Wicked is an IoT-focused threat actor associated with Mirai-derived botnet activity, particularly the SORA and OWARI botnets, and historically linked to the Wicked, Omni, and Owari variant cluster. The actor has been identified through forum monitoring, honeypot analysis, and infrastructure correlations, and has claimed authorship of SORA and OWARI together with an associate known as Karmaahof. Wicked’s operations center on compromising exposed IoT devices and enrolling them into botnets for distributed denial-of-service activity and commercial botnet rental. Early propagation relied on brute-forcing default or weak Telnet credentials in typical Mirai fashion, but the actor later expanded to exploit-based propagation as easily guessable-device populations became saturated. OWARI was observed incorporating exploitation of CVE-2017-17215, and the actor indicated additional exploit development was underway. Wicked also described experimenting with faster password-attack methods to improve infection scale. The actor has shown interest in competitive botnet operations and botkiller behavior. Wicked reportedly operated a Telnet IoT honeypot to study rival malware and identify ways to remove competing infections from compromised devices. This reflects an operational focus not only on initial access and propagation, but also on persistence and post-compromise control of infected IoT assets. Wicked is primarily financially motivated. Reported monetization involved renting botnet capacity to web stresser services, aligning the actor with the DDoS-for-hire ecosystem rather than espionage or destructive state-directed activity. No high-confidence evidence in the available facts supports attribution to a nation state or identifies a reliable country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor associated with authoring and operating multiple Mirai variants, including Owari, Omni, Wicked, and SORA.
IoT botnet operator and developer behind the SORA and OWARI botnets, monetizing access through web stresser services and evolving OWARI with exploit scanners and faster password attack methods.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.