TerraBot is an IoT botnet associated with Mirai- and Gafgyt-derived tradecraft. It conducts opportunistic internet-wide scanning and exploitation attempts against exposed embedded and edge devices in order to compromise them and expand a botnet of infected systems. Observed activity shows repeated targeting of known vulnerabilities affecting GPON routers, D-Link DSL gateways, and MVPower DVR devices, indicating a focus on commodity IoT exploitation for botnet propagation. The actor’s behavior is characterized by automated initial-access attempts against internet-facing devices, broad scanning, and post-compromise payload delivery patterns typical of Mirai-family ecosystems. TerraBot has been observed using exploit requests intended to download and execute malware on vulnerable devices, but some campaigns exhibited poor operational quality, including malformed HTTP requests and incomplete exploit bodies that prevented successful execution. Despite this uneven engineering, the activity aligns with commodity botnet operations that continuously probe for exploitable devices at scale. TerraBot is best understood as a botnet operation rather than a nation-state intrusion set. Available evidence supports financially or operationally motivated botnet growth behavior, but does not establish ransomware, espionage, or destructive objectives. No additional high-confidence aliases or sub-groups are established beyond the TerraBot name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.