Mirai is a malware family and botnet ecosystem centered on compromising insecure Internet of Things and embedded Linux devices, especially routers, cameras, and other edge appliances, to build large-scale distributed denial-of-service infrastructure. It became widely known in 2016 after major attacks against high-profile online targets and later evolved into a broad family of derivative botnets after its source code was publicly released. Mirai operators and follow-on variants primarily seek initial access by scanning for exposed services and exploiting weak security on internet-facing devices. Early Mirai activity relied heavily on brute forcing hardcoded or default Telnet credentials, while later variants expanded to exploit publicly disclosed remote code execution and command injection vulnerabilities in routers and other embedded devices, including flaws in web management interfaces and widely abused enterprise software such as Log4j. Once access is obtained, Mirai malware infects the device, establishes botnet control, and uses the compromised host to scan for additional victims and to generate attack traffic. The actor ecosystem associated with Mirai is best characterized as cybercriminal and opportunistic rather than a coherent nation-state group. The public release of the source code substantially lowered the barrier to entry, leading to many independently operated variants and campaigns. Mirai-derived operations have repeatedly targeted end-of-life or poorly maintained edge devices and have remained active for years because operators can rapidly weaponize proof-of-concept exploits for newly disclosed vulnerabilities affecting consumer and small-office networking equipment. Mirai’s core capability is distributed denial-of-service, but the ecosystem also demonstrates reconnaissance and broad internet scanning for vulnerable devices. Campaigns associated with Mirai have exploited command injection flaws in routers, abused exposed management services, and used compromised devices as infrastructure for further scanning, relaying traffic, and sustained botnet operations. Variants have also incorporated attack modules aimed at game-server-related traffic patterns. Mirai remains one of the most recognizable IoT botnet families and a foundational reference point for modern embedded-device botnet activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical router botnet example showing how vulnerable edge devices can be rapidly conscripted once exploitation is reliable.
A large botnet referenced as an example of home gadgets being conscripted into attack infrastructure.
Botnet activity exploiting vulnerable legacy routers to deploy Mirai variants and compromise devices for botnet operations.
Referenced as a botnet family/operator contextually associated with targeting game servers and abusing Valve Source Engine infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.