Skip to content

Mozi

Mozi is a Mirai- and Gafgyt-influenced peer-to-peer IoT botnet first publicly documented in 2019.

Profile source: Mallory opens in a new tab

Mozi

Family profile

Mozi is a Mirai- and Gafgyt-influenced peer-to-peer IoT botnet first publicly documented in 2019. It targets internet-connected embedded Linux devices, especially routers, gateways, DVRs, NVRs, IP cameras, and other SOHO or edge appliances, with observed support across ARM, MIPS, and x86 architectures. Unlike traditional centralized botnets, Mozi uses a custom protocol built on distributed hash table technology and BitTorrent-like peer discovery, which improves resilience and complicates takedown.

Mozi propagates through weak or default Telnet credentials and through exploitation of multiple known vulnerabilities affecting routers, DVRs, NVRs, CCTV systems, and related IoT products. Infected devices can host or distribute payloads to newly compromised systems and continue spreading the botnet without reliance on a single command-and-control server. The malware has been observed using UPX-packed binaries with deliberately corrupted header fields as an anti-analysis measure.

Core functionality includes distributed denial-of-service attacks, remote command execution, payload download and execution, bot updating, and collection of host information. Later variants added features to improve operational efficiency and survivability, including Mirai-style attack coordination, external IP discovery, and UPnP port mapping to expose download services from devices behind NAT. Mozi has also been associated with cryptocurrency-mining monetization through related node types and later operational evolution.

Mozi has demonstrated tailored persistence on certain network gateways, including startup-script modification, script infection, credential or management-setting changes, service disabling, and port blocking to hinder competing access. On compromised gateways, it can enable man-in-the-middle activity through DNS spoofing and HTTP session hijacking, creating opportunities for traffic interception, redirection, and broader intrusion into enterprise IT or OT environments. Because compromised edge devices can serve as footholds for reconnaissance and lateral movement, Mozi presents risk beyond volumetric botnet abuse alone.

The botnet has remained notable as one of the more prevalent Linux and IoT malware families of its period, with its decentralized architecture allowing infections to persist even after disruption of operators or portions of the network.

Capabilities

  • Brute Force
  • Credential Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Session Hijacking
  • Spoofing

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
Distribution
Host form
1149 IP / 0 hostnames

Leading locations

  • CN875
  • PK52
  • PH28
  • RU26
  • TW22
  • ID17
  • ET15
  • IN15
  • ZA14
  • BR11
  • SE9
  • US9

Leading providers

  • CHINA UNICOM China169 Backbone760
  • CHINANET BACKBONE72
  • Cyber Internet Services (Pvt) Ltd.34
  • China Unicom IP network China169 Guangdong province29
  • Globe Telecom Inc.26
  • Taiwan Fixed Network, Telco and Network Service Provider.18

Infrastructure traits

  • Hosting 1
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
RondoDox

"...alongside NETGEAR-MOZI and other router-related flaws. This pattern suggests that the actor was focused on building or expanding botnets..."

Exploited software

Vulnerabilities linked to Mozi

12 CVEs

MITRE ATT&CK

Mozi in ATT&CK

33 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.