Mirai - Daily Threat Report

Sunday, October 4, 2026

By Yazoul AI · automated

Daily Summary

Mirai activity surged to 100 new samples on 2026-10-04, a 250% increase over the 7-day average of 29. This is the largest single-day volume in the trailing week and represents a clear break from the baseline. No new C2 servers were registered, and 100 new IOCs were logged, indicating the spike is sample-driven rather than infrastructure-driven.

New Samples Detected

The sample mix is dominated by ELF binaries (50 of 100), but the more telling signal is the long tail of architecture-specific artifacts. Alongside x86 (4) and MIPS (4), we see dedicated builds for ARM (3), ARM6 (3), ARM7 (2), ARM5 (2), PowerPC (3), and the unusual .mpsl extension (3). This breadth suggests a single build pipeline cross-compiling for a wide device matrix, consistent with botnet tooling that targets routers, DVRs, and IP cameras rather than a one-off variant. The presence of five distinct ARM sub-architectures is notable: it implies the operators are hedging against unknown target hardware or are casting a wide net across embedded fleets.

Distribution Methods

With no new C2 servers and no geographic data to work with, distribution appears to rely on existing infrastructure. The absence of fresh C2 combined with a tripling of samples is the signature of a staging or repackaging wave: operators are preparing payloads for future deployment rather than activating new command channels. This is a common precursor pattern before a scanning or exploitation push.

IOC Highlights

All 100 IOCs are new today, which is high relative to the sample count. This ratio (1:1 sample-to-IOC) suggests each binary carries distinct embedded indicators, likely hardcoded hosts, keys, or build metadata. No new C2 domains or IPs were added to the tracker, so these IOCs are presumably host-level or binary-level artifacts.

7-Day Trend

Today’s count of 100 is a 245% deviation above the 7-day average of 29, well past the 25% threshold that warrants attention. This is not drift; it is a step change. Whether it sustains or reverts over the next 48 hours will determine if this is a release event or an anomaly.

Security Analysis

The combination of a large sample surge, zero new C2, and unusually broad architecture coverage points to a build-and-stage phase rather than an active campaign. This mirrors the pattern seen in prior Mirai derivatives ahead of coordinated exploitation waves, where operators front-load cross-compiled binaries and activate C2 only once targets are enumerated. Defensively, the low value of static C2 blocklists here is the key insight: with no new infrastructure to block, detection must shift to behavioral signals. Prioritize network egress monitoring for embedded devices attempting outbound connections on non-standard ports, and audit IoT fleets for the ELF families matching today’s architecture footprint. Treat this as a 48-hour watch window.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) • ThreatFox (abuse.ch) • URLhaus (abuse.ch)

More Mirai Reports

Recent Malware Reports