V3G4 is a Mirai-family botnet variant active by late 2025. It has been observed propagating across Linux-based devices through a large exploit set and SSH brute-forcing, indicating a focus on opportunistic compromise of internet-exposed embedded and IoT systems. As a Mirai-derived actor, its operational profile is consistent with botnet-driven distributed denial-of-service activity and large-scale device recruitment rather than targeted espionage. Reported activity places V3G4 within a broader resurgence of Mirai variants that increasingly affect routers, DVRs, industrial controllers, and other connected edge devices. High-confidence reporting specifically attributes to V3G4 the use of 13 CVEs for Linux propagation and brute-force SSH attacks, with a notable wave of new bot growth in November 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
V3G4 is a Mirai variant known for chaining multiple CVEs and brute-forcing SSH credentials to propagate across Linux-based IoT devices. It has been responsible for a resurgence in botnet activity, adding thousands of new bots in November 2025.
V3G4 is a Mirai variant known for chaining multiple CVEs and brute-forcing SSH credentials to propagate across Linux-based IoT devices, resulting in rapid botnet expansion and DDoS capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.