Netskope Threat Labs

Mirai

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Mirai is one of the most famous botnets targeting exposed networking devices running Linux. Discovered in 2016, the malware targets a wide range of devices such as routers, cameras, and other IoT hardware, compromising them through default and weak credentials and conscripting them into distributed denial of service networks that launched record breaking attacks. Since its source code leak, the number of variants of this malware increased considerably, and the family's descendants still dominate IoT botnet activity.

First seen
January 2022
Last seen
October 2026
Alert Name
Android.Backdoor.Mirai
Android.Worm.Mirai
Application.Linux.HackTool.Mirai.3
Document-HTML.Worm.Mirai
Gen:Variant.Linux.Mirai.1
Gen:Variant.Linux.Mirai.2
Gen:Variant.Linux.Mirai.3
Gen:Variant.Linux.Mirai.4
Gen:Variant.Linux.Mirai.7
Gen:Variant.Trojan.Linux.Mirai.1