SORA is a Mirai-derived botnet malware family that compromises IoT devices, network equipment, and Linux systems for distributed denial-of-service attacks. Its original development is associated with the threat actor Wicked, who subsequently shifted development to OWARI. SORA continued circulating in later variants after its original author described the project as abandoned.
SORA propagates through weak or default credentials and exploitation of vulnerable devices and web applications. Observed infection routines guess SSH passwords and download and execute multiple architecture-specific binaries until a compatible payload runs. Analyzed variants also contain exploit routines targeting vulnerabilities including CVE-2020-17496 in vBulletin, CVE-2020-10173 in Comtrend routers, and CVE-2020-10987 in Tenda routers. Its targets include embedded Linux equipment and web servers; compatible builds have also executed on Android and Debian systems.
The malware retains Mirai-style scanning, credential brute-forcing, and remotely controlled DDoS functionality. Analyzed SORA payloads support UDP, SYN, ACK, and GRE floods. Multi-architecture builds cover ARM, MIPS, x86, PowerPC, and other embedded processor families. Some variants use UPX packing, XOR-encoded strings, and process masquerading. Shell droppers distribute and execute architecture-specific payloads, and SORA has also been deployed to already-compromised Linux web servers. Its botnet capacity has been associated with commercial DDoS-for-hire activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to analysis of the samples, they spread themselves with different combinations of the exploits of CVE-2020-5902 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of ... CVE-2020-10987 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of ... CVE-2020-10173 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of CVE-2020-5902 ... CVE-2020-1937 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
Recently, Unit 42 researchers found exploits in the wild leveraging the vBulletin pre-auth RCE vulnerability CVE-2020-17496. The exploits are a bypass of the fix for the previous vulnerability, CVE-2019-16759... We caught the first incident of CVE-2020-17496 exploitation on Aug. 10, 2020, and later found that exploitation attempts from different IP addresses are ongoing. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
Few days ago, our honeypots observed OWARI using CVE-2017–17215 Huawei exploit. Owari did not have exploit before, but now we see it in the latest variants.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The figure below shows a sequence of commands that the SORA Mirai variant executes immediately after gaining access to a device.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
The figure below shows a sequence of commands that the SORA Mirai variant executes immediately after gaining access to a device.
MITRE ATT&CK Technique ID ... Unix Shell T1059.004 ohshit.sh bash dropper
By exploiting this vulnerability, an attacker could have gained privileged access and control over any vBulletin server running versions 5.0.0 up to 5.5.4... allows attackers to send a crafted HTTP request with a specified template name and malicious PHP code, and leads to remote code execution.
UPX 3.94 packed, statically linked, section headers stripped -- standard Mirai anti-analysis
AI generated content and videos that had to do with protests... protests that didn't happen or that were not real content of existing protests... coverage of current events need to be authentic in that sense.
cat sora.< arch > >Chaotic; chmod +x *; ./Chaotic ... MITRE ATT&CK Technique ID ... Masquerading T1036.003 Binary renamed to "Chaotic"
attackers are also using techniques like Botkiller modules to kill existing malware on the device, and then run a copy of their own.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
Figure 17 shows that the exploit is trying to download a PHP script onto the victim server... Some attackers are utilizing the vulnerability to download a Perl-based script malware (Shellbot) with the PHP function shell_exec() for the execution of the system command wget from the address http://178[.]170[.]117[.]50/bot1 and run it.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a FortiGuard detection name for a Gafgyt-related sample; no additional details are provided in the content.
Architecture-specific botnet payloads characterized in the report as a standard Mirai variant, downloaded from 45.141.26[.]73 and executed on compromised WordPress servers.
A botnet family referenced as a competing malware process that CondiBot attempts to kill on infected machines.
Sora is described as a Mirai-variant botnet payload distributed by the ohshit.sh shell dropper. It targets a wide range of Linux/IoT CPU architectures, downloads and executes architecture-specific ELF binaries, uses UPX packing and stripped sections for anti-analysis, and retains Mirai-style DDoS, scanning, credential brute-force, and self-propagation capabilities. The binaries are renamed and executed as "Chaotic."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.