Mirai is a malware ecosystem and botnet operator community centered on compromising internet-exposed IoT and embedded Linux devices, especially routers, IP cameras, network video devices, and similar edge equipment, to build large distributed denial-of-service botnets. First emerging in 2016, Mirai became one of the most widely recognized IoT botnets after being used in major DDoS attacks and after its source code was publicly released, which enabled extensive reuse and proliferation of variants and offshoots. Mirai is best known for large-scale scanning and initial access against poorly secured devices using default or hardcoded credentials, exposed Telnet services, and later a broad range of public remote code execution and command injection vulnerabilities in routers, web applications, and embedded devices. Reported exploitation associated with Mirai or Mirai-derived operators has included vulnerabilities such as CVE-2016-10401, CVE-2017-17215, CVE-2021-32305, CVE-2021-44228, CVE-2023-1389, and CVE-2025-29635. Operators have repeatedly operationalized newly published proof-of-concept exploits to recruit additional bots from unpatched or end-of-life devices. The botnet’s primary operational purpose is DDoS. Observed Mirai variants support multiple UDP- and TCP-based flooding methods, including attacks tailored to game servers and hosting providers. Mirai campaigns have also been associated with credential brute forcing, continuous internet-wide scanning, multi-architecture malware deployment for Linux systems, and anti-analysis measures such as modified UPX headers to hinder unpacking. Mirai generally lacks durable persistence on many infected devices, so operators rely on constant rescanning and reinfection to maintain botnet size. Mirai has a large family tree of variants and related offshoots. Named examples include Satori, also known as Masuta, as well as numerous smaller Mirai-based derivatives. Satori notably exploited Huawei router vulnerabilities and was linked in U.S. criminal proceedings to an alleged operator using the alias Nexus Zeta. Other reporting has tied Mirai derivatives to exploitation of Log4Shell and to campaigns targeting consumer and small-office routers and NAS devices. Mirai is predominantly associated with financially motivated criminal activity through botnet-for-hire, disruptive DDoS operations, and possible extortion-oriented use of rented attack capacity. It is not a nation-state actor. The ecosystem is best understood as a decentralized criminal botnet lineage whose leaked source code lowered the barrier to entry for many operators and made Mirai-derived activity a persistent feature of the IoT threat landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical router botnet example showing how vulnerable edge devices can be rapidly conscripted once exploitation is reliable.
A large botnet referenced as an example of home gadgets being conscripted into attack infrastructure.
Botnet activity exploiting vulnerable legacy routers to deploy Mirai variants and compromise devices for botnet operations.
Referenced as a botnet family/operator contextually associated with targeting game servers and abusing Valve Source Engine infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.