Researchers reported renewed activity from the Mirai-derived Sora malware and linked its development to the same actor behind the Owari IoT botnet. Symantec and NewSky Security said newer Sora samples were built with Aboriginal Linux, letting operators compile binaries for many processor architectures and even target Android devices. The malware was observed attempting broad infections after gaining access through guessed SSH passwords, while overall Mirai activity was said to be rising as unpatched and outdated IoT devices remained exposed.
NewSky Security identified an actor known as Wicked as tied to both Sora and Owari through forum monitoring, honeypots, and infrastructure analysis. In an interview, Wicked claimed Sora had been abandoned while Owari was still being developed, shifting beyond default-credential attacks to exploit-based propagation, including abuse of Huawei flaw CVE-2017-17215. The actor also described using a Telnet honeypot to study rival malware and build botkiller features, while monetizing access by renting botnet capacity to DDoS-for-hire stresser services.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
Symantec said an improved Sora variant compiled with Aboriginal Linux had been active since July 2018. The malware attempted SSH password guessing and then downloaded multiple binaries until one matched the victim device architecture.
Ankit Anubhav of NewSky Security said detections of Sora had been steadily increasing since June 2018. This indicated renewed activity around the Mirai-derived malware family.
During the April 2018 interview, Wicked said he had abandoned SORA and would continue development on OWARI instead. He also said multiple unnamed individuals besides himself had access to SORA servers.
NewSky Security published an interview in which Wicked claimed he and an associate authored the SORA and OWARI botnets. The company said its monitoring and honeypot analysis linked Wicked to the botnets' infrastructure.
By August 2018, researchers said Mirai activity had been increasing throughout the year, with Sora among the variants resurging. Troy Mursch attributed continued infections to outdated and unpatched IoT devices that become vulnerable again after reboot.
Researchers said the Sora Mirai variant was first spotted at the start of 2018. Early versions were described as unremarkable compared with other Mirai variants.
Symantec published findings on an improved Sora variant built with Aboriginal Linux, enabling broad multi-architecture targeting. Researchers said the malware could successfully execute on Android and Debian, expanding beyond platforms Mirai had not previously infected successfully.
NewSky Security said its honeypots observed an evolved OWARI variant using the Huawei CVE-2017-17215 exploit. Wicked confirmed the exploit scanner had been added only recently as operators shifted beyond default-password attacks.
In NewSky Security's April 2018 interview, Wicked said he had started the OWARI botnet about six months earlier. He described OWARI as an actively developed successor while SORA was more recent.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceblog.newskysecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.