Satori is a Mirai-derived botnet malware family that compromises Internet-connected routers and other embedded Linux and IoT devices for distributed denial-of-service attacks. It emerged in late 2017 and rapidly spread across consumer routers, with substantial activity in Egypt and Latin America. Kenneth Currin Schuchman, known as Nexus Zeta, operated Satori with co-conspirators and pleaded guilty in 2019 to conduct involving the botnet.
Satori combines Internet-wide scanning with vulnerability exploitation and, in some variants, Telnet dictionary attacks. Established propagation vectors include CVE-2017-17215 in Huawei HG532 routers and CVE-2014-8361 in Realtek SDK UPnP SOAP implementations. Later variants incorporated the GPON authentication-bypass and command-injection vulnerabilities CVE-2018-10561 and CVE-2018-10562, as well as remote command execution against D-Link DSL-2750B routers. Some versions perform scanning and directly deploy malware to new targets without separate loader infrastructure, enabling worm-like self-propagation. Architecture-specific Linux payloads support a broad range of embedded processors, including ARM, MIPS, x86, SuperH, and ARC.
Infected devices receive attack instructions through command-and-control infrastructure. Observed Satori variants support UDP, TCP SYN, TCP ACK, and GRE floods. Variants have used packed executables, encrypted configuration data, and DNS-based command-and-control mechanisms. Sinkholing and ISP filtering disrupted early outbreaks, but subsequent variants resumed activity.
The Satori.Coin.Robber variant additionally targets exposed Claymore Miner management interfaces, predominantly on Windows mining hosts. It abuses unauthenticated management operations to alter mining-pool and wallet settings and restart mining hosts, redirecting victims’ Ethereum mining proceeds to the attacker while retaining Satori’s router-exploitation capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Port 37215 : Known, exploiting vulnerabilities CVE-2017-17215, Huawei recently released the relevant statement.
Port 52869 : Known, exploiting vulnerabilities CVE-2014-8361, related to some Realtek SDK, the exploit code PoC is published since 2016.
CVE-2018-10561 is a web interface vulnerability reported in DZS GPON ZNID-GPON-25XX series routers in 2018, which allows adversaries to bypass authentication in the web interface of the router. | Well-known malware families such as Satori have been identified in the wild exploiting this vulnerability to compromise devices and spread infections.
Commands are concatenated to the dest_host parameter being passed to the ping command available as a feature for network diagnostics. This leads to a command injection vulnerability (CVE-2018-10562). | Well-known malware families such as Satori have been identified in the wild exploiting this vulnerability to compromise devices and spread infections.
An updated Satori botnet began to perform network-wide scans looking for uc-httpd 1.0.0 devices, most likely for the XiongMai uc-httpd 1.0.0 vulnerability (CVE-2018-10088). | An updated Satori botnet began to perform network wide scan looking for uc-httpd 1.0.0 devices... Satori is a variant of the Mirai botnet.
Hikvision is a CVE CNA and quickly assigned the CVE number, CVE-2021-36260 and released a patch for the vulnerability on the same day as the threat researcher’s disclosure... During our analysis, we observed numerous payloads attempting to leverage this vulnerability... One payload in particular caught our attention. It tries to drop a downloader that exhibits infection behavior and that also executes Moobot... CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product.
On Feb. 20, 2021, Unit 42 researchers observed attempts to exploit CVE-2020-9020, which is a Remote Command Execution (RCE) vulnerability in Iteris’ Vantage Velocity field unit version 2.3.1, 2.4.2 and 3.0. | The exploit captured by Unit 42 researchers utilized the vulnerability to spread Satori, a Mirai botnet variant.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This sudden change in the behavior of Hakai author is related to the recent arrest of Nexus Zeta, the operator of another IoT botnet named Satori.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Those commands are used to download and execute malicious payload from remote C2 servers to deploy bots on new victim devices. | The vulnerable devices lack a check on the htmlNtpServer parameter of /cgi-bin/timeconfig.py, allowing attackers to inject commands via crafted HTTP requests and have them executed on victim’s devices.
the domain name used as a control server to synchronize the activities of the Satori botnet — nexusiotsolutions-dot-net
109 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT botnet composed of compromised devices and used for large-scale DDoS attacks.
An IoT botnet composed of compromised devices and used to conduct large-scale DDoS attacks.
An IoT botnet used to conduct large-scale distributed-denial-of-service attacks.
An IoT botnet malware family derived in part from Mirai code that infects embedded/Linux-based devices, propagates via device vulnerabilities and sometimes Telnet credential attacks, checks in with command-and-control infrastructure, and launches DDoS attacks. The article highlights its evolving variants and expanded support for architectures including superh and ARC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.