Owari is a Mirai-derived IoT botnet that emerged in late 2017 and is associated with the threat actor known as Wicked, who also claimed involvement in the SORA botnet and was later linked to Omni and the exploit-driven WICKED propagation component. Like other Mirai descendants, Owari targets internet-exposed embedded Linux devices and routers, enrolling compromised systems into a botnet primarily used for distributed denial-of-service operations and related botnet-for-hire activity.
Early Owari activity relied on Mirai-style Telnet attacks using default or weak credentials against exposed IoT devices. As the pool of easily brute-forced devices became more saturated, Owari evolved to incorporate exploit-based propagation. High-confidence reporting links Owari to exploitation of Huawei HG532 devices via CVE-2017-17215, and related infrastructure overlaps tie it closely to Omni campaigns exploiting GPON routers via CVE-2018-10561. Owari has also been delivered through the WICKED malware component, which scans for vulnerable IoT and edge devices and uses known remote code execution and command injection flaws to fetch and execute Owari payloads.
Consistent with Mirai lineage, Owari is part of the broader ecosystem of self-propagating IoT malware that compromises devices across multiple CPU architectures, uses automated scanning and credential attacks or exploits for initial access, and incorporates botkiller behavior to remove competing malware from infected hosts. The malware family is tied to commercially motivated operations in which botnet capacity was reportedly rented to stresser services. Owari is generally discussed as one of several successive Mirai-variant projects developed in the same operator milieu as SORA, Wicked, and Omni, reflecting the post-Mirai trend from simple default-password compromise toward faster exploit-assisted propagation against unpatched IoT infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
OWARI retained the default password technique to propagate the victim device and added a few exploit scanners like CVE-2017–17215 Huawei exploit... Gafgyt primarily targets vulnerable IoT devices... It also frequently exploits known vulnerabilities like CVE-2017-17215 and CVE-2018-10561 to deliver next-stage payloads to infected devices. | OWARI, an updated version of the Mirai botnet, surfaced sometime at the end of 2017.
Roughly a week ago, a critical exploit CVE-2018–10561 found in over a million GPON home routers was reported along with POC explanation. Attackers wasted little time on taking advantage of this exploit as NewSky Security has already observed two unrelated attempted attacks by now.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
If a connection is established, it will attempt to exploit the device and download its payload... Exploits and the corresponding target ports are listed below. Port 8080: Netgear DGN1000 and DGN2200 v1 routers... Port 81: CCTV-DVR Remote Code Execution... Port 8443: Netgear R7000 and R6400 Command Injection (CVE-2016-6277)...
Mirai managed to keep 200,000 – 300,000 enslaved devices and peaked at an unbelievable 600,000... FBI special agents compared Mirai’s 1+ Tbps (1,000 Gbps)... The first Mirai incident was reported after the 18th Sep 2016 attack against popular Minecraft servers hosted on French service OVH.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai variant that retained default-password propagation and added exploit scanners plus a bot-killer module to remove competing malware from infected devices.
Owari is mentioned as one of several Mirai variants authored by Wicked.
Owari is identified as another Mirai variant developed by Sora's original author after Sora was abandoned.
Owari is a Mirai variant botnet, delivered by the Wicked bot, used to compromise IoT devices for botnet operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.