This infamous botnet has been killed off - but who pulled the trigger?

DDOS Attack code concept art
(Image credit: Shutterstock / DaLiu)

A major malware botnet known as Mozi suddenly terminated its operations at the end of September, and no one seems to know exactly why.

As reported by cybersecurity researchers ESET, from August 8 until September 27, someone has been sending messages to the bots (which are nothing but infected devices belonging to people and organizations around the world) to cease operations. All the bots in India were the first to fall, followed by China, the country where Mozi originated, BleepingComputer reports.

In the message, the bots were instructed to terminate the Mozi process, disable some system services, replace the Mozi file, execute device configuration commands, block access to different ports, and establish a foothold for the new file. 

Was it the police?

The identity of the people behind this operation remains a mystery. Law enforcement agencies around the world have been doing similar things in the past with other botnets, but the main difference here is that the malware persists on the bots in anticipation of a new payload.

So it could be the botnet’s creators - but it could also be Chinese law enforcement; we might never find out. 

Mozi was first spotted in 2019, when it went after IoT endpoints such as routers, digital video recorders, and other devices with limited visibility. The majority of the compromised devices had weak or default passwords and as such were easy to compromise and assimilate into the botnet. 

The network was used mostly to run distributed denial of service (DDoS) attacks, which are capable of blocking access to front-facing services. 

The infamous Qakbot botnet was taken down by the FBI earlier this year in the same manner. In late August this year, the FBI said it managed to redirect the botnet’s traffic to servers under its command, and used it to instruct the bots to uninstall the malware. Some 700,000 devices were freed from the clutches of the botnet almost instantly.

However, it seems as if the operators returned in October with a new phishing campaign, aimed at delivering a Remote Access Trojan (RAT) to its victims.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
What is a botnet?
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Another huge new botnet is infecting thousands of webcams and video recorders for DDoS attacks
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Dangerous new botnet targets webcams, routers across the world
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Industrial routers are being hit by zero-days from new Mirai botnets
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening