Mozi IoT Malware and Its Botnets: From Theory To Real-World Observations
Josh Sahota, Natalija Vlajic
Abstract
Josh Sahota, Natalija Vlajic
Abstract
Mozi IoT malware arrived on the Internet stage in late 2019, and since then has managed to infected over 1.5 million IoT devices, established numerous large-scale botnets, and generate more attack traffic in 2020 and 2021 than any of its IoT-malware counterparts. Even though Mozi code is a blend of three other infamous malware families (Mirai, Gafgyt, and IoTReaper), the main distinguishing feature of Mozi botnets -relative to those of its direct predecessors - is their P2P networking architecture. Notwithstanding Mozi’s significance and prevalence in the real world, there is very little mention of this IoT malware in academic research literature. This paper is one of the first attempts to bring the attention of the research community to the architecture and operation of Mozi and its botnets. The information provided in the paper is in part based on our own experimentation with live monitored instances of Mozi malware.
OpenAlex reports 11 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Mozi IoT malware arrived on the Internet stage in late 2019, and since then has managed to infected over 1.5 million IoT devices, established numerous large-scale botnets, and generate more attack traffic in 2020 and 2021 than any of its IoT-malware counterparts. Even though Mozi code is a blend of three other infamous malware families (Mirai, Gafgyt, and IoTReaper), the main distinguishing feature of Mozi botnets -relative to those of its direct predecessors - is their P2P networking architecture. Notwithstanding Mozi’s significance and prevalence in the real world, there is very little mention of this IoT malware in academic research literature. This paper is one of the first attempts to bring the attention of the research community to the architecture and operation of Mozi and its botnets. The information provided in the paper is in part based on our own experimentation with live monitored instances of Mozi malware.
Key concepts: Botnet, Malware, Computer security, Computer science, Internet of Things, World Wide Web, The Internet