Researchers and later federal prosecutors tied the Mirai-derived Satori/Masuta botnet activity to the alias Nexus Zeta, identified in court reporting as Kenneth Currin Schuchman. Security reporting said Satori rapidly infected hundreds of thousands of IoT devices by exploiting router flaws rather than relying only on default credentials, including CVE-2017-17215 in Huawei gateways, CVE-2014-8361 in Realtek UPNP SOAP interfaces, and a D-Link HNAP injection issue used by the PureMasuta branch. NewSky linked Masuta and PureMasuta to the same operator through shared command-and-control infrastructure and leaked source code, while investigators said operational security mistakes connected the botnet’s online persona to a real-world suspect.
The malware family continued to evolve after initial disruption efforts. A successor dubbed Satori.Coin.Robber targeted exposed Claymore Miner management interfaces on port 3333 to redirect Ethereum mining rewards by changing pool and wallet settings, while still scanning for vulnerable devices on ports 37215 and 52869. Later technical analysis showed Satori broadened support for additional processor architectures, including superh and ARC, making it one of the first known ARC-targeting malware families and underscoring how Mirai-style botnets were shifting toward exploit-driven propagation, persistent command-and-control, and large-scale DDoS capability across insecure embedded devices.

Pull IOCs and campaign context straight into your stack.
19 events from the most recent confirmed update back to the earliest known activity.
A Pastebin dox published in February 2018 identified Nexus Zeta as Kenneth Currin Schuchman and linked him to the aliases Nexus Zeta and Caleb Wilson. The dox contributed to the public attribution of the botnet operator.
Netlab 360 reported that a successor Satori variant was targeting internet-exposed Claymore Miner instances, especially Windows-based hosts, to redirect mining rewards. The malware also continued exploiting CVE-2017-17215 and CVE-2014-8361 while using a new DNS-based C2 protocol.
The article states that Satori.Coin.Robber had already received its first 1 ETH payout on January 11 after hijacking Claymore Miner configurations. The malware replaced victims' wallet addresses and mining pool settings to steal Ethereum proceeds.
A successor variant named Satori.Coin.Robber began reestablishing botnet activity starting from 2018-01-08 10:42:06 GMT+8. It resumed scanning on ports 37215 and 52869 and added attacks against Claymore Miner on port 3333.
Between 2018-01-08 and 2018-01-12, multiple malware samples associated with Satori.Coin.Robber were captured. Analysis showed the variant shared code structure and scanning payloads with the original Satori.
Check Point published a report on December 29, 2017 linking the Satori control domain nexusiotsolutions-dot-net to the email address nexuszeta1337@gmail.com. The domain was used to synchronize Satori botnet activity.
Netlab360 published a report on December 5, 2017 stating that Satori was spreading rapidly to Huawei routers using two vulnerabilities, including a then-unknown zero-day. The report said about a quarter million infected devices were scanning for new victims.
In December, Qihoo 360 Netlab reported that Satori infected more than 280,000 IP addresses in a 12-hour period and had gained control over 500,000 to 700,000 IoT devices. The report highlighted the botnet's rapid growth.
Researchers discovered Satori in December 2017 as a Mirai-derived IoT malware family. Early variants propagated via a Huawei home gateway zero-day and a known Realtek UPNP SOAP command-execution flaw.
An account using the alias 9gigs_ProxyPipe contacted KrebsOnSecurity on November 28, 2017 about an allegedly dangerous IoT botnet. The same persona was later linked to the Nexus Zeta handle.
A later federal indictment alleged malware activity tied to Satori damaged computers between August and November 2017. The charges were connected to the alleged authorship and use of the botnet.
Mirai popularized large-scale IoT-driven DDoS attacks in late 2016. Its propagation and attack model became the basis for later Mirai-style botnets.
A D-Link HNAP flaw later weaponized by PureMasuta was originally identified in D-Link products in 2015. The flaw enabled authentication bypass and, through improper string handling, arbitrary command execution.
Federal authorities in Alaska indicted Kenneth Currin Schuchman on two Computer Fraud and Abuse Act counts tied to the alleged authorship and operation of the Satori botnet. The case connected Schuchman to the Nexus Zeta alias and the Mirai-derived botnet's activity.
NewSky Security released research identifying a second Masuta variant named PureMasuta that weaponized a D-Link HNAP vulnerability. Honeypot data showed PureMasuta-infected IP addresses had increased twelve-fold since September.
NewSky Security reported that the actor behind Satori, identified as Nexus Zeta, was also behind the Mirai variants Masuta and PureMasuta. The linkage was based on leaked Masuta source code and shared command-and-control infrastructure between Masuta and PureMasuta.
After the December 5 blog post, the security community moved quickly to sinkhole Satori command-and-control infrastructure. This temporarily halted the spread of the original botnet.
Check Point researchers first identified Okiku, also known as Satori, on November 23. The malware was a Mirai-derived IoT botnet variant.
The Mirai source code was publicly released, enabling other actors to build their own Mirai-derived botnets and add new features. This set the stage for later families such as Satori and Masuta.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
arbornetworks.com
Open sourcekrebsonsecurity.com
Open sourcethreatpost.com
Open sourceblog.netlab.360.com
Open sourceeweek.com
Open sourceblog.newskysecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.