Dark.IoT is a botnet referenced in observed opportunistic exploitation activity against internet-exposed devices. In the provided content, it is associated with command injection attempts targeting Milesight industrial cellular routers, specifically activity assessed as attempting exploitation of CVE-2021-36380. Logged requests included a payload that downloaded and executed a script (l.sh) from 194.180.48[.]100, and the analyzed sample included a MIPS binary that reportedly used additional exploits for propagation. The activity is described as botnet-style probing rather than targeted intrusion, and no specific threat actor, industry targeting, or broader malware capabilities beyond spreading via multiple exploits are directly established in the content. Known indicators mentioned in the content include the download host 194.180.48[.]100 and references to CVE-2021-36380 exploitation attempts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This appears to be the Dark.IoT botnet throwing CVE-2021-36380.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT-focused botnet observed attempting command injection-style exploitation against exposed Milesight industrial cellular routers; it downloads and executes a shell script (l.sh) and is described as having additional exploits for propagation.
IoT botnet observed attempting to exploit CVE-2021-36380 and using shell commands to download and execute a script (l.sh) from a remote host; the downloaded payload is a MIPS binary and reportedly contains additional exploits for propagation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.