Mossad is a Mirai-derived Internet of Things (IoT) botnet used to conduct distributed denial-of-service (DDoS) attacks against computers and servers worldwide. Its operators control compromised devices through command-and-control infrastructure and have sold access through cybercrime forums for DDoS attacks and proxy services. Authorities attributed more than 1,000 DDoS attack commands to Mossad and identified attacks against the U.S. Department of Defense Information Network.
Investigators linked Mossad's development to a German hacker using the aliases Snow and Lucy. The botnet has no relation to the Israeli intelligence service of the same name. On March 19, 2026, a coordinated law-enforcement operation involving the United States, Germany, and Canada disrupted command-and-control infrastructure supporting Mossad alongside Aisuru, KimWolf, and JackSkid. The operation targeted infrastructure used to coordinate infected devices and launch further attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The disruption itself focused on seizing domains and backend systems used to coordinate the botnets, effectively cutting off the instructions that tell infected devices where and when to send traffic.
Devices infected by the four botnets include digital video recorders, web cameras, Wi-Fi routers and TV boxes.
The infected devices were enslaved by the botnet operators. The operators then used a “cybercrime as a service” model to sell access to the infected devices to other cyber criminals.
Kimwolf — DDoS-платформой, которую сдавали в аренду «по подписке» другим хакерам... ботнет использовался для проведения более чем 25 000 атак по всему миру... пиковая мощность отдельных атак достигала 31,4 Тбит/с.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet inspired by Kimwolf that adopted weaknesses in residential proxy SDKs. The article describes more than 1,000 attack commands and a March 2026 infrastructure seizure. This name refers to the botnet, not an attributed intelligence organization.
A botnet mentioned only as part of a separate law-enforcement disruption operation.
IoT botnet mentioned as one of several botnets whose infrastructure was disrupted.
Один из четырех DDoS-ботнетов, чья управляющая инфраструктура была отключена в ходе международной правоохранительной операции. Участвовал в заражении IoT-устройств.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.