Torii is a multi-architecture IoT botnet and backdoor platform active since at least December 2017. It compromises Internet-exposed devices through Telnet credential attacks against weak passwords, then uses an architecture-discovery shell script and multiple download utilities to retrieve a suitable ELF payload. Torii supports MIPS, ARM, x86, x86-64, PowerPC, SuperH, and other embedded Linux architectures. Its staged deployment installs a persistent second-stage bot that survives reboots through multiple mechanisms, including shell-profile modification, cron, systemd and init configuration, SELinux-policy modification, and inittab changes. The bot employs delayed execution, runtime string decryption, stripped binaries, and randomized process names to impede analysis and detection. Torii communicates through encrypted, non-TLS traffic over TCP/443, supports C2 failover, fingerprints compromised devices, exfiltrates host and system information, transfers and manages files, downloads content, migrates C2 configuration, and executes arbitrary commands. No clear DDoS or cryptomining functionality was established in observed versions. The operator and ultimate operational purpose remain unattributed; Torii has been assessed as a persistent backdoor and orchestration service for compromised IoT devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
He noticed that the attack was on port 23 specific to Telnet, but the communication was tunneled through the Tor network, a detail that inspired Avast for the botnet name.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a suspected predecessor to RotaJakiro for comparison with PeerBlight; no direct campaign use described in this content.
被描述为僵尸网络(botnet)。文中用于与 RotaJakiro 做溯源对比:在字符串/命令复用、流量构造常数与方式、以及“old-school”持久化与加密隐藏资源等风格上相似,因此作者推测两者可能出自同一团伙。
Linux botnet referenced as potentially related to RotaJakiro based on code, command, traffic, and functional similarities. The content does not establish attribution or confirm a shared operator.
An IoT botnet/backdoor targeting devices with exposed Telnet and weak credentials. It supports many CPU architectures, uses encrypted C2 communications, fingerprints infected devices, exfiltrates host and system information, executes commands remotely, and establishes strong persistence through multiple mechanisms so it survives reboots.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.