
Malware family IotLinuxNetwork Device

Mirai

Mirai is a Linux-based IoT botnet malware family best known for compromising internet-exposed embedded devices such as routers, cameras, and similar appliances and conscripting them into distributed denial-of-service botnets.

Profile source: Mallory opens in a new tab

Mirai

Family profile

Mirai is a Linux-based IoT botnet malware family best known for compromising internet-exposed embedded devices such as routers, cameras, and similar appliances and conscripting them into distributed denial-of-service botnets. It became a foundational codebase in the IoT threat ecosystem, and numerous later botnets have reused or adapted Mirai-derived components and tradecraft.

Mirai-class activity is characterized by large-scale scanning for exposed services, opportunistic compromise of poorly secured devices, and use of infected hosts to launch DDoS attacks. The family is strongly associated with abuse of weak or default credentials on internet-facing devices, and Mirai-style variants have also incorporated exploitation of known remote code execution and command-injection vulnerabilities in edge and IoT products. Compromised devices are typically Linux-based embedded systems spanning consumer and small-office hardware.

Mirai has had enduring influence well beyond the original botnet. Multiple later frameworks and botnets have been assessed as borrowing code or design lineage from Mirai, including newer IoT botnet families in the broader DDoS ecosystem. Public reporting has also documented Mirai variants being distributed through other malicious infrastructures and proxy ecosystems, underscoring its continued operational relevance years after its emergence.

The malwareโ€™s primary operational purpose is botnet formation for DDoS, but Miraiโ€™s broader significance lies in establishing a reusable template for rapidly building IoT attack infrastructure. Its continued reuse reflects the persistence of exposed embedded devices, weak credential hygiene, and slow patching across the IoT landscape.

Capabilities

  • Brute Force
  • Ddos
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
38 IP / 35 hostnames

Leading locations

  • NL14
  • DE13
  • TR10
  • US7
  • RO3
  • LT2
  • FR1
  • LB1
  • SG1
  • SI1
  • TH1
  • VN1

Leading providers

  • TechTies Inc.9
  • Storm Industries LLC8
  • Private-Hosting di Cipriano oscar6
  • SWISSNET LLC4
  • BANATSYNC SRL2
  • HostPapa2

Infrastructure traits

  • Hosting 52
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
Killnet

Even Killnet relies on volunteer cyber partisans, but its structure also includes dedicated sub-groups leveraging IoT botnet infrastructures such as Mirai.

Flax Typhoon

FBI Director Chris Wray last Wednesday disclosed an operation to disrupt a Mirai-variant botnet that has exploited more than 260,000 IoT devices globally.

angelalk21

The operator -- a Chinese-speaking actor using the handle angelalk21 (QQ: 597118859, Telegram: @Kuru_x86) -- runs a Mirai-fork botnet with a novel DNS byte-swap anti-analysis technique that causes passive DNS researchers to track decoy IPs in Japan and the US while the real C2 sits in Germany.

Matrix

...ultimately deploying the Mirai botnet malware and other DDoS-related programs on compromised devices and servers.

InfectedSlurs

Hackers are exploiting vulnerabilities in end-of-life GeoVision IoT devices and Samsungโ€™s MagicINFO server to expand the Mirai botnet... Akamai observed attacks in April targeting GeoVision devices... to download and run an ARM variant of Mirai dubbed LZRD.

