Meris is a large botnet associated with high-volume distributed denial-of-service activity, especially HTTP flood and related extortion campaigns. It became widely known in 2021 after record-setting attacks against major online services, including Yandex, and additional attacks affecting organizations in Russia, New Zealand, and the United States. Meris has been repeatedly linked to abuse of compromised MikroTik routers and other internet-connected devices, with reporting tying its scale in part to exploitation of CVE-2018-14847 and to weak or exposed device administration. The botnet has also been described as overlapping with infrastructure connected to the Glupteba criminal ecosystem, including proxy-oriented operations built on hijacked routers. Meris has been used to generate extremely large request volumes and to target public-facing websites, including business communications and sales platforms. Observed operations include DDoS extortion in which attackers embedded ransom demands directly into attack traffic and threatened financial and reputational harm unless victims paid. In those campaigns, the operators impersonated the REvil brand, but attribution to REvil itself was not confirmed. The botnet’s operators have used compromised devices as attack infrastructure and as proxy capacity, while masking traffic as legitimate browsers or crawlers. The actor’s demonstrated capabilities center on initial compromise of exposed devices, persistence on hijacked infrastructure, defense evasion, spoofing, and large-scale DDoS operations. Meris is best characterized as a financially motivated cybercriminal botnet operation rather than a nation-state intrusion set. Cloudflare has assessed the later Mantis botnet as an evolution of Meris, shifting from primarily compromised MikroTik devices toward cloud-hosted virtual machines and servers while retaining the same emphasis on massive HTTP DDoS capability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for comparison as another MikroTik-based botnet associated with DDoS activity, but not identified as the actor behind the attacks discussed here.
A botnet associated in the content with DDoS attacks using compromised IoT devices, particularly MikroTik routers, against popular websites.
Large botnet abusing MikroTik devices for DDoS attacks; the article suggests the investigated router botnet-as-a-service may be the same as or closely tied to Mēris.
Botnet assessed as the infrastructure behind the DDoS extortion attacks discussed in the article, powered by compromised IoT devices including MikroTik routers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.