Mirai is an IoT malware and DDoS botnet family first observed in 2016. The name also collectively identifies operators of Mirai-based botnets rather than a single, consistently attributable threat group. Mirai compromises internet-exposed routers, IP cameras, and other embedded devices, recruiting them into remotely controlled networks used to disrupt online services. Its original operators conducted major attacks against KrebsOnSecurity, including a 620 Gbps DDoS attack. Publication of its source code enabled numerous independently operated derivatives, including Satori and Mukashi; these are malware variants, not established organizational subgroups. Mirai traditionally propagates through internet-wide scanning for exposed Telnet services and automated login attempts using default or hardcoded credentials. Subsequent variants incorporate command-injection and remote-code-execution exploits against routers, NAS appliances, and server applications. Documented exploitation includes CVE-2016-10401 in Zyxel routers, CVE-2017-17215 in Huawei routers, CVE-2021-32305 in WebSVN, Log4Shell in Apache Log4j, CVE-2023-1389 in TP-Link routers, and CVE-2025-29635 in discontinued D-Link routers. Campaigns rapidly adopt publicly available exploit code and deploy Linux payloads supporting multiple processor architectures. Mirai-derived botnets support multiple TCP- and UDP-based flooding methods, including attacks against hosting infrastructure and Valve Source Engine game servers. Some variants use modified UPX packing to hinder automated unpacking and analysis. Original Mirai infections do not survive device reboot, requiring operators to continually scan for and reinfect vulnerable devices. Mirai-related compromises have affected devices in Argentina, Germany, and the United Kingdom. A separate Killnet squad also uses the name Mirai; the shared name does not establish a connection to the malware family or its original operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical router botnet example showing how vulnerable edge devices can be rapidly conscripted once exploitation is reliable.
A large botnet referenced as an example of home gadgets being conscripted into attack infrastructure.
Botnet activity exploiting vulnerable legacy routers to deploy Mirai variants and compromise devices for botnet operations.
Referenced as a botnet family/operator contextually associated with targeting game servers and abusing Valve Source Engine infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.