<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Mirai</title><description>Cybersecurity articles tagged #Mirai on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Evooo1Bot Linux Botnet Turns Routers Into SOCKS5 Relays</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</guid><description>A new Mirai-based modular Linux botnet called Evooo1Bot targets internet routers, turning them into SOCKS5 traffic relay nodes.</description><pubDate>Sat, 15 Aug 2026 16:14:07 GMT</pubDate><category>DDoS</category><category>Credential Theft</category><category>D Link</category><category>TP Link</category><category>Mirai</category></item><item><title>Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence</title><link>https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</guid><description>The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.</description><pubDate>Tue, 28 Jul 2026 17:36:22 GMT</pubDate><category>Tengu</category><category>Mirai</category><category>Linux Botnet</category><category>Iot Security</category><category>DDoS</category></item><item><title>Analyzing Internet Background Radiation and Automated Scanning Trends</title><link>https://runtimerebel.com/blog/analyzing-internet-background-radiation-and-automated-scanning-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-internet-background-radiation-and-automated-scanning-trends</guid><description>An analysis of automated cybercrime traffic and internet background radiation, detailing how botnets exploit vulnerabilities like CVE-2017-17215.</description><pubDate>Thu, 25 Jun 2026 09:22:13 GMT</pubDate><category>Automated Scanning</category><category>Botnets</category><category>Mirai</category><category>CVE-2017-17215</category><category>Internet Background Radiation</category></item><item><title>Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215</title><link>https://runtimerebel.com/blog/gafgyt-and-mirai-variants-target-iot-devices-via-cve-2017-17215</link><guid isPermaLink="true">https://runtimerebel.com/blog/gafgyt-and-mirai-variants-target-iot-devices-via-cve-2017-17215</guid><description>Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.</description><pubDate>Fri, 08 May 2026 08:41:11 GMT</pubDate><category>Gafgyt</category><category>Mirai</category><category>CVE-2017-17215</category><category>Iot Security</category><category>Botnet</category></item><item><title>CVE-2025-29635: Mirai Exploits EoL D-Link Routers</title><link>https://runtimerebel.com/blog/cve-2025-29635-mirai-exploits-eol-d-link-routers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-29635-mirai-exploits-eol-d-link-routers</guid><description>A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks.</description><pubDate>Wed, 22 Apr 2026 20:25:12 GMT</pubDate><category>Mirai</category><category>D Link DIR 823X</category><category>CVE-2025-29635</category><category>IoT Botnet</category><category>RCE</category><category>Command Injection</category><category>DDoS</category></item><item><title>TP-Link Archer AX21 RCE via CVE-2023-1389 — Mitigation Guide</title><link>https://runtimerebel.com/blog/tp-link-archer-ax21-rce-via-cve-2023-1389-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/tp-link-archer-ax21-rce-via-cve-2023-1389-mitigation-guide</guid><description>Hackers continue targeting discontinued TP-Link Archer AX21 routers with CVE-2023-1389, though many exploitation attempts currently fail to execute payloads.</description><pubDate>Mon, 20 Apr 2026 08:54:58 GMT</pubDate><category>CVE-2023-1389</category><category>TP Link</category><category>Archer AX21</category><category>MooBot</category><category>Mirai</category><category>Command Injection</category></item><item><title>Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet</title><link>https://runtimerebel.com/blog/nexcorium-mirai-variant-exploits-cve-2024-3721-in-tbk-dvr-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/nexcorium-mirai-variant-exploits-cve-2024-3721-in-tbk-dvr-botnet</guid><description>Security researchers identify Nexcorium, a new Mirai variant targeting TBK DVRs and EoL TP-Link routers via CVE-2024-3721 for large-scale DDoS attacks.</description><pubDate>Sat, 18 Apr 2026 08:19:28 GMT</pubDate><category>Nexcorium</category><category>Mirai</category><category>CVE-2024-3721</category><category>TBK DVR</category><category>IoT</category><category>DDoS</category></item><item><title>CVE-2024-32113: Apache OFBiz RCE Exploited for Mirai Botnet</title><link>https://runtimerebel.com/blog/cve-2024-32113-apache-ofbiz-rce-exploited-for-mirai-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-32113-apache-ofbiz-rce-exploited-for-mirai-botnet</guid><description>Technical analysis of CVE-2024-32113 exploitation in Apache OFBiz. Learn how attackers use path traversal to deploy Mirai botnet malware and how to patch.</description><pubDate>Mon, 06 Apr 2026 05:02:01 GMT</pubDate><category>CVE-2024-32113</category><category>Apache OFBiz</category><category>Mirai</category><category>RCE</category><category>Path Traversal</category></item></channel></rss>