The Mozi botnet infected routers, gateways, DVRs, NVRs, and other IoT devices through weak Telnet credentials and known vulnerabilities, then used a DHT-based peer-to-peer architecture to spread malware and maintain command-and-control without relying on centralized servers. Researchers said Mozi reused some Gafgyt code but stood apart for its decentralized design, XOR obfuscation, and ECDSA384 signature checks that protected botnet configuration integrity. Infected devices could be directed to launch DDoS attacks, download and execute payloads, collect system information, and run arbitrary commands, while compromised nodes also hosted malware for further propagation over HTTP on random ports.
Later analysis showed Mozi evolving beyond basic botnet activity by adding persistence mechanisms on Netgear, Huawei, and ZTE gateways, including startup-script changes, credential modification, service disabling, and port blocking. Microsoft reported the malware could also support man-in-the-middle activity such as DNS spoofing and HTTP session hijacking, raising the risk that compromised edge devices could become entry points into enterprise IT and OT networks. Netlab and other researchers found that even after action against its operators and a slowdown in updates, Mozi’s decentralized network continued to sustain lingering infections, while newer variants added Mirai-style C2 logic for DDoS coordination, UPnP port mapping, and additional node roles tied to mining activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
360 Netlab included Mozi in an overview of actively tracked P2P botnets and described it as a DHT-based botnet that began with DDoS-for-profit activity and later added mining. In the sampled period, Mozi ranked behind Pink and Hajime in observed size.
Elastic Security Labs published a case study on collecting and operationalizing Mozi intelligence from open sources, including ThreatFox and Malware Bazaar. The analysis described repairing Mozi's corrupted UPX header, extracting DHT and firewall indicators, and visualizing globally distributed activity across at least 24 countries.
QiAnxin and Sangfor published reports describing WorkMiner as a mining trojan that spreads through weak SSH passwords and exhibits P2P behavior. Later analysis linked WorkMiner to the Mozi ecosystem as the Mozi_ssh node type.
360 Netlab reported newly identified Mozi node types, including Mozi_ftp and Mozi_ssh, both mining trojans that propagate via weak credentials while participating in the same Mozi P2P network. The report said shared XOR keys and configuration-signing public keys indicated they likely came from the same author as Mozi_bot.
360 Netlab stated that Mozi's authors had been taken into custody by law enforcement agencies and that it had provided technical assistance during the action. The same report noted that lingering infected devices could continue spreading because of Mozi's decentralized P2P design.
Microsoft researchers reported that Mozi had evolved persistence techniques for Netgear, Huawei, and ZTE gateways and added man-in-the-middle capabilities such as DNS spoofing and HTTP hijacking. The report highlighted the risk that compromised gateways could provide initial access into enterprise IT and OT environments.
Backend statistics observed in September 2020 showed reporting entries beyond standard Mozi_bot nodes. This later supported identification of additional Mozi roles such as Mozi_ftp and Mozi_ssh within the same P2P ecosystem.
360 Netlab published research describing Mozi as a DHT-based peer-to-peer IoT botnet that spreads via weak Telnet credentials and multiple known device vulnerabilities. The report documented its propagation methods, configuration system, and botnet capabilities including DDoS and payload execution.
360 Netlab identified a suspicious malware sample on September 3, 2019 that many VirusTotal engines initially flagged as Gafgyt. The researchers later determined it was a distinct botnet they named Mozi.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
blog.netlab.360.com
Open sourceelastic.co
Open sourceblog.netlab.360.com
Open sourcemicrosoft.com
Open sourcecujo.com
Open sourceblog.netlab.360.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.