Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Mirai IZ1H9 Botnet: Linux Server Threat Analysis

Palo Alto Networks
07/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


which exploits vulnerabilities in Linux-based servers and networking devices. The variant targets devices running Linux and uses vulnerabilities like Tenda G103 command injection, lblink command injection, dcn dcbi-netlog.lab remote code execution, and zyzexel remote code execution. Once compromised, these devices can be controlled by attackers and used for distributed denial-of-service attacks. Palo Alto Network's next generation firewall offers protection against this variant through cloud-delivered security services, including IoT security, advanced threat protection, wildfire, and advanced URL filtering. Unit 42 researchers have observed multiple campaigns using the IZ1H9 variant since November 2021, suggesting the work of a single threat actor based on similarities in malware and infrastructure. The variant connects to a hard-coded command and control, or C2, address and employs an encrypted string table for configuration. It leverages default login credentials for SSH and telnet channels and exploits remote code execution vulnerabilities for HTTP channel access. Applying patches and updates is crucial to mitigate the risk posed by this variant. Palo Alto Networks provides comprehensive protection to its customers against the Mirai IZ1H9 variant.

TL;DR

  • Unit 42 discovered the IZ1H9 Mirai variant exploiting vulnerabilities in Linux servers and networking devices from vendors including Tenda, lblink, DCN, and Zyxel.
  • Compromised devices are recruited into a botnet for DDoS attacks, with the malware using hardcoded C2 addresses and encrypted configuration tables.
  • Palo Alto Networks offers protection through cloud-delivered services including IoT security, advanced threat protection, WildFire, and URL filtering.

Summary

This threat briefing from Unit 42 examines the IZ1H9 variant of the Mirai botnet, first discovered in April and actively targeting Linux-based servers and networking devices since November 2021. The variant exploits multiple vulnerabilities including command injection flaws in Tenda G103 and lblink devices, as well as remote code execution vulnerabilities in DCN and Zyxel equipment. Once compromised, devices are recruited into a botnet capable of launching distributed denial-of-service attacks. The malware connects to hardcoded command and control infrastructure, uses encrypted configuration tables, and spreads through default SSH and telnet credentials alongside HTTP-based exploitation. Palo Alto Networks positions its next-generation firewall with cloud-delivered security services—including IoT security, advanced threat protection, WildFire, and advanced URL filtering—as comprehensive protection against this threat. The briefing emphasizes that consistent campaign patterns suggest a single threat actor behind IZ1H9 operations, and recommends patching as the primary mitigation strategy.

Chapters

0:00 - IZ1H9 Variant Discovery
0:15 - Targeted Vulnerabilities
0:44 - Protection Solutions
1:04 - Threat Actor Analysis

Key Quotes

0:00 "On April 10th, researchers at Unit 42 discovered a new variant of the Mirai botnet named IZ1H9, which exploits vulnerabilities in Linux-based servers and networking devices."
1:04 "Unit 42 researchers have observed multiple campaigns using the IZ1H9 variant since November 2021, suggesting the work of a single threat actor based on similarities in malware and infrastructure."
1:29 "Applying patches and updates is crucial to mitigate the risk posed by this variant."

FAQ

What devices are targeted by the Mirai IZ1H9 variant?

The IZ1H9 variant targets Linux-based servers and networking devices, specifically exploiting vulnerabilities in Tenda G103, lblink, DCN dcbi-netlog, and Zyxel equipment through command injection and remote code execution flaws.

How can organizations protect against this Mirai variant?

Organizations should apply patches and updates to vulnerable devices, change default login credentials for SSH and telnet, and deploy security solutions with IoT protection and advanced threat detection capabilities.


Categories:
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • IoT Security
  • Network Security
  • Technical Deep Dive
  • Mirai botnet
  • IZ1H9 variant
  • Linux security
  • IoT vulnerabilities
  • DDoS attacks
  • Command injection
  • Remote code execution
  • Threat intelligence
  • Network device security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Mirai IZ1H9 Botnet: Linux Server Threat Analysis

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/21/2026
                        04:00 AM
                        07/21/2026
                        Strategies for Managing AI Governance: Safeguarding App-to-LLM API Traffic
                        https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-safeguarding-app-to-llm-api-traffic/
                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version