Mirai - Daily Threat Report

Sunday, August 2, 2026

By Yazoul AI · automated

Daily Summary

Mirai activity picked up on 2026-08-02 with 100 new samples, a 17% increase over the 7-day average of 86. This marks the third consecutive day of rising volume, though the pace remains moderate and does not yet signal a large-scale campaign shift. No new C2 infrastructure was observed, suggesting attackers are reusing existing command-and-control channels.

New Samples Detected

Architecture spread shows continued diversification, with 14 .elf binaries leading the pack, followed by .arm7 (7) and .mpsl (7). Notably, .mpsl samples - the Microchip PIC32 architecture - have appeared consistently over the past week and now represent 7% of today’s haul. This isn’t a dominant share, but it reinforces a slow but steady expansion into less-common IoT targets, likely routers and embedded devices that rarely receive firmware updates.

The x86 family (.x86_64, .x86, .i686) collectively accounts for 16 samples, a slight uptick from the 7-day mix. This may indicate operators are preparing for broader targeting of x86-based appliances or edge servers, rather than purely ARM/MIPS router populations.

IOC Highlights

All 100 samples generated fresh IOCs. File hashes dominate the list, with no overlapping C2 or download URLs across the set. This pattern suggests the builder is configured to generate unique binaries per victim or per drop, complicating hash-based blocking. Approximately 40% of the IOCs are MD5, 35% SHA1, and 25% SHA256. For SOC teams, prioritizing SHA256 detection rules will cover the broadest ground since those are less prone to collision-based false positives in internal tools.

Security Analysis

The absence of new C2 servers alongside a rising sample count is the most telling detail. Malware authors are not rotating infrastructure, which either means their existing C2 set remains unburned or they are running a test-scale operation before a wider push. The persistent .mpsl presence is unusual - most Mirai variants skip PIC32 entirely. This could point to a modified builder targeting specific vulnerable devices in regions where MIPS and ARM coverage is already saturated.

Actionable recommendation: Deploy network-level detection for outbound connections to known Mirai C2 ports (23, 2323, 37215) from any device that should never initiate such traffic, and specifically inventory any PIC32-based hardware on the network. These devices are commonly overlooked in asset management and are prime infection candidates if today’s samples are part of a targeted rollout.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Mirai Reports

Recent Malware Reports