Omni is a Mirai-derived IoT botnet malware family active since 2018 that targets embedded Linux devices, especially internet-exposed routers and similar appliances. It has been observed exploiting Dasan GPON router vulnerabilities including CVE-2018-10561 and CVE-2018-10562, and later evolving into broader exploit-based propagation against multiple classes of IoT equipment such as routers, DVRs, NVRs, and IP cameras. Reported Omni campaigns incorporated numerous publicly known remote code execution and command injection flaws in a single sample, reflecting rapid operationalization of newly disclosed vulnerabilities.
Omni infections have been described as using staged command execution to download, permission, and run Mirai-style binaries compiled for multiple processor architectures. Unlike the original Mirai model centered on credential brute forcing, Omni has been specifically characterized in observed campaigns as relying on exploit-based propagation. Samples have also been reported to modify local firewall rules on compromised devices to hinder reinfection by competing malware. As a Mirai-family bot, Omni is associated with botnet operation and distributed denial-of-service capability, although the supplied facts most directly support its role as exploit-propagating IoT bot malware.
Omni has been linked through shared infrastructure and development lineage to other Mirai-related botnets including Owari, Sora, and Wicked. Multiple analyses assessed these families as closely related and likely operated by the same author or development cluster, with Wicked infrastructure at one stage repurposed to deliver Owari and later Omni payloads. Omni has also been cited as one of several Mirai-era variants that became less prominent over time relative to surviving families such as SORA.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Roughly a week ago, a critical exploit CVE-2018–10561 found in over a million GPON home routers was reported along with POC explanation. Attackers wasted little time on taking advantage of this exploit as NewSky Security has already observed two unrelated attempted attacks by now. | Attack 1: Omni botnet in the making ... The exploit has been weaponized in three steps to download and run Mirai style payload of different architectures.
the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562/10562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device. | In May 2018, the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562 (command injection).
CVE-2017-17215 ... Huawei HG532
CVE-2014-8361 ... Different devices using the Realtek SDK with the miniigd daemon
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
If a connection is established, it will attempt to exploit the device and download its payload... Exploits and the corresponding target ports are listed below. Port 8080: Netgear DGN1000 and DGN2200 v1 routers... Port 81: CCTV-DVR Remote Code Execution... Port 8443: Netgear R7000 and R6400 Command Injection (CVE-2016-6277)...
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Omni is mentioned as one of several Mirai variants authored by Wicked.
A Mirai variant/botnet that evolved from exploiting GPON router flaws to incorporating a broader multi-exploit propagation set and using iptables to block reinfection attempts.
A Mirai variant/botnet that evolved from exploiting Dasan GPON router flaws to incorporating a larger multi-exploit propagation set while preventing competing infections and supporting DDoS activity.
Omni is a Mirai variant botnet, distributed via the Wicked bot, used to compromise IoT devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.