LeetHozer is a Mirai-derived IoT botnet first observed in March 2020. It primarily targets XiongMai H.264 and H.265 surveillance devices, enabling Telnet through an exposed device vulnerability and then attempting authentication with default credentials. It uses Mirai-style high-speed scanning and retains elements of Mirai reporter and loader functionality, but implements distinct bot logic, string encryption, and command-and-control protocols. LeetHozer supports tcpraw, ICMP echo, and UDP flood distributed-denial-of-service attacks. Variants use both direct and Tor-mediated command-and-control communications, with a custom two-stage handshake before receiving heartbeat, bot-group, and attack instructions. LeetHozer shares an exploitation string and downloader infrastructure with a moobot_xor variant, while the Moobot_leet variant reuses LeetHozer's encryption method, demonstrating technical overlap among these IoT botnet developments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We exposed a new branch developed by this group, LeetHozer, on April 27, 2020, and compared with Matryosh, the similarities between the two are reflected in the following 3 aspects.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The sample uses a custom algorithm for encryptiton. The decryption algorithm is as follows: xorkey="qE6MGAbI"
112 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another malware family previously observed using Tor-based C2 communications.
A previously exposed botnet branch attributed in the content to the Moobot group, cited for similarities to Matryosh in TOR-like C2 model, port 31337, and command format.
Referenced because Moobot_leet reuses its encryption method for Tor-C2 string protection.
A newly identified Mirai-like botnet malware branch, likely linked to the Moobot group, targeting XiongMai H.264/H.265 devices via TCP/9530 to enable telnetd, log in with default credentials, propagate, report infected device information, and receive C2 commands to launch DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.