Mirai
Overview
Executive Summary
Mirai is arguably the most infamous Internet of Things (IoT) Botnet and Worm in cybersecurity history. Discovered in 2016, Mirai is designed to scan the internet for vulnerable Linux-based IoT devices (such as IP cameras, home routers, and DVRs), compromise them using default credentials, and enlist them into a massive botnet capable of launching unprecedented Distributed Denial-of-Service (DDoS) attacks.Propagation and Exploitation Mechanics
The source code for Mirai was leaked online in 2016, leading to the creation of countless variants. However, the core mechanics remain consistent:- Aggressive Scanning: Infected devices continuously and aggressively scan the internet for other devices listening on Telnet (Port 23) or SSH (Port 22).
- Brute-Force Infection: When an open port is found, Mirai attempts to log in using a hardcoded list of over 60 common default usernames and passwords (e.g., `admin:admin`, `root:12345`). If successful, it loads the Mirai payload into the device's volatile memory (RAM).
- Botnet Command and Control: Once infected, the device connects to a centralized C2 server, awaiting instructions to launch massive volumetric DDoS attacks (such as UDP floods, SYN floods, or HTTP GET floods) against specified targets.
Threat Impact
A Mirai infection on a local network can severely degrade internet bandwidth due to its aggressive outbound scanning. Globally, the Mirai botnet has been responsible for some of the largest DDoS attacks on record, taking down major DNS providers, web hosts, and gaming networks, causing millions of dollars in economic damage.Remediation and Defense
- Reboot to Clear (Temporary): Because Mirai typically resides in volatile RAM, simply rebooting the infected IoT device will clear the infection. However, if the device remains connected to the internet with the same default credentials, it will be re-infected by the botnet within minutes.
- Credential Management: The only permanent fix is to change the default administrative passwords on all IoT devices immediately upon installation.
- Network Segmentation and Hardening: Never expose IoT administrative interfaces (Telnet, SSH, web GUIs) directly to the public internet. Place IoT devices on an isolated network segment (VLAN) to prevent them from communicating with or scanning the corporate LAN.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1110.001 T1498.001 T1059.004
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1059.004: Restrict execution of scripting languages such as PowerShell, VBScript, or Python to authorized administrators. Enforce Script Block Logging.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_MIRAI {
meta:
description = "Detects Mirai (advanced_threat)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "mirai" ascii wide nocase
$s2 = "linux.mirai" ascii wide nocase
$s3 = "worm.mirai" ascii wide nocase
$s4 = "botnet.mirai" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Mirai Activity
id: c631dac97d3f6112e92c51af79b3ed4a
status: experimental
description: Detects generic indicators of the mirai malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*mirai*"
- "*linux.mirai*"
- "*worm.mirai*"
- "*botnet.mirai*"
condition: selection
level: mediumReferences & External Analysis
- Search "mirai" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Mirai Advanced_Threat from Windows?
Manual removal of Mirai is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Mirai a virus or a Advanced_Threat?
Mirai is classified as a Advanced_Threat. Unlike traditional viruses that infect files, modern malware like Mirai typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Mirai infection?
Symptoms of Mirai can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: advanced_threat)
Explore other malware families in the same category:
Protect Your Network Against Advanced_Threats
Want to prevent Mirai and similar threats from compromising your organization? Read our comprehensive defensive guide: Suspect an Infection? What to do.
Machine-readable
Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/mirai.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.