Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Others integrated Mirai code with multiple exploits targeting both known and unknown vulnerabilities, similar to a new variant recently discovered by FortiGuard Labs, which we now call WICKED. | Port 8443: Netgear R7000 and R6400 Command Injection ( CVE-2016-6277 )
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
If a connection is established, it will attempt to exploit the device and download its payload... Exploits and the corresponding target ports are listed below. Port 8080: Netgear DGN1000 and DGN2200 v1 routers... Port 81: CCTV-DVR Remote Code Execution... Port 8443: Netgear R7000 and R6400 Command Injection (CVE-2016-6277)...
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wicked is mentioned as a Mirai variant name within the Wicked-authored family of variants.
Wicked is a Mirai variant that uses known exploits rather than brute force to compromise IoT devices. It selects exploits based on the port it connects to and is capable of downloading and delivering other Mirai variants.
A Mirai variant that scans ports 8080, 8443, 80, and 81, exploits unpatched IoT devices, and downloads payloads from a malicious site. It appears to have been repurposed over time to deliver other Mirai-derived botnets including Owari and later Omni.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.