LeetHozer is a Mirai-like IoT botnet malware family assessed as a distinct branch associated with the Moobot ecosystem. First observed in 2020, it departs from conventional Mirai variants by redesigning core bot logic, string encryption, and command-and-control communications while still reusing portions of Mirai’s reporter and loader functionality. It targets internet-exposed embedded Linux devices, particularly XiongMai H.264 and H.265 surveillance hardware.
LeetHozer propagates by scanning for devices exposing a vulnerable service on TCP port 9530. It exploits that service to enable Telnet access and then attempts authentication with built-in default credentials to complete compromise. After successful access, the malware reports the infected device to its botnet infrastructure and waits for commands from its controller. Observed samples were ELF binaries for Linux-based embedded systems.
The malware uses custom XOR-based string obfuscation and a bespoke command-and-control protocol that includes a multi-stage handshake, heartbeat messaging, bot-group reporting, and attack tasking. Multiple versions have been observed using both direct IP-based and Tor-based command-and-control infrastructure, indicating active development and operational adaptation. Reverse-engineering has shown interaction with watchdog devices and other execution behaviors consistent with maintaining stable operation on constrained embedded targets.
LeetHozer’s primary operational purpose is distributed denial-of-service activity. Observed attack methods include tcpraw, icmpecho, and udpplain. Similarities in exploitation tradecraft, encryption design, infrastructure overlap, and attack nomenclature link LeetHozer to Moobot-related development, and it has been characterized as a likely new branch within that broader botnet lineage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We exposed a new branch developed by this group, LeetHozer, on April 27, 2020, and compared with Matryosh, the similarities between the two are reflected in the following 3 aspects.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The sample uses a custom algorithm for encryptiton. The decryption algorithm is as follows: xorkey="qE6MGAbI"
112 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously exposed botnet branch attributed in the content to the Moobot group, cited for similarities to Matryosh in TOR-like C2 model, port 31337, and command format.
Referenced because Moobot_leet reuses its encryption method for Tor-C2 string protection.
A newly identified Mirai-like botnet malware branch, likely linked to the Moobot group, targeting XiongMai H.264/H.265 devices via TCP/9530 to enable telnetd, log in with default credentials, propagate, report infected device information, and receive C2 commands to launch DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.