Dark.IoT is a Mirai-derived botnet first disclosed in September 2021. It compromises internet-facing routers, firewalls, and other vulnerable systems to conduct distributed denial-of-service attacks. Its capabilities include IP-in-IP-based DDoS attacks, remote command execution, and an exit command added to Mirai's original command set. Observed payloads include MIPS binaries targeting network appliances.
Dark.IoT propagates through exploitation of software vulnerabilities and weak or default credentials. Exploited vulnerabilities include CVE-2018-10561 in GPON routers, CVE-2020-8949 in GoCloud routers, CVE-2015-2051 in D-Link routers, Realtek SDK vulnerabilities, and CVE-2022-26134 in Atlassian Confluence. In June 2023, it was observed exploiting CVE-2023-28771 in Zyxel firewalls through crafted Internet Key Exchange packets, followed by scripts that downloaded and executed MIPS payloads. Credential-based propagation targets services including Telnet, SSH, and Elasticsearch. Runtime parameters identify the propagation route used to infect a device.
Dark.IoT protects its configuration using ChaCha20 combined with XOR. It uses designated DNS resolvers, including DNS hosting services and OpenNIC infrastructure, to resolve command-and-control destinations. Some variants query attacker-configured DNS records for legitimate domain names, directing infected systems to attacker-selected addresses without requiring compromise of the legitimate service. Infected devices maintain command-and-control communication and receive instructions specifying attack targets and ports.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Running Parameters Propagation Path Platform: gocloud — CVE-2020-8949 — GoCloud router.
It initially spread through the Realtek SDK vulnerability (CVE-2021-35395), which was only disclosed for five days.
In June 2023, FortiGuard Labs detected the propagation of several DDoS botnets exploiting the Zyxel vulnerability (CVE-2023-28771). These attacks specifically target the command injection vulnerability in the Internet Key Exchange (IKE) packet transmitted over UDP on Zyxel devices.
Running Parameters Propagation Path Platform: Unknown — CVE-2015-2051 — Dlink router.
Later, in August 2022, it had its second active peak through CVE-2022-26134 vulnerability.
Running Parameters Propagation Path Platform: realtek/exploit.realtek — CVE-2021-35394 — Realtek SDK.
Running Parameters Propagation Path Platform: gpon — CVE-2018-10561 — Gpon fiber router.
This appears to be the Dark.IoT botnet throwing CVE-2021-36380.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT-focused botnet observed attempting command injection-style exploitation against exposed Milesight industrial cellular routers; it downloads and executes a shell script (l.sh) and is described as having additional exploits for propagation.
IoT botnet observed attempting to exploit CVE-2021-36380 and using shell commands to download and execute a script (l.sh) from a remote host; the downloaded payload is a MIPS binary and reportedly contains additional exploits for propagation.
Mirai-derived botnet observed exploiting CVE-2023-28771 to compromise Zyxel firewalls and deploy MIPS payloads. It encrypts its configuration using ChaCha20 with an XOR-modified key, resolves C2 domains through OpenNIC, and launches DDoS attacks against IP addresses and ports specified by its controller. The June 2023 version added two C2 domains.
Mirai-derived botnet targeting routers and other exposed services through known vulnerabilities and weak or default credentials. Its latest variant uses attacker-configured ClouDNS resolution records to make a legitimate-looking domain, raw.pastebin.com, resolve to attacker-controlled C2 infrastructure. This does not establish that Pastebin itself hosts the C2 server. The updated malware encrypts its configuration using ChaCha20 combined with XOR, supports command execution and exit commands, and can conduct IPIP-protocol DDoS attacks. The report describes gradually expanding activity, limited by low scanner investment and reliance on older vulnerabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.