Unstable is a Mirai-family IoT botnet variant associated with exploitation activity against internet-exposed embedded devices. It has been observed alongside other DDoS-capable botnets targeting vulnerable routers, digital video recorders, IP cameras, smart TVs, and similar connected systems. Reported activity links Unstable to campaigns exploiting known remote code execution and command injection flaws in edge and IoT products, including mass exploitation waves against vulnerable DVR infrastructure. As a Mirai-derived threat, it is associated with establishing persistent remote access on compromised devices and using them as part of a botnet for large-scale distributed denial-of-service operations. The broader activity attributed to this cluster reflects common Mirai tradecraft such as opportunistic exploitation of newly disclosed vulnerabilities and targeting of poorly secured embedded Linux environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Broadside malware infects TBK DVR devices impacted by CVE-2024-3721, an OS command injection flaw that can be exploited remotely for arbitrary code execution.
1 distinct technique documented for this family, organized by ATT&CK tactic.
We discovered a new Mirai variant ... that exploits nine vulnerabilities, most notable of which is CVE-2020-10173 ... Another relatively recent vulnerability also used in this campaign is Netlink GPON Router 1.0.11 RCE ... the remaining five old vulnerabilities that were exploited by the variant are the following...
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unstable is a botnet malware family that targets IoT devices, including TBK DVRs, for DDoS attacks and persistent access.
Named as another Mirai variant seen in recent months.
Botnet mentioned as exploiting CVE-2024-3721 in TBK Vision DVR devices to enable DDoS-capable infections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.