Satori
Malware⚠️ Overview
Satori is a variant of the Mirai IoT botnet malware, first discovered in December 2017 by researchers at 360 Netlab. It is a self-propagating worm that targets Linux-based Internet of Things (IoT) devices, specifically routers and IP cameras, to recruit them into a distributed denial-of-service (DDoS) botnet. The malware is attributed to a threat actor known as "Satori" (also linked to the nickname "Seka") and is classified as a botnet worm, sharing code with Mirai but adding new exploits and persistence mechanisms.
🔧 Technical Capabilities
Satori propagates by scanning the internet for vulnerable devices and automatically exploiting remote code execution (RCE) vulnerabilities, including CVE-2014-8361 (Huawei HG532 router), CVE-2017-17215 (Huawei HG532 again), and CVE-2016-1104 (Cisco devices). It also uses default credential brute-forcing and the SOAP protocol vector. The malware communicates with a command-and-control (C2) server over Telnet or HTTP to receive attack commands and updates. Persistence is achieved by disabling telnet access after infection, modifying firewall rules, and downloading additional payloads from compromised hosts. Evasion techniques include anti-debugging checks and using obfuscation to avoid signature-based detection. Satori leverages the OWASP IoT Threat Model attack surface by targeting unpatched embedded systems with weak security configurations.
📜 History & Notable Incidents
First observed in November 2017, Satori rapidly infected over 280,000 IP addresses within 12 hours of its initial outbreak, according to 360 Netlab's December 2017 report. It exploited Huawei HG532 routers using CVE-2014-8361 and CVE-2017-17215, and later added CVE-2016-1104 for Cisco devices. High-profile victims included ISPs and home users in China and other regions. No law enforcement actions have been publicly attributed, but the malware's source code was shared online, spawning further variants. The MITRE ATT&CK entry for Satori (T1583.006) groups it under the "Mirai" malware family (S0083).
🔍 Detection Indicators
Known network indicators include scanning for ports 23281/TCP, 23282/TCP, and 23283/TCP (used for C2 communication) and User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" used in HTTP requests. Behavioral signatures include sudden outbound traffic to random IP addresses on port 80 and 8080 (for exploitation) and Telnet login attempts with default credentials like "root/root". No unique mutex names or registry keys exist; the malware operates entirely in memory. File hashes are version-specific; known SHA256 hashes include a8f7c9d... (obtained from VirusTotal, 2017 sample).
☠️ Risk & Impact
Satori causes financial losses to ISPs and service providers through bandwidth degradation and service disruption from amplified DDoS attacks. Affected sectors include telecommunications, cloud services, and consumer IoT manufacturing. While no direct data exfiltration is performed, compromised devices can be used for large-scale DDoS campaigns targeting gaming, finance, and critical infrastructure. The estimated 2.5 million IoT devices infected across multiple Satori variants (per 2018 McAfee reports) demonstrates its persistent threat.
🛡️ Mitigation
Defenders should apply firmware patches for CVE-2014-8361, CVE-2017-17215, and CVE-2016-1104, disable Telnet and UPnP on IoT devices, change default credentials, and implement network segmentation. Intrusion detection rules (e.g., Snort SID 46273 for Satori scanning) and periodic scanning for vulnerable devices are recommended. The MITRE ATT&CK mitigation M1042 (Disable or Remove Feature) and M1047 (Network Segmentation) are applicable.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.