Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- Distribution
- Host form
- 1149 IP / 0 hostnames
Mozi is a Mirai- and Gafgyt-influenced peer-to-peer IoT botnet first publicly documented in 2019.
Profile source: Mallory opens in a new tabMozi
Mozi is a Mirai- and Gafgyt-influenced peer-to-peer IoT botnet first publicly documented in 2019. It targets internet-connected embedded Linux devices, especially routers, gateways, DVRs, NVRs, IP cameras, and other SOHO or edge appliances, with observed support across ARM, MIPS, and x86 architectures. Unlike traditional centralized botnets, Mozi uses a custom protocol built on distributed hash table technology and BitTorrent-like peer discovery, which improves resilience and complicates takedown.
Mozi propagates through weak or default Telnet credentials and through exploitation of multiple known vulnerabilities affecting routers, DVRs, NVRs, CCTV systems, and related IoT products. Infected devices can host or distribute payloads to newly compromised systems and continue spreading the botnet without reliance on a single command-and-control server. The malware has been observed using UPX-packed binaries with deliberately corrupted header fields as an anti-analysis measure.
Core functionality includes distributed denial-of-service attacks, remote command execution, payload download and execution, bot updating, and collection of host information. Later variants added features to improve operational efficiency and survivability, including Mirai-style attack coordination, external IP discovery, and UPnP port mapping to expose download services from devices behind NAT. Mozi has also been associated with cryptocurrency-mining monetization through related node types and later operational evolution.
Mozi has demonstrated tailored persistence on certain network gateways, including startup-script modification, script infection, credential or management-setting changes, service disabling, and port blocking to hinder competing access. On compromised gateways, it can enable man-in-the-middle activity through DNS spoofing and HTTP session hijacking, creating opportunities for traffic interception, redirection, and broader intrusion into enterprise IT or OT environments. Because compromised edge devices can serve as footholds for reconnaissance and lateral movement, Mozi presents risk beyond volumetric botnet abuse alone.
The botnet has remained notable as one of the more prevalent Linux and IoT malware families of its period, with its decentralized architecture allowing infections to persist even after disruption of operators or portions of the network.
Samples
f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8 4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7 12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605 c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887 2e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6 Reported operators
"...alongside NETGEAR-MOZI and other router-related flaws. This pattern suggests that the actor was focused on building or expanding botnets..."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.