Satori is a Mirai-derived botnet known for rapidly compromising internet-exposed IoT and SOHO networking devices by exploiting known router and embedded-device vulnerabilities. It is associated with large-scale opportunistic scanning and mass exploitation campaigns against vulnerable routers and similar appliances, and has been linked to abuse of vulnerabilities in Huawei HG532 routers and D-Link DSL-2750B devices. Reporting has also connected Satori to exploitation activity against Xiongmai-based surveillance and DVR ecosystems through vulnerabilities used to recruit devices into botnets. Like other Mirai-lineage botnets, Satori is primarily oriented toward building large pools of compromised devices for downstream criminal use, especially distributed denial-of-service operations. Its operational pattern centers on identifying exposed embedded systems, exploiting weakly maintained or unpatched devices at scale, establishing control over them, and incorporating them into a botnet. The actor’s behavior is consistent with reconnaissance, scanning, initial access through vulnerability exploitation, persistence on compromised devices, and post-compromise use for DDoS activity. Satori is best understood as part of the broader ecosystem of Mirai variants and offshoots that continue to target insecure IoT infrastructure worldwide.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai-associated botnet activity cluster noted for mass router infections via exploitation of D-Link DSL-2750B devices.
Botnet reported by a third party (Netlab 360) as being linked to exploitation activity against Xiongmai devices, in the context of CVE-2018-10088 exploitation claims.
Botnet reported by a third party (Netlab 360) as being linked to exploitation activity against Xiongmai devices, in the context of CVE-2018-10088 exploitation claims.
Referenced as a botnet previously known to abuse the same Huawei router vulnerability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.