Mirai is a botnet malware family primarily targeting Linux-based Internet of Things devices and network equipment, including routers, IP cameras, digital video recorders, and network-attached storage systems. It emerged in 2016 and recruits compromised devices to conduct distributed denial-of-service attacks under remote command-and-control. The original malware scanned the internet for exposed devices and attempted authentication using approximately 60 factory-default credential pairs. Mirai was used in the October 2016 attack against DNS provider Dyn, which disrupted access to major online services.
The public release of Mirai's source code enabled numerous independently operated derivatives. These variants extend propagation beyond default-password attacks to exploitation of command-injection and remote-code-execution vulnerabilities in routers, surveillance equipment, and internet-facing applications. Mirai botnets have incorporated exploitation of Log4j vulnerability CVE-2021-44228, while other campaigns have targeted Sunhillo SureLine and multiple router vendors. Variants support multiple processor architectures and commonly receive commands for UDP, TCP, and other network-flooding attacks. Some derivatives also target Android TV and set-top boxes through exposed Android Debug Bridge interfaces.
Mirai-derived infrastructure has been used for reconnaissance as well as DDoS. Integrity Technology Group, associated with the China-linked threat actor Flax Typhoon, operated a Mirai-variant IoT botnet supporting MicroScan vulnerability scanning against prospective targets, including energy companies, airports, nongovernmental organizations, and universities. This use of compromised devices as operational infrastructure is distinct from the capabilities of separate phishing and data-theft tools used in the same operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2018-10561, CVE-2018-10562: Authentication bypass and command injection vulnerabilities, respectively, for the Dasan gigabit passive optical network (GPON) routers.
Arbitrary command execution vulnerability in Huawei HG532 routers.
In early December 2022, a security advisory warned of a critical command injection vulnerability (tracked as CVE-2022-46169, severity rating 9.8 out of 10) in Cacti that could be exploited without authentication.
/cgi-bin/luci/;stok=/locale – 39 hits (OpenWrt/LuCI authentication bypass, CVE-2023-1389, widely used by Mirai variants)
GeoServer의 원격 코드 실행 취약점(CVE-2024-36401)이 공개된 이후 최근까지도 해당 취약점을 악용해 악성코드를 설치하는 사례들이 확인되고 있다.
The SIRT uncovered a vulnerability in FXC AE1021 and AE1021PE outlet wall routers that are being actively exploited in the wild. The vulnerability allows an authenticated attacker to achieve OS command injection with a payload delivered via a POST request to the management interface.
Home Network Administration Protocol (HNAP) SOAPAction-header command execution vulnerability that works on certain D-Link devices.
Universal Plug and Play (UPnP) Simple Object Access Protocol (SOAP) command execution vulnerability affecting different devices using Realtek software development kit (SDK) with the miniigd daemon.
Vulnerability that can allow the execution of remote arbitrary commands in Netgear R7000 and R6400 devices.
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
CVE-2024-7029 is a command injection vulnerability found in the brightness function of AVTECH closed-circuit television (CCTV) cameras that allows for remote code execution (RCE).
During routine sandbox hunting analysis, the Uptycs Threat Research team uncovered evidence of an ongoing live campaign exploiting the Log4j vulnerability, which commenced in January 2024.
CVE-2018-10561, CVE-2018-10562: Authentication bypass and command injection vulnerabilities, respectively, for the Dasan gigabit passive optical network (GPON) routers.
We observed Dark IoT botnet samples targeting vulnerabilities from 2021, CVE-2021-20090 / CVE-2021-20091 and CVE-2021-35395.
It observed multiple remote command execution attempts "by a Mirai-like botnet" and advised owners of affected Zyxel NAS devices to actively search for signs of compromise, especially if the patches weren't applied immediately.
In June 2023, FortiGuard Labs detected the propagation of several DDoS botnets exploiting the Zyxel vulnerability (CVE-2023-28771). These attacks specifically target the command injection vulnerability in the Internet Key Exchange (IKE) packet transmitted over UDP on Zyxel devices.
CVE-2021-20090 / CVE-2021-20091 — Path traversal vulnerability and Configuration File Injection
It was published 16th August and we already saw samples leveraging it on the 20th.
This botnet has also been observed exploiting CVE-2024-7214, which affects TOTOLINK IoT devices.
The most notable of these vulnerabilities is CVE-2020-10173, a Multiple Authenticated Command injection vulnerability found in Comtrend VR-3033 routers.
We observed Dark IoT botnet samples targeting vulnerabilities from 2021 ... along with an old one from 2014, CVE-2014-3206.
“The default creds for the DVR device were root/zlxx. – including the full stop.” The article links this credential issue to “an old CVE for various Unix distros: CVE-1999-0502.”
On June 2, Atlassian published an advisory for CVE-2022-26134, a critical zero-day remote code execution vulnerability in Confluence Server and Data Center.
In 2017, the mipseb and mipsel atks added an exploit targeting the TR-064 service on port 7547 (CVE-2016-10372).
