Linux.Wifatch is a Linux-based IoT malware family and botnet known for behavior that has often been characterized as vigilante or pseudo-defensive rather than overtly destructive or financially motivated. It targets insecure embedded Linux devices, particularly Internet-connected routers and similar IoT systems, and is widely discussed alongside other major IoT malware families such as Mirai and Hajime. Linux.Wifatch is notable because later malware such as Hajime was explicitly compared to it for appearing to secure compromised devices after infection. The family is associated with compromised IoT environments rather than traditional enterprise endpoints, and its significance lies in the evolution of IoT botnet behavior and competition for control of exposed devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Notable IoT malware BASHLITE BrickerBot Carna Hajime Linux.Darlloz Linux.Wifatch Mirai Remaiten
Mentioned as notable IoT malware in related listing only; no further details provided in the content.
Notable IoT malware BASHLITE BrickerBot Carna Hajime Linux.Darlloz Linux.Wifatch Mirai Remaiten
Referenced as similar to Hajime in that it appears to attempt to secure infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.