Gorilla Botnet is a Mirai-derived botnet associated with distributed denial-of-service activity against critical infrastructure. It has been reported targeting organizations in the United States, Canada, and Germany. As a Mirai variant, it is part of the broader ecosystem of malware that compromises internet-connected devices to assemble botnets for large-scale network attacks. High-confidence reporting in the available material supports DDoS operations and targeting of critical infrastructure, but does not provide sufficient corroborated detail on operator identity, origin country, additional victim sectors, or broader intrusion lifecycle behaviors beyond botnet-enabled attack activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai-variant botnet conducting large-scale attacks and targeting critical infrastructure in multiple countries.
Mirai-variant botnet conducting large-scale attacks and targeting critical infrastructure in multiple countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.