Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Mirai IZ1H9 Botnet: Linux Server Threat Analysis

Palo Alto Networks
07/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


which exploits vulnerabilities in Linux-based servers and networking devices. The variant targets devices running Linux and uses vulnerabilities like Tenda G103 command injection, lblink command injection, dcn dcbi-netlog.lab remote code execution, and zyzexel remote code execution. Once compromised, these devices can be controlled by attackers and used for distributed denial-of-service attacks. Palo Alto Network's next generation firewall offers protection against this variant through cloud-delivered security services, including IoT security, advanced threat protection, wildfire, and advanced URL filtering. Unit 42 researchers have observed multiple campaigns using the IZ1H9 variant since November 2021, suggesting the work of a single threat actor based on similarities in malware and infrastructure. The variant connects to a hard-coded command and control, or C2, address and employs an encrypted string table for configuration. It leverages default login credentials for SSH and telnet channels and exploits remote code execution vulnerabilities for HTTP channel access. Applying patches and updates is crucial to mitigate the risk posed by this variant. Palo Alto Networks provides comprehensive protection to its customers against the Mirai IZ1H9 variant.

TL;DR

  • Unit 42 discovered the IZ1H9 Mirai variant exploiting vulnerabilities in Linux servers and networking devices from vendors including Tenda, lblink, DCN, and Zyxel.
  • Compromised devices are recruited into a botnet for DDoS attacks, with the malware using hardcoded C2 addresses and encrypted configuration tables.
  • Palo Alto Networks offers protection through cloud-delivered services including IoT security, advanced threat protection, WildFire, and URL filtering.

Summary

This threat briefing from Unit 42 examines the IZ1H9 variant of the Mirai botnet, first discovered in April and actively targeting Linux-based servers and networking devices since November 2021. The variant exploits multiple vulnerabilities including command injection flaws in Tenda G103 and lblink devices, as well as remote code execution vulnerabilities in DCN and Zyxel equipment. Once compromised, devices are recruited into a botnet capable of launching distributed denial-of-service attacks. The malware connects to hardcoded command and control infrastructure, uses encrypted configuration tables, and spreads through default SSH and telnet credentials alongside HTTP-based exploitation. Palo Alto Networks positions its next-generation firewall with cloud-delivered security services—including IoT security, advanced threat protection, WildFire, and advanced URL filtering—as comprehensive protection against this threat. The briefing emphasizes that consistent campaign patterns suggest a single threat actor behind IZ1H9 operations, and recommends patching as the primary mitigation strategy.

Chapters

0:00 - IZ1H9 Variant Discovery
0:15 - Targeted Vulnerabilities
0:44 - Protection Solutions
1:04 - Threat Actor Analysis

Key Quotes

0:00 "On April 10th, researchers at Unit 42 discovered a new variant of the Mirai botnet named IZ1H9, which exploits vulnerabilities in Linux-based servers and networking devices."
1:04 "Unit 42 researchers have observed multiple campaigns using the IZ1H9 variant since November 2021, suggesting the work of a single threat actor based on similarities in malware and infrastructure."
1:29 "Applying patches and updates is crucial to mitigate the risk posed by this variant."

FAQ

What devices are targeted by the Mirai IZ1H9 variant?

The IZ1H9 variant targets Linux-based servers and networking devices, specifically exploiting vulnerabilities in Tenda G103, lblink, DCN dcbi-netlog, and Zyxel equipment through command injection and remote code execution flaws.

How can organizations protect against this Mirai variant?

Organizations should apply patches and updates to vulnerable devices, change default login credentials for SSH and telnet, and deploy security solutions with IoT protection and advanced threat detection capabilities.


Categories:
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • IoT Security
  • Network Security
  • Technical Deep Dive
  • Mirai botnet
  • IZ1H9 variant
  • Linux security
  • IoT vulnerabilities
  • DDoS attacks
  • Command injection
  • Remote code execution
  • Threat intelligence
  • Network device security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Mirai IZ1H9 Botnet: Linux Server Threat Analysis

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                      https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/03/2026
                      01:00 PM
                      09/03/2026
                      Verge.io: Can You Afford Your Next Storage Refresh?
                      https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version