Omni is a Mirai-derived botnet targeting Linux-based routers and other embedded devices, including digital video recorders, network video recorders, and IP cameras. Observed in May 2018, it compromises vulnerable devices and enrolls them into a centrally controlled botnet capable of distributed denial-of-service attacks. Its payloads support multiple processor architectures.
Early Omni campaigns exploited CVE-2018-10561 and CVE-2018-10562, an authentication bypass and command injection vulnerability in Dasan GPON routers that together enable unauthenticated remote command execution. The infection sequence separately downloaded a payload, granted it executable permissions, and executed it. Subsequent Omni-related samples combined eleven known exploits affecting routers and surveillance equipment, including vulnerabilities in Huawei, Netgear, D-Link, and Realtek-based devices. These samples propagated exclusively through exploitation rather than credential brute forcing, encrypted configuration strings using XOR-based schemes, and installed firewall rules to block subsequent infection attempts on selected ports.
Omni shared payload-hosting infrastructure with Owari and was also distributed through the exploit-based WICKED malware. These operational links connect it to the broader cluster of Mirai-derived botnets that included Owari, Sora, and WICKED, without establishing a confirmed operator identity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2018-10561, CVE-2018-10562: Authentication bypass and command injection vulnerabilities, respectively, for the Dasan gigabit passive optical network (GPON) routers.
Vulnerability that can allow the execution of remote arbitrary commands in Netgear R7000 and R6400 devices.
CVE-2018-10561, CVE-2018-10562: Authentication bypass and command injection vulnerabilities, respectively, for the Dasan gigabit passive optical network (GPON) routers.
Arbitrary command execution vulnerability in Huawei HG532 routers.
Universal Plug and Play (UPnP) Simple Object Access Protocol (SOAP) command execution vulnerability affecting different devices using Realtek software development kit (SDK) with the miniigd daemon.
Home Network Administration Protocol (HNAP) SOAPAction-header command execution vulnerability that works on certain D-Link devices.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
If a connection is established, it will attempt to exploit the device and download its payload... Exploits and the corresponding target ports are listed below. Port 8080: Netgear DGN1000 and DGN2200 v1 routers... Port 81: CCTV-DVR Remote Code Execution... Port 8443: Netgear R7000 and R6400 Command Injection (CVE-2016-6277)...
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Omni is mentioned as one of several Mirai variants authored by Wicked.
A historical Mirai variant cited for previously combining 11 of the exploits used by the newly reported variant. Its exploit set targeted routers, network video recorders, and digital video recorders; it did not include the Linksys and ThinkPHP exploits added in the current campaign.
A Mirai variant/botnet that evolved from exploiting GPON router flaws to incorporating a broader multi-exploit propagation set and using iptables to block reinfection attempts.
A Mirai variant/botnet that evolved from exploiting Dasan GPON router flaws to incorporating a larger multi-exploit propagation set while preventing competing infections and supporting DDoS activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.