Mozi is a Mirai- and Gafgyt-influenced peer-to-peer IoT botnet first publicly documented in 2019. It targets internet-connected embedded Linux devices, especially routers, gateways, DVRs, NVRs, IP cameras, and other SOHO or edge appliances, with observed support across ARM, MIPS, and x86 architectures. Unlike traditional centralized botnets, Mozi uses a custom protocol built on distributed hash table technology and BitTorrent-like peer discovery, which improves resilience and complicates takedown.
Mozi propagates through weak or default Telnet credentials and through exploitation of multiple known vulnerabilities affecting routers, DVRs, NVRs, CCTV systems, and related IoT products. Infected devices can host or distribute payloads to newly compromised systems and continue spreading the botnet without reliance on a single command-and-control server. The malware has been observed using UPX-packed binaries with deliberately corrupted header fields as an anti-analysis measure.
Core functionality includes distributed denial-of-service attacks, remote command execution, payload download and execution, bot updating, and collection of host information. Later variants added features to improve operational efficiency and survivability, including Mirai-style attack coordination, external IP discovery, and UPnP port mapping to expose download services from devices behind NAT. Mozi has also been associated with cryptocurrency-mining monetization through related node types and later operational evolution.
Mozi has demonstrated tailored persistence on certain network gateways, including startup-script modification, script infection, credential or management-setting changes, service disabling, and port blocking to hinder competing access. On compromised gateways, it can enable man-in-the-middle activity through DNS spoofing and HTTP session hijacking, creating opportunities for traffic interception, redirection, and broader intrusion into enterprise IT or OT environments. Because compromised edge devices can serve as footholds for reconnaissance and lateral movement, Mozi presents risk beyond volumetric botnet abuse alone.
The botnet has remained notable as one of the more prevalent Linux and IoT malware families of its period, with its decentralized architecture allowing infections to persist even after disruption of operators or portions of the network.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
It deletes the file /home/httpd/web_shell_cmd.gch. This file can be used to gain access through exploitation of the vulnerability CVE-2014-2321; deleting it prevents future attacks. | Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs).
A specific check is conducted for the existence of the /overlay folder, and whether the malware does not have write permissions to the folder /etc. In this case, it will try to exploit CVE-2015-1328. Successful exploitation of the vulnerability will grant the malware access to the following folders. | Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs).
The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a . | The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2017-17215 ... Huawei Router HG532
The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2018-10561, CVE-2018-10562 ... GPON Routers | The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a .
The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a . | The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2018-10561, CVE-2018-10562 ... GPON Routers
The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2014-8361 ... Devices using the Realtek SDK | The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a .
Widely known Internet of Things device vulnerabilities including the Spring Cloud Gateway RCE, tracked as CVE-2022-22947, the TBK DVR-4104 and DVR-4216 command injection bug, tracked as CVE-2024-3721, and an MVPower DVR misconfiguration were also abused in botnet attacks.
Widely known Internet of Things device vulnerabilities including the Spring Cloud Gateway RCE, tracked as CVE-2022-22947, the TBK DVR-4104 and DVR-4216 command injection bug, tracked as CVE-2024-3721, and an MVPower DVR misconfiguration were also abused in botnet attacks.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
“...most of the malware samples are from well-known malware families like Mirai, Gafgyt and Mozi.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...alongside NETGEAR-MOZI and other router-related flaws. This pattern suggests that the actor was focused on building or expanding botnets..."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Bot deployment : this is where the bot is deployed into a target system member of the network, for instance through an exploit... Alternatively, DDG uses exploits against Redis, Nexus Repository Manager and Supervisord... Additionally, a number of exploits affecting IoT devices such as CCTV, DVR, NVR and routers are included as a supplemental infection method.
It places the script file named S95Baby.sh in these folders. The script runs the files /usr/networks or /user/networktmp . It adds the script to /etc/rcS.d and /etc/rc.local in case it lacks privileges.
One key technique to stymie reverse engineering botnet code is to obfuscate the code by compressing or encrypting the executable, called packing.
Attackers use packers to obfuscate their code, concealing the original code with the intent of evading detection and making malware analysis more difficult and time consuming.
Bot deployment : this is where the bot is deployed into a target system member of the network, for instance through an exploit, or by brute-forcing the credentials... DDG’s method of infection involves brute-forcing the root user password against SSH servers... FritzFrog... relies on SSH credential brute-forcing as its propagation mechanism... Mozi uses weak Telnet credential brute-forcing as a way to propagate.
The Mozi botnet has been leveraging vulnerable Internet of Things (IoT) devices to launch campaigns that can take advantage of the force multiplication provided by a botnet (Distributed Denial of Service (DDoS), email spam, brute-force, password spraying, etc.).
Execution of the following commands changes the password and disables the management server for Huawei modem/router devices
The Mozi botnet communicates using a Distributed Hash Table (DHT) which records the contact information for other nodes in the botnet. This is the same serverless mechanism used by file sharing peer-to-peer (P2P) clients.
When the infected device is accessing the network through NAT... The new version of Mozi implements port mapping on the router through upnp's AddPortMapping to ensure normal access to the service.
Threat actors use peer-to-peer (P2P) botnets like these to build a platform that can later be used to carry out malicious operations... The need for increased takedown resistance eventually drove botnet operators to adapt and explore peer-to-peer approaches. | The Mozi malware family makes use of a custom P2P protocol built on top of Distributed Hash Tables (DHT) in order to build a network of infected nodes.
killall i .i mozi.m Mozi.m mozi.a Mozi.a kaiten Nbrute minerd /bin/busybox || pkill -9 -f i .i mozi.m Mozi.m mozi.a Mozi.a sora phantom zero kaiten Nbrute minerd /bin/busybox
80 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mirai-derived peer-to-peer botnet targeting IoT devices across multiple CPU architectures, propagating via direct-to-IP communications and embedding exploitation payloads directly in HTTP requests.
Botnet malware observed among families associated with the mapped C2 infrastructure.
An IoT botnet associated with abuse of compromised routers and embedded devices.
A competing botnet family referenced in the malware's process-kill list, indicating anti-competition behavior against other resident botnets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.