V3G4 is a Mirai-derived Linux malware family that combines botnet functionality with cryptocurrency mining. It targets Linux servers and internet-exposed IoT devices across multiple CPU architectures, including x86_64, ARM, and MIPS variants. The malware has been observed using a multi-stage infection chain in which a shell-based downloader identifies the victim architecture, retrieves an appropriate binary, and launches it. V3G4 bot components are associated with SSH-focused internet scanning and brute-force propagation, while related activity has also been reported exploiting multiple vulnerabilities to expand infections.
Once active, V3G4 performs host reconnaissance, disguises itself as legitimate system processes, detaches from the controlling terminal, and suppresses standard input and output to reduce visibility. The bot establishes command-and-control connectivity using TCP and DNS-based resolution, and uses multi-threaded SYN scanning to identify additional SSH targets for propagation. As a Mirai-derived botnet, it is associated with distributed denial-of-service operations and persistent remote control of compromised devices.
A notable feature of V3G4 is its hybrid monetization model. In addition to botnet activity, later-stage payloads deploy an XMRig-based Monero miner configured at runtime rather than through static on-disk files. This fileless configuration approach allows operators to rotate mining parameters dynamically and reduces forensic artifacts. The miner process is also disguised to blend into the host environment.
V3G4 has been tracked in campaigns affecting Linux infrastructure and IoT environments, with reporting linking it to active large-scale propagation and botnet growth. The family reflects the continuing evolution of Mirai-derived malware toward multi-purpose operations that combine DDoS capability, stealth, credential attacks, and cryptocurrency mining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Once executed, the UPX-packed and stripped binary gathers system information through environment reconnaissance
Once executed, the UPX-packed and stripped binary gathers system information through environment reconnaissance
Multiple worker threads simultaneously perform high-velocity SYN packet spraying on port 22 across the internet, enabling rapid SSH brute-force propagation to new victims.
Once executed, the UPX-packed and stripped binary gathers system information through environment reconnaissance, checking kernel details and process limits to determine operational parameters.
the bot performs multi-threaded DNS queries against Google’s public DNS server (8.8.8.8) to resolve the C2 domain baojunwakuang.asia, which maps to 159.75.47.123 and serves both botnet commands and miner configuration through non-standard ports like 60194
The attack begins with a compact shell script called Universal Bot Downloader that automatically identifies the victim system’s CPU architecture using the uname -m command... the script constructs a tailored download URL and fetches the appropriate bot binary from the attacker-controlled server at 103.149.93.224.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
V3G4 is a Mirai variant that uses a chain of 13 CVEs to propagate via SSH brute-force and exploits, rapidly expanding its botnet for DDoS operations.
V3G4 is a Mirai variant known for chaining multiple CVEs and brute-forcing SSH credentials to propagate across Linux-based IoT devices, forming large botnets for DDoS attacks.
A Mirai-derived botnet targeting Linux systems, paired with a fileless cryptocurrency miner for Monero.
A sophisticated Linux malware campaign combining Mirai-derived DDoS botnet functionality with a stealthy fileless cryptominer. It targets Linux servers and IoT devices, performs SSH brute-force propagation, establishes C2 communications, and deploys a covert miner while using process masquerading and dynamic configuration retrieval for stealth.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.