Exploited software

Vulnerabilities linked to Mirai

63 CVEs
CVE-2022-22965 Spring4Shell CVE-2017-17215 Remote Code Execution in Huawei HG532 SOAP Service CVE-2025-29635 Command Injection in D-Link DIR-823X /goform/set_prohibiting CVE-2026-34908 Improper Access Control in Ubiquiti UniFi OS CVE-2026-34909 Path Traversal in Ubiquiti UniFi OS CVE-2026-34910 Command Injection in Ubiquiti UniFi OS CVE-2020-17483 Improper Access Control in Uffizio GPS Tracker CVE-2026-41940 Authentication Bypass in cPanel & WHM Login Flow CVE-2023-26801 Command Injection in LB-LINK /goform/set_LimitClient_cfg CVE-2026-48172 Privilege Escalation in LiteSpeed User-End cPanel Plugin redisAble Function CVE-2021-44228 Log4Shell CVE-2022-22954 VMware Workspace ONE Access and Identity Manager Server-Side Template Injection RCE CVE-2023-33538 Authenticated command injection in TP-Link /userRpm/WlanNetworkRpm CVE-2023-1389 Unauthenticated Command Injection in TP-Link Archer AX21 Locale API CVE-2017-6884 Command Injection in Zyxel EMG2926 nslookup Diagnostic Tool CVE-2016-10372 Unauthenticated TR-064 Command Execution in Eir D1000 modem CVE-2017-5638 Apache Struts Jakarta Multipart Parser RCE CVE-2018-10562 Command Injection in Dasan GPON Home Routers diag_Form CVE-2018-10561 Dasan GPON Router Authentication Bypass via ?images Parameter CVE-2014-9222 Misfortune Cookie in AllegroSoft RomPager CVE-2016-10401 Hardcoded SU Password in ZyXEL PK5001Z CVE-2022-36553 Command Injection in Hytec Inter HWL-2511-SS popen.cgi CVE-2025-9528 OS Command Injection in Linksys E1700 /goform/systemCommand CVE-2024-3721 OS Command Injection in TBK DVR-4104 and DVR-4216 CVE-2025-4008 Command Injection in Smartbedded Meteobridge /public/template.cgi CVE-2025-34043 Unauthenticated Command Injection in Vacron NVR board.cgi CVE-2014-3206 Remote Code Execution in Seagate BlackArmor NAS CVE-2020-10987 Command Injection in Tenda AC15 AC1900 goform/setUsbUnload CVE-2020-9054 Pre-authentication command injection in Zyxel weblogin.cgi CVE-2024-10914 Unauthenticated OS Command Injection in D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi CVE-2023-41011 Command Execution in China Mobile Intelligent Home Gateway HG6543C4 shortcut_telnet.cg CVE-2013-1599 Command Injection in D-Link IP Camera rtpd.cgi CVE-2023-23333 CVE-2023-23333 CVE-2022-40619 Unauthenticated Command Injection in NETGEAR/Orbi FunJSQ CVE-2014-8361 OS Command Injection in Realtek SDK miniigd SOAP Service CVE-2024-21887 Command Injection in Ivanti Connect Secure and Policy Secure CVE-2018-5999 Authentication Bypass in AsusWRT POST Request Handling CVE-2024-41710 Command Injection in Mitel 6800/6900/6900w Series SIP Phones CVE-2024-7399 Path Traversal in Samsung MagicINFO 9 Server CVE-2026-24061 GNU Inetutils telnetd remote authentication bypass CVE-2021-22986 Unauthenticated RCE in F5 BIG-IP/BIG-IQ iControl REST CVE-2025-55182 React2Shell CVE-2021-3129 Laravel Ignition Debug Mode Remote Code Execution CVE-2017-9841 PHPUnit eval-stdin.php Remote Code Execution CVE-2022-47945 ThinkPHP lang parameter LFI to RCE CVE-2022-22947 Spring Cloud Gateway Actuator Code Injection RCE CVE-2022-29303 Command Injection in SolarView Compact 6.00 conf_mail.php CVE-2024-11120 Unauthenticated OS Command Injection in GeoVision EoL Devices CVE-2017-18368 Unauthenticated Command Injection in ZyXEL P660HN-T1A ViewLog.asp Remote System Log CVE-2024-6047 OS Command Injection in GeoVision EoL Devices CVE-2024-32113 Path Traversal in Apache OFBiz CVE-2021-35394 Unauthenticated RCE in Realtek Jungle SDK UDPServer (MP Daemon) CVE-2021-36260 Unauthenticated Command Injection in Hikvision Web Server CVE-2025-24016 Unsafe Deserialization RCE in Wazuh DistributedAPI CVE-2020-5902 F5 BIG-IP TMUI Remote Code Execution CVE-2020-8193 Unauthenticated Access to Certain URL Endpoints in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP CVE-2020-8195 Path Traversal / LFI in Citrix ADC, Gateway, and SD-WAN WANOP CVE-2020-8196 Improper access control in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP CVE-2024-12856 OS Command Injection in Four-Faith F3x24/F3x36 apply.cgi CVE-2021-20090 Authentication bypass via path traversal in Buffalo WSR-2533DHPL2/WSR-2533DHP3 web interface CVE-2025-4632 Arbitrary File Write in Samsung MagicINFO 9 Server CVE-2025-1316 RCE in Edimax IC-7100 via Improper Neutralization of Requests CVE-2024-7029 Unauthenticated Command Injection in AVTECH IP Camera Brightness Function

