Mēris is a large distributed denial-of-service botnet composed primarily of compromised MikroTik routers and other internet-connected networking devices. It emerged publicly in 2021 and was associated with some of the largest application-layer DDoS attacks observed at the time, including record-setting HTTP request floods against major online services and attacks affecting organizations in multiple countries.
The botnet is closely associated with exploitation of MikroTik RouterOS devices, especially long-unpatched systems vulnerable to CVE-2018-14847, and in some cases with password-guessing against exposed router administration services. Infected devices were observed being reconfigured to support proxying behavior, including open SOCKS functionality, and Mēris operators used those compromised devices to generate high-throughput Layer 7 attack traffic. Researchers also reported use of HTTP pipelining to maximize requests per connection and increase attack efficiency.
Mēris has been linked to DDoS attacks against internet companies, financial organizations, government entities, and other public-facing services. It was implicated in attacks against Yandex, in DDoS extortion activity targeting service providers and financial entities, and in disruptive campaigns affecting Ukrainian institutions during the early 2022 Russia-Ukraine conflict. Reported victim sectors include banking and financial services, software and IT services, publishing, gambling, cryptocurrency-related services, and government websites.
Multiple investigations found that the botnet consisted predominantly of MikroTik equipment and likely represented only part of a broader, distributed infrastructure. Sinkholing efforts by defenders exposed tens of thousands of infected devices and suggested total botnet size estimates ranging from tens of thousands to roughly a quarter million systems. Geographic distribution of infected nodes was global, with substantial concentrations reported in countries including Brazil, Indonesia, India, the United States, Russia, China, Ukraine, and others.
Several analyses identified technical overlap between Mēris-related MikroTik compromise workflows and the Glupteba malware ecosystem. Observed similarities included infection logic, scheduler-task deployment patterns, and infrastructure characteristics, leading some researchers to assess that Glupteba-infected Windows hosts or Glupteba-associated tooling may have helped assemble or supply devices to the botnet. Public reporting did not conclusively establish whether the same operators controlled both ecosystems, but the linkage is widely noted.
Mēris is best characterized as an IoT and network-device botnet built for large-scale DDoS operations. Its significance lies in the scale of abuse of edge infrastructure, the efficiency of its HTTP-flooding techniques, and its demonstrated use in both criminal extortion and geopolitically relevant disruptive campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MikroTik said the attackers abused an old vulnerability (CVE-2018-14847) in its RouterOS to assemble their botnet using devices that haven't been updated by their owners. ... Glupteba module at the time that was specialized in attacking MikroTik routers found on companies' internal networks via the CVE-2018-14847 vulnerability. | Rostelecom-Solar, the cybersecurity division of Russian telecom giant Rostelecom, said on Monday that it sinkholed a part of the Meris DDoS botnet after identifying a mistake from the malware's creators.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
While the vulnerability was patched after its detection back in 2018, it’s still being exploited in compromised devices that do not use the patched RouterOS versions, or that use the default usernames and passwords.
some infected routers were reaching out and asking for new instructions from an unregistered domain at cosmosentry[.]com.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MikroTik-based botnet used for DDoS attacks and discussed as a comparison point for Zhadnost; the report says Zhadnost IPs do not appear to be part of Mēris.
A large-scale DDoS botnet historically associated with compromised MikroTik devices, used to generate high-volume distributed denial-of-service traffic.
A massive IoT botnet linked in the article as possibly spawned by Glupteba and associated with very large DDoS attacks.
Mēris is described as a large MikroTik-based DDoS botnet, likely overlapping with or representing the same infrastructure as the investigated botnet-as-a-service controlling nearly 230,000 vulnerable routers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.