Mozi
- First seen
- 2019-09-01 00:00:00
- Malware type
- botnet, ddos
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:20:34
- Profile updated
- 2026-07-07 14:25:05
Targeted industries: technology-and-telecommunications
Context
Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.
Detection coverage
- 1 YARA rules
Detection rules
- ESET_Mozi_Killswitch (yara-rule)
Reports & references
- blog.netlab.360.com — P2P Botnets Review Status Continuous Monitoring (report)
- CrowdStrike — Linux Targeted Malware Increased By 35 Percent In 2021 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Mozi (report)
- blog.netlab.360.com — The Mostly Dead Mozi And Its Lingering Bots (report)
- cloudsek.com — Mozi Resurfaces As Androxgh0St Botnet Unraveling The Latest Exploitation Wave (report)
- Microsoft — How To Proactively Defend Against Mozi Iot Botnet (report)
- nozominetworks.com — How Iot Botnets Evade Detection And Analysis (report)
- go.recordedfuture.com — Cta 2021 1112 (report)
- blog.centurylink.com — New Mozi Malware Family Quietly Amasses Iot Bots (report)
- elastic.co — Collecting And Operationalizing Threat Data From The Mozi Botnet (report)
- blog.netlab.360.com — Mozi Another Botnet Using Dht (report)
- nozominetworks.com — Overcoming The Challenges Of Detecting P2P Botnets On Your Network (report)
- youtube.com — Watch (report)
- cujo.com — Upx Anti Unpacking Techniques In Iot Malware (report)