MITRE ATT&CK

Mirai in ATT&CK

74 distinct techniques

Techniques

74 techniques
T1562 Impair Defenses T1057 Process Discovery T1498 Network Denial of Service T1090.003 Multi-hop Proxy T1190 Exploit Public-Facing Application T1036 Masquerading T1071 Application Layer Protocol T1499.003 Application Exhaustion Flood T1499.002 Service Exhaustion Flood T1068 Exploitation for Privilege Escalation T1584.008 Network Devices T1046 Network Service Discovery T1078 Valid Accounts T1059 Command and Scripting Interpreter T1105 Ingress Tool Transfer T1496 Resource Hijacking T1595 Active Scanning T1592 Gather Victim Host Information T1203 Exploitation for Client Execution T1082 System Information Discovery T1110 Brute Force T1059.004 Unix Shell T1584.005 Botnet T1095 Non-Application Layer Protocol T1021 Remote Services T1498.001 Direct Network Flood T1657 Financial Theft T1078.001 Default Accounts T1620 Reflective Code Loading T1499 Endpoint Denial of Service T1070 Indicator Removal T1210 Exploitation of Remote Services T1556 Modify Authentication Process T1027 Obfuscated Files or Information T1218 System Binary Proxy Execution T1211 Exploitation for Defense Evasion T1610 Deploy Container T1047 Windows Management Instrumentation T1070.004 File Deletion T1568.002 Domain Generation Algorithms T1562.001 Disable or Modify Tools T1562.006 Indicator Blocking T1489 Service Stop T1021.001 Remote Desktop Protocol T1622 Debugger Evasion T1497.001 System Checks T1071.004 DNS T1595.001 Scanning IP Blocks T1005 Data from Local System T1083 File and Directory Discovery T1571 Non-Standard Port T1518 Software Discovery T1547 Boot or Logon Autostart Execution T1053.003 Cron T1568 Dynamic Resolution T1033 System Owner/User Discovery T1027.002 Software Packing T1608.001 Upload Malware T1036.005 Match Legitimate Resource Name or Location T1568.001 Fast Flux DNS T1499.001 OS Exhaustion Flood T1572 Protocol Tunneling T1222 File and Directory Permissions Modification T1219 Remote Access Tools T1071.001 Web Protocols T1543.003 Windows Service T1583.006 Web Services T1499.004 Application or System Exploitation T1584 Compromise Infrastructure T1583.005 Botnet T1573 Encrypted Channel T1222.002 Linux and Mac File and Directory Permissions Modification T1609 Container Administration Command T1133 External Remote Services

Reporting

Research mentioning Mirai

Jul 18
Cyberveille

Mycelium Framework : premier botnet AI-as-a-Service observรฉ en underground | CyberVeille

Malware / Outils # Mycelium Framework (botnet) Mirai (botnet) DorkBot (botnet) RageBot (botnet) Phorpiex (botnet) IRCBot.HI (botnet)

Jul 16
Scworld

New TuxBot v3 Evolution IoT botnet framework shows signs of AI development | brief | SC Media

Tracing its lineage to botnets like Mirai and AISURU, TuxBot v3 Evolution also incorporates code from the MHDDoS Python toolkit.

Jul 16
Cyber Security News

New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

That reuse follows a familiar pattern in the IoT threat landscape, where Mirai-derived DDoS botnets continue to give attackers a quick foundation for building new attack tools.

Jul 16
Cysecurity News

AI-Assisted TuxBot v3 Evolution Botnet Targets IoT Devices With Modular Multi-Channel Attack Framework - CySecurity News - Latest Information Security and Hacking Incidents

Researchers traced the botnet's origins to code borrowed from multiple malware families, including Mirai, AISURU, and Wuhan...

Jul 15
The Hacker News

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

The modular framework's lineage has been traced back to three different botnets, like Mirai, AISURU, and Wuhan...

Jul 15
Palo Alto Networks Unit 42

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

The source tree contains approximately 92 individual method implementations across three lineages: 30 from the traditional Mirai codebase.

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Mirai5

Jul 10
Security Week

'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek

...resulting in a far more heterogeneous population of compromised hosts than botnets such as Mirai.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.