Skip to content

Mozi

Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.

C2 Infrastructure

ISP/Residential100%

Last 7 days

Mar 23, 2026
C2 Hosts: 1

Further Reading

Mozi Resurfaces as Androxgh0st Botnet: Unraveling The Latest Exploitation Wave | CloudSEK

The Androxgh0st botnet, an emerging cyber threat since January 2024, has resurfaced with advanced capabilities and integration of IoT-focused Mozi payloads. Exploiting over 20 vulnerabilities in te...

cloudsek.com
Linux-Targeted Malware Increases by 35% in 2021 | CrowdStrike

CrowdStrike has observed that malware targeting Linux-based systems increased by 35% in 2021. XorDDoS, Mirai and Mozi were the most common malware families.

crowdstrike.com
Collecting and operationalizing threat data from the Mozi botnet — Elastic Security Labs

The Mozi botnet is an ongoing malware campaign targeting unsecured and vulnerable networking devices. This post will showcase the analyst journey of collecting, analyzing, and operationalizing thre...

elastic.co
How to proactively defend against Mozi IoT botnet | Microsoft Security Blog

Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs). It works by exploiting weak telnet passwords...

microsoft.com
How IoT Botnets Evade Detection and Analysis - Part 1

Packing is a key technique to stymie reverse engineering botnet code. Learn more about packers used by IoT malware, and how to analyze packed samples.

nozominetworks.com
Overcoming the Challenges of Detecting P2P Botnets on Your Network

It can be challenging to disrupt the malicious activities of P2P botnets. Find out how to protect your OT/IoT networks against them.

nozominetworks.com