Owari is a Mirai-derived IoT botnet malware family associated with the threat actor known as Wicked and closely related to the Sora, Omni, and Wicked botnet lineage. It targets Internet-exposed embedded Linux devices and routers, propagating first through default-credential attacks and later through exploit-based compromise as the operator expanded beyond Mirai’s original Telnet-centric model. Owari has been observed incorporating exploitation of CVE-2017-17215 affecting Huawei devices, and reporting has linked its broader ecosystem to exploit-driven delivery chains used against vulnerable IoT infrastructure.
Like other Mirai variants, Owari is designed to compromise devices at scale, enroll them into a botnet, and support distributed denial-of-service operations. Its development reflects the broader evolution of post-Mirai botnets from simple brute-force propagation toward mixed scanning and exploitation workflows. The malware has been described as actively developed after Sora was abandoned, with additional exploit scanners added to improve growth in an increasingly saturated IoT environment where default-password compromises were becoming less effective.
Owari is part of a cluster of related malware families that share infrastructure, development patterns, and operator overlap. Security reporting has linked Owari with Omni through shared hosting and operational artifacts, and assessed that these botnets were likely developed by the same author or group. In later observations, infrastructure previously used to distribute Owari payloads was repurposed to deliver Omni, indicating iterative reuse of tooling and delivery mechanisms across successive Mirai-variant projects. Owari has also been referenced as less persistent in the active threat landscape than Sora, suggesting it was eventually superseded within the same development lineage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Roughly a week ago, a critical exploit CVE-2018–10561 found in over a million GPON home routers was reported along with POC explanation. Attackers wasted little time on taking advantage of this exploit as NewSky Security has already observed two unrelated attempted attacks by now.
Few days ago, our honeypots observed OWARI using CVE-2017–17215 Huawei exploit. Owari did not have exploit before, but now we see it in the latest variants. | OWARI was started around 6 months ago ... At first, these two botnets both used only default password attacks, but as it progressed I added a few exploit scanners into OWARI.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
If a connection is established, it will attempt to exploit the device and download its payload... Exploits and the corresponding target ports are listed below. Port 8080: Netgear DGN1000 and DGN2200 v1 routers... Port 81: CCTV-DVR Remote Code Execution... Port 8443: Netgear R7000 and R6400 Command Injection (CVE-2016-6277)...
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Owari is mentioned as one of several Mirai variants authored by Wicked.
Owari is identified as another Mirai variant developed by Sora's original author after Sora was abandoned.
Owari is a Mirai variant botnet, delivered by the Wicked bot, used to compromise IoT devices for botnet operations.
A Mirai variant delivered by Wicked from the same malicious infrastructure before being replaced by Omni. The article states Owari was one of the author's projects and was later abandoned.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.