Mirai (ELF)
Aliases: Katana
- First seen
- 2016-08-01 00:00:00
- Malware type
- botnet, ddos, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:08:19
- Profile updated
- 2026-07-07 13:11:41
Targeted industries: energy-and-utilities technology-and-telecommunications retail-and-hospitality
Context
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.
Exploited vulnerabilities
- CVE-2020-10173 (vulnerability)
- CVE-2020-17496 (vulnerability)
- CVE-2020-5902 (vulnerability)
- CVE-2021-32305 (vulnerability)
- CVE-2021-44228 (vulnerability)
- CVE-2022-22954 (vulnerability)
- CVE-2022-22965 (vulnerability)
Related threat objects
- Mirai (infrastructure)
- katana (infrastructure)
Reports & references
- twitter.com — 1535417776290111489 (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- Palo Alto Unit 42 — Cve 2022 22954 Vmware Vulnerabilities (report)
- blog.netlab.360.com — Some Details Of The Ddos Attacks Targeting Ukraine And Russia In Recent Days (report)
- blog.netlab.360.com — Wo Men Kan Dao De Wu Ke Lan Bei Ddosgong Ji Xi Jie (report)
- uptycs.com — Discovery Of Simps Botnet Leads Ties To Keksec Group (report)
- uptycs.com — Mirai Code Re Use In Gafgyt (report)
- Palo Alto Unit 42 — Unit42 Multi Exploit Iotlinux Botnets Mirai Gafgyt Target Apache Struts Sonicwall (report)
- blackberry.com — Report Bb 2021 Threat Report (report)
- Palo Alto Unit 42 — Hoaxcalls Mirai Target Legacy Symantec Web Gateways (report)
- cujo.com — Mirai Gafgyt With New Ddos Modules Discovered (report)
- radware.com — Alert Realtek Sdk (report)
- Palo Alto Unit 42 — New Mirai Variant Adds 8 New Exploits Targets Additional Iot Devices (report)
- Palo Alto Unit 42 — Mirai Variant Echobot Resurfaces With 13 Previously Unexploited Vulnerabilities (report)
- blog.malwaremustdie.org — Mmd 0065 2021 Linuxmirai Fbot Re (report)
- researchcenter.paloaltonetworks.com — Unit42 Finds New Mirai Gafgyt Iotlinux Botnet Campaigns (report)
- zscaler.com — Threatlabz Analysis Log4Shell Cve 2021 44228 Exploit Attempts (report)
- medium.com — Logs Of Log4Shell Cve 2021 44228 Log4J Is Ubiquitous En 809064312039 (report)
- cadosecurity.com — Analysis Of Initial In The Wild Attacks Exploiting Log4Shell Log4J Cve 2021 44228 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Mirai (report)
- Palo Alto Unit 42 — New Mirai Variant Targets Enterprise Wireless Presentation Display Systems (report)
- CERT-UA — 37139 (report)