Mozi

First seen
2019-09-01 00:00:00
Malware type
botnet, ddos
Family
Malware family
Last IoC activity
2026-07-22 04:20:34
Profile updated
2026-07-07 14:25:05

Targeted industries: technology-and-telecommunications

Context

Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.

Detection coverage

  • 1 YARA rules

Detection rules

  • ESET_Mozi_Killswitch (yara-rule)

Reports & references

  • blog.netlab.360.com — P2P Botnets Review Status Continuous Monitoring (report)
  • CrowdStrike — Linux Targeted Malware Increased By 35 Percent In 2021 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Mozi (report)
  • blog.netlab.360.com — The Mostly Dead Mozi And Its Lingering Bots (report)
  • cloudsek.com — Mozi Resurfaces As Androxgh0St Botnet Unraveling The Latest Exploitation Wave (report)
  • Microsoft — How To Proactively Defend Against Mozi Iot Botnet (report)
  • nozominetworks.com — How Iot Botnets Evade Detection And Analysis (report)
  • go.recordedfuture.com — Cta 2021 1112 (report)
  • blog.centurylink.com — New Mozi Malware Family Quietly Amasses Iot Bots (report)
  • elastic.co — Collecting And Operationalizing Threat Data From The Mozi Botnet (report)
  • blog.netlab.360.com — Mozi Another Botnet Using Dht (report)
  • nozominetworks.com — Overcoming The Challenges Of Detecting P2P Botnets On Your Network (report)
  • youtube.com — Watch (report)
  • cujo.com — Upx Anti Unpacking Techniques In Iot Malware (report)

External references