Aquabot is a Mirai-based botnet malware family used for distributed denial-of-service attacks. It has been known since at least November 2023, with Antiy Labs reporting earlier versions, and Akamai SIRT identified a newer distinct iteration in January 2025 that they named Aquabotv3. In that campaign, Aquabotv3 was actively exploiting CVE-2024-41710, a command injection vulnerability in Mitel 6800, 6900, and 6900w series SIP phones, including the 6970 Conference Unit through R6.4.0.HF1, to gain root access and deploy the bot on compromised devices. The exploit abused the 8021xsupport.html endpoint to inject malicious content, then fetched and executed a shell script from raw2.intenseapi.com, which downloaded architecture-specific Aqua binaries for x86, ARM, ARM5, ARM6, ARM7, m68k, mips, mpsl, and sh4 and executed them. Akamai also observed the same malware spreading through exploitation of a Hadoop YARN vulnerability and targeting CVE-2018-17532, CVE-2023-26801, CVE-2022-31137, Linksys E-series RCE, CVE-2018-10562, and CVE-2018-10561. Aquabot retains standard Mirai DDoS capabilities including TCP, UDP, GRE, and bypass attack routines. Aquabotv3 was assessed as most similar to Aquabotv2 but distinct due to unusual signal-handling logic: a defend_binary() function installs handlers for SIGTERM, SIGINT, SIGKILL, SIGQUIT, SIGTSTP, SIGTTIN, SIGTTOU, and SIGHUP, sets an is_defending flag when triggered, and uses a report_kill() function to send a TCP message to command-and-control infrastructure when a kill signal is caught. Akamai stated it had not previously seen this kill-signal reporting behavior in a Mirai variant. The malware also includes process-killing functions to terminate competing or unwanted processes, including local shells, retains obfuscation and persistence-related traits introduced in Aquabotv2, and renames itself to httpd.x86 for concealment. Observed command-and-control infrastructure included 193.200.78.57:33966 and 89.190.156.145:7733. Distribution and related infrastructure included domains such as intenseapi.com and eye-network.ru, and published malicious domains included dogmuncher.xyz, cardiacpure.ru, fuerer-net.ru, eye-network.ru, intenseapi.com, cloudboats.vip, theeyefirewall.su, and awaken-network.net. Akamai reported that the operators advertised the botnet as DDoS-for-hire on Telegram under the names Cursinq Firewall, The Eye Services, and The Eye Botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the other vulnerabilities that we observed being targeted by the botnet were: ... CVE-2022-31137 ... Although the filenames differ from the straightforward “Aqua” naming from the Mitel exploit attempts, the malware from these other exploits appears to be the same. | The Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based malware, Aquabot, that is actively attempting to exploit Mitel SIP phones. As this is the third distinct iteration of Aquabot, we have dubbed it Aquabotv3.
CVE-2024-41710 is a command injection vulnerability that affects Mitel 6800, 6900, and 6900w series SIP phones, including the 6970 Conference Unit through R6.4.0.HF1 (R6.4.0.136)... Akamai SIRT detected exploit attempts targeting this vulnerability through our global network of honeypots in early January 2025... This payload will attempt to fetch and execute a shell script called “bin.sh”, which will in turn fetch and execute Mirai malware on the target system. | The Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based malware, Aquabot, that is actively attempting to exploit Mitel SIP phones. As this is the third distinct iteration of Aquabot, we have dubbed it Aquabotv3.
Some of the other vulnerabilities that we observed being targeted by the botnet were: ... CVE-2023-26801 ... Although the filenames differ from the straightforward “Aqua” naming from the Mitel exploit attempts, the malware from these other exploits appears to be the same. | The Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based malware, Aquabot, that is actively attempting to exploit Mitel SIP phones. As this is the third distinct iteration of Aquabot, we have dubbed it Aquabotv3.
The Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based malware, Aquabot, that is actively attempting to exploit Mitel SIP phones. As this is the third distinct iteration of Aquabot, we have dubbed it Aquabotv3. | Some of the other vulnerabilities that we observed being targeted by the botnet were: ... CVE-2018-10562, and CVE-2018-10561.
Some of the other vulnerabilities that we observed being targeted by the botnet were: CVE-2018-17532... Although the filenames differ from the straightforward “Aqua” naming from the Mitel exploit attempts, the malware from these other exploits appears to be the same. | The Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based malware, Aquabot, that is actively attempting to exploit Mitel SIP phones. As this is the third distinct iteration of Aquabot, we have dubbed it Aquabotv3.
Some of the other vulnerabilities that we observed being targeted by the botnet were: ... CVE-2018-10562, and CVE-2018-10561. | The Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based malware, Aquabot, that is actively attempting to exploit Mitel SIP phones. As this is the third distinct iteration of Aquabot, we have dubbed it Aquabotv3.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai-derived botnet variant that attempts to exploit Mitel phone vulnerabilities to conscript devices for DDoS activity.
A Mirai-based botnet focused on distributed denial-of-service (DDoS) activity. The newly described Aquabotv3 exploits vulnerable devices, downloads architecture-specific binaries, communicates with C2 infrastructure, kills competing processes, and uniquely reports caught kill signals back to its C2.
A Mirai-based botnet focused on distributed denial-of-service (DDoS) activity. The newly described Aquabotv3 exploits vulnerable devices, downloads architecture-specific binaries, communicates with C2 infrastructure, kills competing processes, and uniquely reports caught kill signals back to its C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.