Sora is a Mirai-derived IoT botnet targeting Linux-based embedded devices, including routers, cameras, and other exposed network-connected systems. It retains core Mirai botnet behavior: scanning for accessible targets, attempting default or weak credentials over remote administration services, propagating through known remote-code-execution and command-injection vulnerabilities, and enrolling compromised devices for distributed denial-of-service operations. Observed Sora payloads support multiple processor architectures, enabling infection across a broad range of embedded Linux devices; later variants were also observed executing on Android. Its DDoS functionality includes Mirai-style UDP, TCP SYN, ACK, and GRE flooding methods. Sora has been associated with the actor using the Wicked pseudonym, who claimed authorship alongside the OWARI botnet and stated that Sora development had been abandoned. Subsequent activity indicates that other operators continued to deploy and modify Sora-derived payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to analysis of the samples, they spread themselves with different combinations of the exploits of CVE-2020-5902 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of ... CVE-2020-10987 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of ... CVE-2020-10173 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
According to analysis of the samples, they spread themselves with different combinations of the exploits of CVE-2020-5902 ... CVE-2020-1937 ... and the vulnerability CVE-2020-17496 discussed in this blog. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
Recently, Unit 42 researchers found exploits in the wild leveraging the vBulletin pre-auth RCE vulnerability CVE-2020-17496. The exploits are a bypass of the fix for the previous vulnerability, CVE-2019-16759... We caught the first incident of CVE-2020-17496 exploitation on Aug. 10, 2020, and later found that exploitation attempts from different IP addresses are ongoing. | One exploit is found to download a Mirai variant (Sora) from the attacker’s server. However, the payload is ineffective as it uses the wrong HTTP method.
Few days ago, our honeypots observed OWARI using CVE-2017–17215 Huawei exploit. Owari did not have exploit before, but now we see it in the latest variants.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The figure below shows a sequence of commands that the SORA Mirai variant executes immediately after gaining access to a device.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
The figure below shows a sequence of commands that the SORA Mirai variant executes immediately after gaining access to a device.
MITRE ATT&CK Technique ID ... Unix Shell T1059.004 ohshit.sh bash dropper
By exploiting this vulnerability, an attacker could have gained privileged access and control over any vBulletin server running versions 5.0.0 up to 5.5.4... allows attackers to send a crafted HTTP request with a specified template name and malicious PHP code, and leads to remote code execution.
UPX 3.94 packed, statically linked, section headers stripped -- standard Mirai anti-analysis
AI generated content and videos that had to do with protests... protests that didn't happen or that were not real content of existing protests... coverage of current events need to be authentic in that sense.
cat sora.< arch > >Chaotic; chmod +x *; ./Chaotic ... MITRE ATT&CK Technique ID ... Masquerading T1036.003 Binary renamed to "Chaotic"
attackers are also using techniques like Botkiller modules to kill existing malware on the device, and then run a copy of their own.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
Figure 17 shows that the exploit is trying to download a PHP script onto the victim server... Some attackers are utilizing the vulnerability to download a Perl-based script malware (Shellbot) with the PHP function shell_exec() for the execution of the system command wget from the address http://178[.]170[.]117[.]50/bot1 and run it.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a FortiGuard detection name for a Gafgyt-related sample; no additional details are provided in the content.
Architecture-specific botnet payloads characterized in the report as a standard Mirai variant, downloaded from 45.141.26[.]73 and executed on compromised WordPress servers.
A botnet family referenced as a competing malware process that CondiBot attempts to kill on infected machines.
Sora is described as a Mirai-variant botnet payload distributed by the ohshit.sh shell dropper. It targets a wide range of Linux/IoT CPU architectures, downloads and executes architecture-specific ELF binaries, uses UPX packing and stripped sections for anti-analysis, and retains Mirai-style DDoS, scanning, credential brute-force, and self-propagation capabilities. The binaries are renamed and executed as "Chaotic."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.