Satori is a Mirai-derived IoT botnet first identified in late 2017 and also referred to in some reporting as Okiru or Masuta. It targets Internet-connected embedded and networking devices, especially home and small-office routers and other Linux-based IoT systems, and became notable for extremely rapid propagation and large botnet growth. Early Satori activity infected hundreds of thousands of devices within hours to days, with major concentrations observed in regions where vulnerable consumer router models were widely deployed.
Unlike the original Mirai campaigns that relied heavily on Telnet access with default credentials, Satori variants prominently incorporated exploit-driven propagation against specific device vulnerabilities. Reported propagation vectors include exploitation of flaws in Huawei home gateways, Realtek SDK UPnP SOAP interfaces, D-Link DSL routers, DASAN GPON routers, and later other embedded products. Some variants also retained Telnet-based spreading with credential dictionaries. Satori payload delivery follows the common Mirai model of selecting architecture-appropriate Linux binaries for the victim device, and later variants expanded support to additional embedded CPU architectures including ARC and SuperH, broadening the range of susceptible hardware.
Operationally, Satori functions as a self-propagating botnet with worm-like behavior: compromised devices scan for additional targets, exploit exposed services or attempt Telnet logins, retrieve a matching payload, and join command-and-control infrastructure. Like Mirai, Satori is associated with distributed denial-of-service activity and supports coordinated flooding attacks through reused and modified Mirai attack code. Variants have also shown adaptation beyond pure DDoS botnet growth. A successor strain known as Satori.Coin.Robber targeted exposed Claymore Miner management interfaces on Windows-based mining hosts to alter mining configuration and steal cryptocurrency proceeds, while still preserving the router-focused propagation logic seen in earlier Satori samples.
Satori has been linked in public reporting to the actor alias Nexus Zeta and to related Mirai-family variants including Masuta and PureMasuta. Its evolution illustrates the post-Mirai trend toward rapidly weaponizing newly disclosed embedded-device vulnerabilities, combining exploit-based initial access, automated scanning, and multi-architecture payload deployment to build large IoT botnets for DDoS and other criminal monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hikvision is a CVE CNA and quickly assigned the CVE number, CVE-2021-36260 and released a patch for the vulnerability on the same day as the threat researcher’s disclosure... During our analysis, we observed numerous payloads attempting to leverage this vulnerability... One payload in particular caught our attention. It tries to drop a downloader that exhibits infection behavior and that also executes Moobot... CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product.
APEP also spreads by taking advantage of CVE-2017-17215, which involves another RCE vulnerability and affects Huawei HG532 router devices, for its attacks. The vulnerability was also reported to be involved in Satori and Brickerbot variants. Huawei has since released a security notice and outlined measures to circumvent possible exploitation. | The vulnerability was also reported to be involved in Satori and Brickerbot variants.
Port 52869 : Known, exploiting vulnerabilities CVE-2014-8361, related to some Realtek SDK, the exploit code PoC is published since 2016 | The security community was moving very fast to take actions and sinkhole the Satori botnet C2 after our December 5 blog. The spread of this new botnet has been temporarily halted, but the threat still remains.
On Feb. 20, 2021, Unit 42 researchers observed attempts to exploit CVE-2020-9020, which is a Remote Command Execution (RCE) vulnerability in Iteris’ Vantage Velocity field unit version 2.3.1, 2.4.2 and 3.0. | The exploit captured by Unit 42 researchers utilized the vulnerability to spread Satori, a Mirai botnet variant.
Satori Botnet — The infamous botnet that infected 260,000 devices in just 12 hours last year, Satori (also known as Okiru) has also been observed to include GPON exploit in its latest variant. | Gigabit-capable Passive Optical Network (GPON) routers manufactured by DASAN Zhone Solutions have been found vulnerable to an authentication bypass (CVE-2018-10561) and a root-RCE (CVE-2018-10562) flaws that eventually allow remote attackers to take full control of the device.
Gigabit-capable Passive Optical Network (GPON) routers manufactured by DASAN Zhone Solutions have been found vulnerable to an authentication bypass (CVE-2018-10561) and a root-RCE (CVE-2018-10562) flaws that eventually allow remote attackers to take full control of the device. | Satori Botnet — The infamous botnet that infected 260,000 devices in just 12 hours last year, Satori (also known as Okiru) has also been observed to include GPON exploit in its latest variant.
the botnet is co-located with a Xiongmai NVR/IP camera’s HTTP server... correlate three known vulnerabilities this server is affected by: CVE-2017-7577, CVE-2018-10088, and CVE-2022-45460... CVE-2018-10088, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Satori, also known as “Masuta,” is a variant of the Mirai botnet, a powerful IoT malware strain that first came online in July 2016.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Those commands are used to download and execute malicious payload from remote C2 servers to deploy bots on new victim devices. | The vulnerable devices lack a check on the htmlNtpServer parameter of /cgi-bin/timeconfig.py, allowing attackers to inject commands via crafted HTTP requests and have them executed on victim’s devices.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IoT botnet malware family derived in part from Mirai code that infects embedded/Linux-based devices, propagates via device vulnerabilities and sometimes Telnet credential attacks, checks in with command-and-control infrastructure, and launches DDoS attacks. The article highlights its evolving variants and expanded support for architectures including superh and ARC.
A named DDoS botnet referenced as having previously used the same Realtek router targeting approach.
A Mirai variant that infected large numbers of routers by exploiting a flaw in D-Link DSL-2750B devices.
Mirai-derived IoT botnet that spreads by exploiting remote code execution and command injection flaws in routers and similar edge devices, downloading architecture-specific payloads to maximize infections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.