The exploit targets the /camera-cgi/admin/param.cgi endpoint in Edimax devices, and injects commands into the NTP_serverName option as part of the ipcamSource option of param.cgi. This exploit requires authentication, and all the exploit attempts we observed were passing default credentials; typically admin:1234.
“Ubiquiti published security advisory SAB-064 on 21 May 2026 addressing CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. Each vulnerability was assigned a CVSS score of 10.0 and, when chained, could allow an unauthenticated remote attacker to obtain root-level access to affected UniFi systems.”
“That mismatch is CVE-2026-34908 (broken access control) and CVE-2026-34909 (path traversal), the pair Ubiquiti describes in SAB-064.”
“A URL that starts with the public prefix /api/auth/validate-sso/ but contains encoded ../ sequences passes the gateway's public check, then decodes into a protected /proxy/<service>/… path and reaches the backend with no authentication.”
This botnet has also been observed targeting various other vulnerabilities in our network of honeypots, including a Docker API endpoint exploit. In addition, they also have targeted CVE-2021-36220, and a Hadoop YARN vulnerability.
The vulnerability exists in the Sureline software due to improper input validation in the "ipAddr" and "dnsAddr" parameters. That allows an attacker to manipulate the resulting command by injecting valid OS command input allowing the establishment of an interactive remote shell session. | Also, the Mirai malware are used as a payload for further infiltration. ... Oct 09, 2023: FortiGuard Labs team observed that the IZ1H9 Mirai-based DDoS campaign targeted Sunhillo SureLine and released a detailed analysis.
The chmod command was also observed in a Mirai botnet malware sample exploiting the vulnerability Spring4Shell (CVE-2022-22965) documented in April. | “The chmod command was also observed in a Mirai botnet malware sample exploiting the vulnerability Spring4Shell (CVE-2022-22965) documented in April.”
In the honeypots Kaspersky detected the exploitation of the CVE-2024-3721 vulnerability to deploy a bot – it turned out to be a Mirai botnet modification.
The same threat actor targeted /soap.cgi?service=WANIPConn1 (CVE-2013-7471) with the most-mips payload and the same C2 IP address.
On April 19, 2023, PaperCut updated its advisory to report exploitation of CVE-2023-27350 in the wild. Sophos observed an affected customer as early as April 13, with Cobalt Strike detected during post-exploitation activity.
The report labels a request to /app/options.py containing shell commands in delcert as exploitation of CVE-2022-31137.
A vulnerability in Zhejiang Uniview ISC camera model 2500-S firmware through version 20210930 allows OS command injection through the setNatConfig function in /Interface/DevManage/VM.php. Akamai observed an exploitation attempt delivering the most-arm malware payload.
The vulnerability it targets, assigned CVE-2021-41653, was only just discovered on November 12 of this year. And barely two weeks later, on November 22, a sample from the MANGA malware campaign was seen actively exploiting it in the wild.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Integrity Tech built and ran a botnet made up of infected Internet of Things (IoT) devices running a version of the Mirai malware.”
Court documents allege that Integrity Tech created and operated an IoT botnet that leveraged a variant of the Mirai malware.
Analysis of the Scar rental botnet confirmed that the group contains not only the new botnet family found this time, but also other botnet families Mirai and Moobot.
Mirai spreads by scanning for Internet-facing IoT devices and brute-forcing default credentials.
EnemyBot is mainly built on Gafgyt’s source code, with several modules from the original Mirai source code, and other botnets.
“Some of the key players are Mirai Botnet ... Passion Botnet ... Tesla-Botnet ... MistNet ... SkyNet Botnet ... and Godzilla-BotNet.”
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The observed traffic focused on port 23, commonly used by Telnet... Mirai families have repeatedly abused weak credentials and reachable remote services.
“By leveraging the UPX executable packer, threat actors can avoid standard heuristic detection methodologies.”
HTTP/S was used for panel APIs, JS staging, challenge/response traffic, and ClickFix command retrieval.
Les attaquants recourent massivement aux réseaux proxy résidentiels... Une connexion sortante chiffrée et persistante vers un serveur proxy est maintenue.
2,477 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Recruits poorly secured routers, cameras, and DVRs using default credentials. Associated with the 2016 Dyn attack and an estimated peak of 600,000 infected devices. Its leaked source code supports numerous continuing variants.
A Mirai variant infected IoT devices in a botnet operated by Integrity Technology Group and used to power Microscan reconnaissance. In June 2024, the botnet database held records for more than 1.2 million infected devices, including more than 385,000 in the United States. Approximately 260,000 devices were actively infected at that time, including about 126,000 in the United States.
A Mirai variant infected IoT devices to build Integrity Technology Group’s botnet, supporting Microscan reconnaissance and vulnerability scanning. The Justice Department previously disrupted this botnet in September 2024, when it controlled more than 200,000 consumer devices in the United States and abroad. The variant is not separately named in the content.
A variant of Mirai infected IoT devices belonging to the botnet created and operated by Integrity Technology Group. The reference does not name the variant or identify specific vulnerabilities it exploited.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.