Mukashi is a Mirai variant targeting internet-exposed Zyxel network-attached storage and related network security appliances. It emerged in 2020 and was observed abusing CVE-2020-9054, a critical pre-authentication command injection flaw in vulnerable Zyxel NAS firmware, to gain remote code execution and deploy architecture-specific bot binaries. It has also been described targeting Zyxel NAS, UTM, ATP, and VPN firewall products.
Functionally, Mukashi follows the Mirai botnet model. After compromise, it executes as a Linux bot, enforces a single running instance, changes its process identity for concealment, and can remove traces of the dropped payload. It scans random hosts over Telnet, brute-forces default or weak credentials, and reports successful logins back to its command-and-control infrastructure for further propagation. Like other Mirai-derived malware, it is built to conscript devices into a botnet that can be used for distributed denial-of-service operations.
Mukashi supports multiple botnet commands and DDoS attack modes, including TCP-, UDP-, and HTTP-based flooding variants. Analysis also noted anti-competition behavior in some builds and code traits associated with the dvrhelper Mirai lineage. Its string handling differs from earlier Mirai samples by using a custom decryption routine rather than the conventional XOR scheme commonly seen in older variants.
Mukashi is part of the broader post-Mirai ecosystem in which leaked Mirai source code enabled rapid creation of specialized descendants focused on newly disclosed vulnerabilities and poorly secured embedded Linux devices. Its observed targeting of Zyxel NAS platforms illustrates the continued convergence of IoT botnet activity and attacks on small-office and edge infrastructure, where exposed management services, default credentials, and delayed patching create favorable conditions for botnet recruitment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A preauthentication command injection vulnerability (CVE-2020-9054), which resides in a “web login.cgi” program used by the Zyxel devices, is potentially allowing attackers to perform remote code execution via command injection. | Mukashi, a new variant of Mirai, uses brute-force attacks to log into Zyxel NAS, UTM, ATP, and VPN firewall products to take control of the devices and add them to a network of infected bots that can be used to carry out Distributed Denial of Service (DDoS) attacks.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
this threat actor attempted to download a shell script to the tmp directory, execute the downloaded script, and remove the evidence on a vulnerable device.
Mirai managed to keep 200,000 – 300,000 enslaved devices and peaked at an unbelievable 600,000... FBI special agents compared Mirai’s 1+ Tbps (1,000 Gbps)... The first Mirai incident was reported after the 18th Sep 2016 attack against popular Minecraft servers hosted on French service OVH.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai variant targeting Zyxel devices via brute force and exploitation, enrolling compromised devices into a DDoS botnet.
Named as another Mirai variant seen in recent months.
A new Mirai variant targeting vulnerable Zyxel NAS devices via CVE-2020-9054. It scans random hosts on TCP/23, brute-forces default credentials, reports successful logins to its C2, receives commands, and launches DDoS attacks including UDP, TCP, HTTP, and bypass variants. It also enforces single-instance execution and in some builds can kill competing processes.
Mirai variant specifically noted for targeting Zyxel NAS devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.