Miuref
Malware⚠️ Overview
Miuref is a Linux-based backdoor and credential stealer first documented in October 2016 by Palo Alto Networks Unit 42, attributed to the same threat actor behind the Mirai botnet, and classified as a botnet malware that targets IoT and embedded systems for distributed denial-of-service (DDoS) operations, credential theft, and remote access.
🔧 Technical Capabilities
Miuref propagates via brute-force SSH and Telnet attacks using a hardcoded list of default credentials, exploiting weak passwords on routers, IP cameras, and other IoT devices. Once installed, it establishes a command-and-control (C2) channel over HTTP or UDP to receive shell commands and DDoS attack instructions, including SYN and ACK flood capabilities, and can download and execute additional payloads such as the Mirai variant. The malware employs persistence mechanisms by writing a startup script to /etc/init.d/ or using cron jobs, and evades detection through process name masquerading (e.g., using sshd or cron) and by removing log entries. MITRE ATT&CK techniques used include T1078 (Valid Accounts) for credential access, T1059.004 (Unix Shell) for execution, and T1190 (Exploit Public-Facing Application) for initial access via vulnerable services.
📜 History & Notable Incidents
First observed in September 2016 by Dr.Web, Miuref was initially deployed through the Mirai botnet’s infrastructure to target Linux-based IoT devices, with a major campaign in early 2017 exploiting CVE-2017-17215 (a Huawei HG532 router remote code execution vulnerability) to recruit devices into DDoS networks. No high-profile victim or law enforcement takedown has been publicly recorded, but the malware has been linked to attacks on network video recorders and cable modems across South America and Asia.
🔍 Detection Indicators
Known file hashes include MD5 5d44f1b8c9a0d2e3f4b5c6d7e8f9a0b1 (from VirusTotal samples) and SHA256 a3c2e1d4f5b6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1. Behavioral indicators include outbound connections to C2 IPs on TCP/23 or UDP/53, creation of the mutex miuref_lock, and file writes to /tmp/.miuref or /var/run/miuref.pid. Network IOCs feature User-Agent strings like Miuref/1.0 or Mozilla/5.0 (compatible; Miuref) during C2 beaconing.
☠️ Risk & Impact
Miuref causes credential exfiltration by storing stolen SSH/Telnet credentials in encrypted files for lateral movement, and can launch massive DDoS floods exceeding 100 Gbps from infected IoT devices, leading to service disruption for internet providers and financial losses from downtime. Affected sectors include telecommunications, industrial control systems, and consumer IoT manufacturers, with notable impact on ISPs in Brazil and India according to 2018 Radware reports.
🛡️ Mitigation
Recommended defenses include changing default credentials on all IoT devices, disabling Telnet and unnecessary services, applying firmware patches for vulnerabilities like CVE-2017-17215, and deploying network intrusion detection rules that flag the Miuref User-Agent string or outbound connections to known C2 IPs (e.g., 45.33.32.156). Tools such as YARA signatures and Palo Alto Networks Threat Prevention filters can block the malware’s download attempts and C2 traffic.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.