Mirai - Daily Threat Report

Sunday, July 5, 2026

Daily Summary

Today’s Mirai sample count reached 100, a 17% increase above the 7-day average of 86. While this is a moderate uptick rather than a major surge, the distribution of new file types shows a broadening of architectures compared to recent prior days, warranting attention from network defenders monitoring diverse IoT environments.

New Samples Detected

The sample set shows notable architectural variety. The standard .elf format dominates with 75 samples, but the appearance of .mips (5), .mipsel (1), .sh4 (1), .armv5l (1), and .armv6l (1) suggests active targeting of less common IoT hardware. The presence of .sh scripts (3) and the unusual .ghost variant (3) indicates a possible shift toward multi-stage infection chains that deploy initial shell-based payloads before dropping architecture-specific binaries. The .ghost extension, not seen in typical Mirai activity, may represent a rebranded variant or a targeted build for a specific exploit kit.

New IOCs

All 100 new samples are listed as new IOCs today. While no C2 infrastructure changes were detected, the volume of unique malware binaries creates significant noise for signature-based detection systems. Defenders should prioritize behavioral detection rules for outbound connection attempts on ports commonly associated with Mirai C2 communication (e.g., 23, 2323, 48101), rather than relying solely on file hashes.

Security Analysis

The concurrent presence of .sh, .ghost, and varied architecture-specific ELF files suggests the threat actors are testing or refining a multi-platform propagation method, likely via a modular loader. This mirrors patterns seen in the “Mirai Okiru” variant but with an expanded architecture footprint. Notably, the absence of any new C2 servers implies existing infrastructure is being reused, which lowers the barrier for defenders to track command traffic via historical IOC feeds.

Actionable Recommendation: Deploy network signatures to detect .elf downloads to uncommon directories (e.g., /tmp, /var/tmp) across all monitored IoT segments. Combine this with outbound connection monitoring to known Mirai C2 ports, as the reused infrastructure provides a consistent detection surface despite evolving malware binaries.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Mirai Reports

Recent Malware Reports