Mozi is a Mirai- and Gafgyt-derived peer-to-peer IoT botnet first publicly identified in 2019. It primarily compromises Linux-based routers, network gateways, DVR/NVR and CCTV equipment, and other embedded devices across ARM, MIPS, and x86 architectures. Mozi propagates through Telnet credential brute-forcing, weak or default remote-access credentials, and exploitation of publicly known vulnerabilities in exposed IoT products. Infected devices join a decentralized Distributed Hash Table overlay that provides peer discovery, command distribution, and resilience against centralized infrastructure disruption; compromised nodes can also serve payloads to newly targeted devices.
Mozi supports distributed denial-of-service operations, password spraying and brute-force activity, command execution, payload download and update, and further propagation. Later variants added cryptocurrency-mining functionality and used a Mirai-compatible control component to improve DDoS task coordination. It can modify firewall behavior, kill competing botnet processes, and use altered UPX metadata to impede automated unpacking and analysis. Gateway-focused variants have employed device-specific persistence mechanisms, privilege escalation, script-based persistence, service-disabling changes, and port blocking. These variants can also support DNS spoofing, HTTP traffic injection, and HTTP session hijacking, creating a man-in-the-middle risk for traffic transiting an infected gateway. Mozi's decentralized architecture enables residual infections to continue operating and spreading even after disruption of operators or individual nodes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
It deletes the file /home/httpd/web_shell_cmd.gch. This file can be used to gain access through exploitation of the vulnerability CVE-2014-2321; deleting it prevents future attacks. | Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs).
A specific check is conducted for the existence of the /overlay folder, and whether the malware does not have write permissions to the folder /etc. In this case, it will try to exploit CVE-2015-1328. Successful exploitation of the vulnerability will grant the malware access to the following folders. | Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs).
The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a . | The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2017-17215 ... Huawei Router HG532
The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2018-10561, CVE-2018-10562 ... GPON Routers | The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a .
The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a . | The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2018-10561, CVE-2018-10562 ... GPON Routers
The vulnerabilities used by Mozi Botnet are shown in the following table: ... CVE-2014-8361 ... Devices using the Realtek SDK | The sample represents a brand new P2P botnet implemented based on the DHT protocol, the last botnet which uses DHT is the Hajime, and we call it Mozi according to the characteristics of its propagation sample file name Mozi.m , Mozi.a .
Widely known Internet of Things device vulnerabilities including the Spring Cloud Gateway RCE, tracked as CVE-2022-22947, the TBK DVR-4104 and DVR-4216 command injection bug, tracked as CVE-2024-3721, and an MVPower DVR misconfiguration were also abused in botnet attacks.
Widely known Internet of Things device vulnerabilities including the Spring Cloud Gateway RCE, tracked as CVE-2022-22947, the TBK DVR-4104 and DVR-4216 command injection bug, tracked as CVE-2024-3721, and an MVPower DVR misconfiguration were also abused in botnet attacks.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
“...most of the malware samples are from well-known malware families like Mirai, Gafgyt and Mozi.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...alongside NETGEAR-MOZI and other router-related flaws. This pattern suggests that the actor was focused on building or expanding botnets..."
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Bot deployment : this is where the bot is deployed into a target system member of the network, for instance through an exploit... Alternatively, DDG uses exploits against Redis, Nexus Repository Manager and Supervisord... Additionally, a number of exploits affecting IoT devices such as CCTV, DVR, NVR and routers are included as a supplemental infection method.
It places the script file named S95Baby.sh in these folders. The script runs the files /usr/networks or /user/networktmp . It adds the script to /etc/rcS.d and /etc/rc.local in case it lacks privileges.
“the botnet spreads via the use of weak and default remote access passwords for targeted devices”
It places the script file named S95Baby.sh in these folders. The script runs the files /usr/networks or /user/networktmp . It adds the script to /etc/rcS.d and /etc/rc.local in case it lacks privileges.
“the observed anti-analysis technique used by the analyzed Mozi samples consists solely of zeroing out the 8 bytes after the ‘UPX!’ magic bytes.”
“Right away we see that we have a UPX packed ELF binary” and “the p_info section of the file appears to be corrupted.”
“the botnet spreads via the use of weak and default remote access passwords for targeted devices”
“The Mozi botnet has been leveraging vulnerable Internet of Things (IoT) devices to launch campaigns that can take advantage of the force multiplication provided by a botnet (... brute-force, password spraying, etc.).”
“The Mozi botnet has been leveraging vulnerable Internet of Things (IoT) devices to launch campaigns that can take advantage of the force multiplication provided by a botnet (... brute-force, password spraying, etc.).”
Execution of the following commands changes the password and disables the management server for Huawei modem/router devices
The Mozi botnet communicates using a Distributed Hash Table (DHT) which records the contact information for other nodes in the botnet. This is the same serverless mechanism used by file sharing peer-to-peer (P2P) clients.
“The Mozi botnet communicates using a Distributed Hash Table (DHT) which records the contact information for other nodes in the botnet.”
Threat actors use peer-to-peer (P2P) botnets like these to build a platform that can later be used to carry out malicious operations... The need for increased takedown resistance eventually drove botnet operators to adapt and explore peer-to-peer approaches. | The Mozi malware family makes use of a custom P2P protocol built on top of Distributed Hash Tables (DHT) in order to build a network of infected nodes.
85 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mirai-derived peer-to-peer botnet targeting IoT devices across multiple CPU architectures, propagating via direct-to-IP communications and embedding exploitation payloads directly in HTTP requests.
Botnet malware observed among families associated with the mapped C2 infrastructure.
An IoT botnet associated with abuse of compromised routers and embedded devices.
A competing botnet family referenced in the malware's process-kill list, indicating anti-competition behavior against other resident botnets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.