Satori is a Mirai-derived IoT botnet family, also referred to as Okiru, that emerged in late 2017. It compromises vulnerable internet-connected routers, home gateways, cameras, and other embedded Linux devices, enrolling them into a remotely controlled botnet primarily used for distributed denial-of-service attacks. Early versions propagated rapidly by exploiting vulnerabilities affecting Huawei home gateways and Realtek SDK UPnP services; subsequent variants incorporated exploits for GPON routers, D-Link routers, XiongMai uc-httpd devices, and Iteris traffic-management field units. Some versions perform self-scanning and self-propagation directly on infected devices, producing worm-like propagation rather than relying solely on separate loader infrastructure. Satori variants have also used Telnet scanning and embedded weak-credential dictionaries to expand infections. The malware supports multiple architecture-specific Linux payloads and has been observed using UDP, TCP SYN, TCP ACK, and GRE flood capabilities. A successor, Satori.Coin.Robber, additionally targeted exposed Claymore Miner management interfaces, modifying mining configuration to redirect Ethereum mining proceeds. Satori has been associated with the Nexus Zeta persona, identified as Kenneth Currin Schuchman, who pleaded guilty in 2019 to operating the botnet. The family has affected large populations of consumer and SOHO IoT devices, particularly routers deployed in regions including Latin America, Egypt, and elsewhere.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VPN Mentor disclosed CVE-2018-10562 as a GPON command-execution vulnerability. The content provides POST payloads abusing the router diagnostic endpoint to execute wget commands and download Muhstik components. | Satori also added a GPON vulnerability exploit in its latest update; it had previously infected 260,000 devices in 12 hours in December 2017.
The core Satori sample exploited the GPON vulnerability CVE-2018-10561, using a crafted request to the GponForm diagnostic endpoint to execute a wget-and-shell payload. | An updated Satori botnet began to perform network wide scan looking for uc-httpd 1.0.0 devices... Satori is a variant of the Mirai botnet.
An updated Satori botnet began to perform network-wide scans looking for uc-httpd 1.0.0 devices, most likely for the XiongMai uc-httpd 1.0.0 vulnerability (CVE-2018-10088). | An updated Satori botnet began to perform network wide scan looking for uc-httpd 1.0.0 devices... Satori is a variant of the Mirai botnet.
The one on port 52869 is derived from CVE-2014-8361. Not only are Satori penetrating with these exploits, but they also drive infected devices to download themselves from the same original download URL. | "We noticed a new version of Satori (a mirai variant which we named Satori), starting to propagate very quickly on port 37215 and 52869."
Hikvision is a CVE CNA and quickly assigned the CVE number, CVE-2021-36260 and released a patch for the vulnerability on the same day as the threat researcher’s disclosure... During our analysis, we observed numerous payloads attempting to leverage this vulnerability... One payload in particular caught our attention. It tries to drop a downloader that exhibits infection behavior and that also executes Moobot... CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product.
APEP also spreads by taking advantage of CVE-2017-17215, which involves another RCE vulnerability and affects Huawei HG532 router devices, for its attacks. The vulnerability was also reported to be involved in Satori and Brickerbot variants. Huawei has since released a security notice and outlined measures to circumvent possible exploitation. | The vulnerability was also reported to be involved in Satori and Brickerbot variants.
On Feb. 20, 2021, Unit 42 researchers observed attempts to exploit CVE-2020-9020, which is a Remote Command Execution (RCE) vulnerability in Iteris’ Vantage Velocity field unit version 2.3.1, 2.4.2 and 3.0. | The exploit captured by Unit 42 researchers utilized the vulnerability to spread Satori, a Mirai botnet variant.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Satori, also known as “Masuta,” is a variant of the Mirai botnet, a powerful IoT malware strain that first came online in July 2016.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Those commands are used to download and execute malicious payload from remote C2 servers to deploy bots on new victim devices. | The vulnerable devices lack a check on the htmlNtpServer parameter of /cgi-bin/timeconfig.py, allowing attackers to inject commands via crafted HTTP requests and have them executed on victim’s devices.
the domain name used as a control server to synchronize the activities of the Satori botnet — nexusiotsolutions-dot-net
107 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT botnet composed of compromised devices and used for large-scale DDoS attacks.
An IoT botnet composed of compromised devices and used to conduct large-scale DDoS attacks.
An IoT botnet used to conduct large-scale distributed-denial-of-service attacks.
An IoT botnet malware family derived in part from Mirai code that infects embedded/Linux-based devices, propagates via device vulnerabilities and sometimes Telnet credential attacks, checks in with command-and-control infrastructure, and launches DDoS attacks. The article highlights its evolving variants and expanded support for architectures including superh and ARC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.