Murdoc Botnet is a Mirai-derived botnet malware operation targeting Linux-based embedded systems, particularly IoT and network-connected devices such as IP cameras and routers. Activity associated with this variant has been observed since at least July 2024 and has focused on exploiting known vulnerabilities in exposed devices, including AVTECH cameras and Huawei HG532 routers, with additional indications of targeting TP-Link equipment. The infection chain uses remote command execution to deliver shell scripts and ELF binaries that retrieve, execute, and then remove the malware payload from compromised hosts. The scripts use common Unix tooling and GTFOBins-style tradecraft to stage the payload and complete installation.
As a Mirai variant, Murdoc Botnet is associated with botnet operations and distributed denial-of-service activity. Its infrastructure has included numerous servers used both for malware distribution and for communication with infected devices. The malware is notable for broad targeting of insecure or unpatched Unix-like devices and for maintaining a multi-architecture payload set, including x86 and x86_64 samples, consistent with campaigns aimed at heterogeneous embedded environments. Murdoc Botnet fits the broader post-leak Mirai ecosystem in which actors adapt the original codebase to build scalable botnets against vulnerable IoT and edge devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This botnet also uses some existing exploits (CVE-2024-7029, CVE-2017-17215) to download the next-stage payloads. Figure 4: Huawei Exploit inside binary (CVE-2017-17215) | The Qualys Threat Research Unit has uncovered a large-scale, ongoing operation within the Mirai campaign, dubbed Murdoc Botnet... Murdoc Botnet Mirai malware, here dubbed as Murdoc Botnet, is a prominent malware family for *nix systems.
This botnet also uses some existing exploits (CVE-2024-7029, CVE-2017-17215) to download the next-stage payloads. Figure 5: Embedding Payloads by exploiting CVE-2024-7029 | The Qualys Threat Research Unit has uncovered a large-scale, ongoing operation within the Mirai campaign, dubbed Murdoc Botnet... Murdoc Botnet Mirai malware, here dubbed as Murdoc Botnet, is a prominent malware family for *nix systems.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet listed as using Mirai malware.
Mirai botnet variant exploiting vulnerabilities in AVTECH IP cameras and Huawei routers to build botnets for large-scale attacks.
A Mirai variant targeting vulnerable AVTECH cameras, Huawei HG532 routers, TP-Link devices, IP cameras, network devices, and other IoT devices. It propagates by exploiting known vulnerabilities, downloading next-stage payloads via shell scripts/ELF binaries, establishing botnet infections, and was analyzed in connection with DDoS activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.