Malware
Mozi
- First Reported
- May 21, 2026
- Latest Reported
- Jun 24, 2026
Reported Context (2)
- IoT botnets such as Hajime (106), Mozi (82), and Mirai (27) continue to exploit embedded devices and consumer routers across the region, consistent with Eastern Europe's large installed base of internet-exposed IoT Hunt.io Maps 3,923 Potentially Malicious Infrastructure Endpoints Across Eastern Europe
- The most common detections fall into two groups: IoT botnets like Hajime, Mozi, and Mirai, which are malware, and Threat Activity Enablers like Tactical RMM, Cobalt Strike, and Sliver, which are dual-use tools that show Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers
CVE (5)
Malware (26)
People (4)
Threat Actors (17)
MITRE ATT&CK (14)
Vendors (45)
Products (17)
Tools (12)
Industries (8)
Countries (25)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.