logo

Who killed Mozi? Finally putting the IoT zombie botnet in its grave

ID: de839626-7d57-5907-a8ea-63afc670a0d4

STIX ID: report--de839626-7d57-5907-a8ea-63afc670a0d4

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2023-11-01

Date Updated: 2026-05-01

...
...

ESET Research describes how a signed control payload (a kill switch) was used in August–September 2023 to disable much of the Mozi IoT botnet’s functionality by killing processes, disabling services, replacing binaries, altering device configuration, and blocking ports; the report includes two control payload variants, associated SHA‑1 file hashes, a hosting IP, MITRE ATT&CK mappings, and a hypothesis that the takedown was performed either by the botnet authors or by Chinese law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.