Mukashi is a Mirai variant that targets Linux-based network-attached storage devices, notably vulnerable Zyxel NAS systems. It was observed being deployed shortly after public disclosure of CVE-2020-9054, a critical pre-authentication command injection flaw in Zyxel NAS firmware, demonstrating rapid weaponization of newly published exploit code against internet-exposed storage appliances.
Operationally, Mukashi follows established Mirai botnet behavior while incorporating variant-specific implementation details. Infection activity associated with Mukashi used remote command execution on vulnerable NAS devices to retrieve and run a shell script that downloaded architecture-specific bot binaries, executed them, and removed traces. Once active, the malware scans random hosts for Telnet services, brute-forces logins using default credential combinations, and reports successful compromises to its command-and-control infrastructure. It also receives remote commands to launch distributed denial-of-service attacks, with support for multiple UDP-, TCP-, and HTTP-based flooding modes.
Mukashi includes several bot-management and defense-evasion features. It changes its process name to resemble benign system activity, binds a local TCP port to enforce single-instance execution, and decodes embedded strings such as credentials and command names during initialization using a custom decryption routine rather than the simpler obfuscation commonly seen in earlier Mirai samples. Some builds also exhibit anti-competition behavior associated with Mirai-derived botnets, including functionality intended to remove or suppress rival malware processes.
The malware is part of the broader evolution of Mirai-derived botnets from generic IoT targeting toward exploitation of NAS appliances and other embedded Linux systems. Its activity underscores the attractiveness of NAS devices as botnet targets because they are frequently internet-exposed, often under-hardened, and commonly run on capable Linux-based hardware. Mukashi is primarily associated with botnet propagation, credential brute-forcing, and DDoS operations against network-connected devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
As soon as the proof-of-concept (PoC) for CVE-2020-9054 was made publicly available last month, this vulnerability was promptly abused to infect vulnerable versions of Zyxel network-attached storage (NAS) devices with a new Mirai variant - Mukashi.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Mirai variant seen in recent months.
A new Mirai variant targeting vulnerable Zyxel NAS devices via CVE-2020-9054. It scans random hosts on TCP/23, brute-forces default credentials, reports successful logins to its C2, receives commands, and launches DDoS attacks including UDP, TCP, HTTP, and bypass variants. It also enforces single-instance execution and in some builds can kill competing processes.
Mirai variant specifically noted for targeting Zyxel NAS devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.