Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-27076: Tenda G103 command injection vulnerability ... This malicious traffic was first detected as a part of the IZ1H9 campaign on April 10, 2023. The command injection vulnerability is due to the failure to sanitize the value of the language parameter in the cgi-bin/luci interface of Tenda G103. | On April 10, Unit 42 researchers observed a Mirai variant called IZ1H9, which used several vulnerabilities to spread itself.
CVE-2023-26802: DCN DCBI-Netlog-LAB remote code execution vulnerability ... The exploit was detected on April 10, 2023. The exploit works due to the Digital China Network DCBI-Netlog-LAB nsg_masq.cgi component failing to adequately sanitize the user-supplied input data, which leads to remote command execution. | On April 10, Unit 42 researchers observed a Mirai variant called IZ1H9, which used several vulnerabilities to spread itself.
CVE-2023-26801: LB-Link command injection vulnerability ... We captured this exploit traffic on April 10, 2023. The exploit targets a command injection vulnerability in the LB-Link wireless router’s /goform/set_LimitClinet_cfg component, which does not successfully sanitize the user input in the time1, time2 and mac parameters. | On April 10, Unit 42 researchers observed a Mirai variant called IZ1H9, which used several vulnerabilities to spread itself.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
This threat group tried to download and execute a shell script downloader lb.sh... If executed, the shell script downloader would first delete logs to hide its tracks. Then the following bot clients would be downloaded and executed...
If executed, the shell script downloader would first delete logs to hide its tracks.
For SSH and telnet channels, IZ1H9 inherits the most significant feature from the original Mirai source code: a data section with embedded default login credentials for scanner and brute-force purposes.
The IZ1H9 variant uses a table key during the string decryption process: 0xBAADF00D ... For each encrypted character, the malware performs XOR decryption... The original Mirai and IZ1H9 also both encrypt their login credentials with a 1 byte XOR key.
Compromised devices can be fully controlled by attackers and become a part of the botnet. Those devices can be used to conduct further attacks, such as distributed denial-of-service (DDoS) attacks... the threat actor defines a set of attack methods... TCP SYN flooding, UDP flooding, HTTP flooding, DNS amplification.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IZ1H9 is a Mirai variant botnet targeting exposed Linux servers and networking/IoT devices. It spreads via brute forcing telnet/SSH credentials and by exploiting remote code execution and command injection flaws, then downloads architecture-specific bot clients, blocks remote recovery access by modifying iptables, connects to hard-coded C2 infrastructure, and enables multiple DDoS attack methods.
A Mirai variant that uses the same ThinkPHP RCE exploit as Miori and also spreads via Telnet with default credentials, infecting Linux/IoT devices for botnet activity and DDoS operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.