Mirai - Daily Threat Report

Sunday, July 12, 2026

Daily Summary

Mirai sample submissions reached 100 on 2026-07-12, a 17% increase over the 7-day average of 86. This marks a sustained rising trend, though the volume does not constitute a major outbreak. No new C2 servers were identified today, suggesting existing infrastructure remains active.

New Samples Detected

The sample set shows strong architectural diversity, with 43 standard ELF binaries leading, followed by 5 samples each for PPC, ARM6, MIPS, and MPSL architectures. This distribution mirrors typical Mirai targeting of IoT devices across multiple CPU types. Notably, x86_64 and x86 samples account for only 8 combined submissions, indicating a continued emphasis on embedded systems rather than x86 servers. The absence of ARM5 or SPARC variants, which occasionally appear in regional campaigns, suggests no shift toward legacy or niche hardware today.

7-Day Trend

The 17% rise above the 7-day average, while notable, remains below the 25% threshold that would indicate a major surge. However, the consistent upward trajectory over recent days warrants monitoring. If this pace holds, tomorrow’s count could exceed 110 samples, which would mark a 28% increase and trigger elevated alerting.

IOC Highlights

All 100 new IOCs were associated with Mirai payload hashes, with no new C2 domains or IPs recorded. This pattern typically indicates active recompilation of existing malware variants rather than infrastructure expansion. Analysts should prioritize monitoring for reused C2 addresses from prior weeks, as the rise in samples may correlate with a fresh campaign using known command channels.

Security Analysis

The absence of new C2 servers alongside a 17% increase in samples suggests either a recycling campaign using pre-existing infrastructure or a single actor distributing variants of the same build. This differs from typical Mirai surges that accompany new C2 deployments. For SOC teams, prioritize blocking outbound connections to known Mirai C2 IPs from the past 30 days, as the infrastructure may see renewed use within 48 hours. Also, verify that IoT device hardening patches for default credentials remain enforced, as this sample spike likely targets unpatched embedded systems.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Mirai Reports

Recent Malware Reports