Sora is a Mirai-derived IoT botnet malware family targeting Linux-based embedded devices and, in later variants, a broader set of architectures including Android-capable builds. It has been associated with the threat actor known as Wicked and was identified as part of the post-Mirai ecosystem of rapidly iterated botnet variants used to compromise exposed routers, cameras, DVRs, web servers, and other internet-facing devices.
Sora retains core Mirai functionality centered on enrolling compromised devices into a botnet for distributed denial-of-service operations. Reported variants include multi-architecture payloads and standard Mirai-style attack modules, scanner logic, credential brute-forcing, and self-propagation routines. Some campaigns used broad architecture coverage to maximize execution success across heterogeneous embedded Linux environments, and later samples were reported to run on Android as well as conventional Linux targets.
Propagation attributed to Sora has included both credential attacks and exploit-based compromise. High-confidence reporting links it to guessed or brute-forced SSH credentials and to exploitation of multiple known vulnerabilities affecting IoT devices and internet-facing applications, including vBulletin, Apache Tomcat Ghostcat, Comtrend routers, Tenda routers, Netgear routers, and GPON equipment. Sora has also been observed in the wider Mirai ecosystem as a family that competing botnets explicitly attempt to kill on infected hosts, indicating operational overlap in contested IoT environments.
Operational behavior described for Sora variants includes immediate post-compromise command execution typical of Mirai botnets, downloader or dropper components that fetch architecture-specific binaries, and process masquerading in some later campaigns. Multi-binary deployment logic has been used to try successive payloads until one matches the victim architecture. Open-directory campaigns tied to the Sora naming convention in 2026 showed continued use of packed ELF payloads and Mirai-style DDoS command sets, suggesting either continued reuse of the codebase or rebranding by later operators after the original author reportedly deprioritized the project.
Sora is closely linked to the Wicked/Owari/Omni cluster of Mirai variants. Wicked publicly claimed authorship of Sora and later stated that the project had been abandoned in favor of Owari, but subsequent reporting indicates that Sora continued to circulate and evolve after that point. Security telemetry has continued to identify Sora as an active Mirai-related threat in honeypot observations and malware campaigns, demonstrating the persistence of the family within the IoT botnet landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to analysis of the samples, they spread themselves with different combinations of the exploits of CVE-2020-5902 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of ... CVE-2020-10987 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of ... CVE-2020-10173 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of CVE-2020-5902 ... CVE-2020-1937 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
Recently, Unit 42 researchers found exploits in the wild leveraging the vBulletin pre-auth RCE vulnerability CVE-2020-17496. The exploits are a bypass of the fix for the previous vulnerability, CVE-2019-16759... We caught the first incident of CVE-2020-17496 exploitation on Aug. 10, 2020, and later found that exploitation attempts from different IP addresses are ongoing. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
Few days ago, our honeypots observed OWARI using CVE-2017–17215 Huawei exploit. Owari did not have exploit before, but now we see it in the latest variants.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The figure below shows a sequence of commands that the SORA Mirai variant executes immediately after gaining access to a device.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
The figure below shows a sequence of commands that the SORA Mirai variant executes immediately after gaining access to a device.
MITRE ATT&CK Technique ID ... Unix Shell T1059.004 ohshit.sh bash dropper
By exploiting this vulnerability, an attacker could have gained privileged access and control over any vBulletin server running versions 5.0.0 up to 5.5.4... allows attackers to send a crafted HTTP request with a specified template name and malicious PHP code, and leads to remote code execution.
UPX 3.94 packed, statically linked, section headers stripped -- standard Mirai anti-analysis
AI generated content and videos that had to do with protests... protests that didn't happen or that were not real content of existing protests... coverage of current events need to be authentic in that sense.
cat sora.< arch > >Chaotic; chmod +x *; ./Chaotic ... MITRE ATT&CK Technique ID ... Masquerading T1036.003 Binary renamed to "Chaotic"
attackers are also using techniques like Botkiller modules to kill existing malware on the device, and then run a copy of their own.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
Figure 17 shows that the exploit is trying to download a PHP script onto the victim server... Some attackers are utilizing the vulnerability to download a Perl-based script malware (Shellbot) with the PHP function shell_exec() for the execution of the system command wget from the address http://178[.]170[.]117[.]50/bot1 and run it.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a FortiGuard detection name for a Gafgyt-related sample; no additional details are provided in the content.
A botnet family referenced as a competing malware process that CondiBot attempts to kill on infected machines.
Sora is described as a Mirai-variant botnet payload distributed by the ohshit.sh shell dropper. It targets a wide range of Linux/IoT CPU architectures, downloads and executes architecture-specific ELF binaries, uses UPX packing and stripped sections for anti-analysis, and retains Mirai-style DDoS, scanning, credential brute-force, and self-propagation capabilities. The binaries are renamed and executed as "Chaotic."
Competing malware that Zerobot attempts to terminate on infected systems during deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.