Mirai - Daily Threat Report

Sunday, August 23, 2026

By Yazoul AI · automated

Daily Summary

Mirai activity rose to 100 new samples on 2026-08-23, a 17% increase over the 7-day average of 86, continuing a gradual upward trend. Sample volume remains well below outbreak thresholds, but the sustained climb across the last three days warrants attention. No new C2 servers were registered today, and the distribution of target architectures remained largely consistent with recent patterns.

New Samples Detected

The architecture spread today mirrors the broader Mirai ecosystem, with x86 and ARM variants dominating at 61 and 4 samples respectively, followed by smaller counts for MIPS, m68k, and PowerPC builds. The notable shift is the uptick in .elf samples, which now represent 61% of today’s haul versus 55% over the previous 7-day average. This suggests attackers are consolidating on a single generic binary format, likely to streamline deployment across heterogeneous IoT fleets rather than tailoring per-device builds.

The presence of four .mipsrouter and two .spc samples indicates continued targeting of legacy router firmware and SuperH-based devices, both of which remain poorly patched in many regional ISP deployments. The absence of any Android or BLX variants suggests the campaign is purely focused on Linux-based embedded systems today.

IOC Highlights

All 100 samples were logged as new IOCs, a clean sweep with no repeat hashes from the prior week. This is a meaningful signal: the operator is rotating binaries aggressively, likely recompiling with new obfuscation or embedding fresh XOR keys per build to evade hash-based detections. Analysts should treat file hashes as ephemeral indicators and pivot to behavioral detections based on connection attempts and process injection patterns.

Security Analysis

The rising volume paired with zero new C2 infrastructure points to an operator scaling up using existing command-and-control assets, a pattern consistent with the resurgence of Mirai variants like V3G4 or the derivative “Mirai-Scanner” campaigns observed in mid-2026. The consolidation toward .elf binaries across heterogeneous architectures is the more telling detail: it signals a maturity in the operator’s tooling, where a single compiled artifact is now portable enough to run unmodified across most targets.

Defensive teams should prioritize network-level detection of outbound connections from IoT segments to known Mirai C2 ports (typically 23, 2323, and 37215) rather than relying on static file signatures. Given the rapid hash rotation, implementing a honeypot that emulates Telnet and SSH services on common weak credentials (root/admin, admin/1234) will surface the scanning behavior earlier than signature matching, allowing preemptive blocking of command-and-control handshakes before device compromise.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Mirai Reports

Recent Malware Reports