Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets. The exploit is included in some version of rapperbot and exploited in 2026. | “The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity.”
4 distinct techniques documented for this family, organized by ATT&CK tactic.
KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mirai-derived botnet observed exploiting the KGUARD DVR command-execution vulnerability to propagate malware and conduct subsequent DDoS activity.
A Mirai-derived botnet reported to exploit the KGUARD DVR command-execution vulnerability for propagation and subsequent DDoS activity.
Another Mirai variant mentioned in the timeline as having first exploited the same RUIJIE vulnerability to spread.
Another Mirai variant reported to be exploiting the same (undisclosed) KGUARD DVR vulnerability to propagate.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.