ES EN

Family

IranBot

A Mirai fork the industry detects and won't name. Its author signs the binary with a joke, and they still file it under the usual heading.

The honeypot, right now live console view →

IoT botnet (DDoS) first seen 2026 2 chapters

IranBot is a Mirai fork, and one of the kind that has a name of its own: there’s a public dossier with its markers, and they’re unmistakable. The author left a joke inside the binary —Not a mirai at all— along with a political slogan, and named the files with an iran. prefix.

That last part is worth stating in full, because it’s the first thing people misread: those are strings he wrote. They serve to identify the family and nothing else. They don’t say where it comes from, who pays for it, or where it’s run from.

And dossier or no dossier, the industry doesn’t name it: the engines that detect it file it under the usual heading. Inside, it delivers what the lineage promises —a telnet scanner with factory passwords, self-replication, an attack arsenal— so what’s interesting isn’t what it hides. It’s what it doesn’t bother to hide.

Here we catch it coming in over telnet, and then go looking for who it answers to.