Mirai-related botnets remained highly active as operators rapidly incorporated newly disclosed remote code execution flaws and weak-credential attacks against internet-facing IoT and network security devices. Palo Alto Networks Unit 42 reported an active campaign exploiting vulnerabilities including CVE-2021-27561, CVE-2021-27562, CVE-2021-22502, and CVE-2020-26919 across products such as SonicWall SSL-VPN, D-Link DNS-320, Yealink Device Management, Micro Focus Operation Bridge Reporter, Netis routers, and Netgear ProSAFE Plus devices. Fortinet likewise observed roughly 200 attacks per day in a three-week honeypot study, with nearly 4,000 of about 4,700 Telnet attacks tied to Mirai-related malware families and variants quickly adding exploits such as OptiLink GPON RCE, CVE-2021-1498, and CVE-2021-31755.
Successful compromises typically fetched shell scripts that installed multi-architecture Mirai binaries, and in some cases added SSH brute-force and scanning tools, attempted persistence, removed artifacts, and blocked management ports to retain control. Researchers said the broader botnet ecosystem also remained resilient beyond Mirai alone: Fortinet identified active variants including SORA, SYLVEON, Hajime, and MANGA, while earlier Netlab 360 analysis showed Hajime continuing to grow through a modular peer-to-peer architecture and propagation via TR-069 flaws and weak Telnet credentials. The combined reporting underscores that unpatched edge devices and default or weak passwords continued to fuel large-scale botnet expansion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Unit 42 says the attacks were still ongoing when the report was published on March 15, 2021. The campaign was actively exploiting vulnerabilities in devices from vendors including SonicWall, D-Link, Yealink, Micro Focus, Netis, and Netgear.
Unit 42 states that an exploit for CVE-2020-26919 was added to the malware samples on 2021-03-13. This further broadened the campaign's targeting of exposed devices.
Unit 42 reports that on 2021-03-03 the same malware samples were served from a third IP address with an added exploit for CVE-2021-22502. This showed the campaign rapidly expanding its exploit set.
Unit 42 says one IP involved in the campaign was updated on 2021-02-23 to serve a Mirai variant leveraging CVE-2021-27561 and CVE-2021-27562. The report notes these Yealink exploits were incorporated within hours of public disclosure.
Unit 42 reports that it first observed the Mirai-based campaign on 2021-02-16. The activity targeted internet-facing network security and IoT devices through multiple remote code execution vulnerabilities.
Netlab 360 says it captured a signed Hajime configuration file on 2017-08-29 that contained settings for x64 CPU support. The finding suggested either planned expansion beyond IoT architectures or possible signing-key compromise, with researchers favoring expansion.
Netlab 360 reports further Hajime updates on 2017-08-18, 2017-08-19, 2017-08-22, and 2017-09-04. The report characterizes these as patches to existing code rather than dramatic changes.
Netlab 360 identifies another Hajime update on 2017-08-12. Researchers linked this update with a rapid increase in active Hajime nodes.
Netlab 360 reports a Hajime update on 2017-08-06 and says bot numbers increased quickly after this and a later August update. The event reflects active maintenance of the botnet.
Netlab 360 says Hajime file updates resumed in August 2017 after the July lull. The renewed updates were associated with a quick increase in active bot numbers.
Netlab 360 reports that Hajime activity declined in the second half of July 2017 and that no botnet file updates occurred during that period. This lull preceded a renewed wave of updates and growth.
Netlab 360 states that Rapidity Networks first discovered the Hajime botnet in October 2016. This marks the earliest referenced public identification of Hajime in the provided sources.
FortiGuard Labs notes that Mirai source code was publicly released in late 2016, enabling many copycat IoT botnet variants to emerge. This release helped drive the later proliferation of Mirai-derived malware families.
FortiGuard Labs reports that the MANGA Mirai variant recently added exploits for OptiLink ONT1GEW GPON RCE, CVE-2021-1498, and CVE-2021-31755. The report also says MANGA targeted a broader set of vulnerabilities including CVE-2021-22986, CVE-2020-25506, CVE-2021-22502, CVE-2021-27561, CVE-2021-27562, and SonicWall VisualDoor.
FortiGuard Labs identifies SORA and SYLVEON among the Mirai variants actively observed in its honeypot data. It also notes recently updated SYLVEON binaries on a download server, indicating the variant was still being actively operated.
FortiGuard Labs reports that over a three-week observation period its telnet honeypot received nearly 4,700 connections and about 200 attacks per day on average, with nearly 4,000 attacks attributed to Mirai-related malware families. The data showed Mirai-derived botnets remained highly active.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.netlab.360.com
Open sourcesupport.f5.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.