murdoc
Murdoc is a Mirai-based botnet variant, specifically a derivative of the Corona strain, active as of November 2025. It exploited Four-Faith routers via CVE-2024-12856 and primarily targeted industrial systems and sectors, including manufacturing and critical infrastructure. Murdoc peaked at approximately 15,000 infected bots, with major activity observed in China, the U.S., and disruptions reported in Iranian telecommunications. Its infection vectors included exploitation of unpatched firmware and supply chain vulnerabilities. Murdoc's operations contributed to high-volume DDoS attacks and disruptions in targeted sectors. There is no direct evidence linking Murdoc to nation-state actors, but its impact on industrial and critical infrastructure aligns with tactics seen in advanced IoT botnet campaigns. No known aliases or sub-groups are mentioned in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Murdoc is a Mirai-based botnet variant that primarily targets industrial and manufacturing sectors by exploiting vulnerabilities in Four-Faith routers and other IoT devices. It uses brute-force attacks and custom-packed binaries to propagate and conduct DDoS attacks.
Murdoc is a Mirai-based botnet variant active in November 2025, targeting industrial and manufacturing sectors by exploiting router vulnerabilities and launching DDoS attacks. It uses brute-force Telnet attacks and custom packers for persistence.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.