Murdoc is a Mirai-derived botnet, also described as a Corona derivative, that targets internet-exposed IoT and router infrastructure for botnet propagation and distributed denial-of-service operations. It has been observed exploiting CVE-2024-12856 in Four-Faith routers and using brute-force Telnet activity to compromise devices. Reported functionality includes Mirai-style scanning and DDoS command support, with malware samples using custom packing for obfuscation. Activity attributed to Murdoc reached roughly 15,000 bots in late 2025, with bot populations reported primarily in China and the United States. Murdoc has been associated with attacks affecting industrial environments and telecommunications, including disruption impacting manufacturing and telecom targets. Known aliases include Murdoc_Botnet and Murdoc.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet using Mirai malware.
Murdoc is a Mirai-based botnet variant that primarily targets industrial and manufacturing sectors by exploiting vulnerabilities in Four-Faith routers and other IoT devices. It uses brute-force attacks and custom-packed binaries to propagate and conduct DDoS attacks.
Murdoc is a Mirai-based botnet variant active in November 2025, targeting industrial and manufacturing sectors by exploiting router vulnerabilities and launching DDoS attacks. It uses brute-force Telnet attacks and custom packers for persistence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.