Satori
- First seen
- 2017-11-27 00:00:00
- Malware type
- worm, botnet
- Family
- Malware family
- Last IoC activity
- 2026-06-26 08:55:50
- Profile updated
- 2026-07-07 14:29:31
Context
Satori is a variation of elf.mirai which was first detected around 2017-11-27 by 360 Netlab. It uses exploit to exhibit worm-like behaviour to spread over ports 37215 and 52869 (CVE-2014-8361).
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2014-8361 (vulnerability)
Detection rules
- MALPEDIA_Elf_Satori_Auto (yara-rule)
Related threat objects
- Satori (infrastructure)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Satori (report)
- blog.netlab.360.com — Warning Satori A New Mirai Variant Is Spreading In Worm Style On Port 37215 And 52869 En (report)
- blog.radware.com — New Satori Botnet Variant Enslaves Thousands Dasan Wifi Routers (report)
- krebsonsecurity.com — Alleged Satori Iot Botnet Operator Sought Media Spotlight Got Indicted (report)
- arbornetworks.com — The Arc Of Satori (report)
- blog.netlab.360.com — Art Of Steal Satori Variant Is Robbing Eth Bitcoin By Replacing Wallet Address En (report)
- Palo Alto Unit 42 — Satori Mirai Botnet Variant Targeting Vantage Velocity Field Unit Rce Vulnerability (report)
- eweek.com — Collaborative Takedown Kills Iot Worm Satori (report)