uglybotnet is a DDoS-oriented threat actor associated with operation of a Mirai-family botnet variant referred to as Mirai.zushi. The actor has been linked to social-media claims of responsibility for disruptive attacks and to infrastructure used in a high-profile denial-of-service incident affecting a livestream on X. Reported activity indicates use of compromised devices at scale, with the botnet assessed to comprise roughly ten thousand infected systems, and use of encrypted command-and-control communications. The group’s observed tradecraft is centered on distributed denial-of-service operations rather than espionage or intrusion for data theft. Attributed activity includes operation of Mirai command-and-control infrastructure and coordination of volumetric and application-layer flooding, including HTTP request floods delivered through proxies and VPS-hosted systems to exhaust target resources. The actor is therefore best characterized as a botnet operator focused on disruptive network attacks. High-confidence reporting directly ties uglybotnet to Mirai.zushi operations, but does not firmly establish a nation-state sponsor, broader intrusion set, or additional sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.