Mirai - Daily Threat Report

Sunday, August 16, 2026

By Yazoul AI · automated

Daily Summary

Mirai activity on 2026-08-16 saw 100 new samples, a 17% increase over the 7-day average of 86, confirming a rising trend. The sample volume is climbing steadily, though today’s count does not represent an outlier spike. Notably, we detected zero new C2 servers, suggesting attackers are reusing existing infrastructure rather than expanding their footprint.

New Samples Detected

The sample distribution shows a heavy concentration in ELF binaries (65 of 100 samples), which is consistent with Mirai’s typical targeting of Linux-based IoT devices. However, the secondary file types reveal a modest but meaningful shift toward alternate architectures: .sh scripts (5), .arm5 (4), and a spread across .x86_64, .i586, .mpsl, .arm, .mips, .ppc, and .sh4 at 2 samples each.

The presence of 5 shell scripts is worth attention. These are not standard for Mirai payloads, which typically ship as compiled binaries. A 5% share of script-based variants suggests either an evolving loader mechanism or an attempt to obfuscate initial execution. The .arm5 and .sh4 entries indicate continued targeting of older, less-patched embedded devices, which aligns with Mirai’s established preference for legacy architectures.

7-Day Trend

While today’s 17% uptick does not trigger the 25% deviation threshold for a separate trend section, the cumulative direction is notable. Over the past week, volume has remained consistently above the historical baseline, and today’s 100-sample mark is the highest single-day count in that window. The absence of new C2 infrastructure alongside rising sample counts points to campaign consolidation rather than fresh operations.

IOC Highlights

All 100 samples were flagged as new IOCs, but the intelligence value lies in the structure rather than the volume alone. The ELF binaries are likely repackaged or recompiled variants of known Mirai strains, which means hashes alone will not catch everything. The shell scripts, in particular, warrant immediate hash extraction and distribution across EDR and network detection rules, as they may represent a novel entry vector for targeted environments.

Security Analysis

The combination of rising sample volume with zero new C2 infrastructure suggests a shift toward reuse and adaptation of proven Mirai campaigns rather than greenfield development. This pattern resembles the strategy seen in the 2023-2024 period where operators iterated on the same codebase, tweaking compilation flags and architecture targets to evade signature-based detection. The 5% shell script share is an outlier worth investigating further, as script-based deployment can bypass traditional binary allowlisting controls on IoT gateways.

Defensive recommendation: prioritize blocking outbound connections from IoT segments to known Mirai C2 IP ranges, even if those ranges are stale. Since operators are reusing existing infrastructure, routinely updating blocklists with historical C2 data will disrupt command and control with minimal effort. Additionally, ensure that .sh file execution is restricted to approved administrative paths on all writable partitions of embedded devices, as script-based Mirai variants exploit weak default execution permissions.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Mirai Reports

Recent Malware Reports