Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Wicked was a Mirai-based botnet described by FortiGuard Labs in a May 2018 analysis. In the samples researchers examined, its scanner used known vulnerabilities to target routers, CCTV/DVR equipment and already-compromised web servers, rather than relying on the traditional credential brute-forcing associated with the original Mirai. The report documents activity observed then; it does not establish that Wicked is active or widespread today.

What was the Wicked botnet?

FortiGuard Labs researchers Rommel Joven and Kenny Yang published their analysis, “A Wicked Family of Bots”, on May 17, 2018. They named the malware Wicked after strings in its configuration, including /bin/busybox WICKED. Contemporary reports from SecurityWeek and TechTarget also described it as a newly reported Mirai variant.

Mirai-based botnets infect internet-connected devices and can use them as bots. The Wicked report is a historical account of particular samples and behavior—not evidence of a current campaign or a count of infected devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How was Wicked different from Mirai?

FortiGuard contrasted the analyzed Wicked scanner with original Mirai’s traditional attempts to gain access by brute-forcing device credentials. Wicked’s scanner instead used known, available exploits. Joven and Yang wrote: “The WICKED bot, on the other hand, uses known and available exploits, with many of them already being quite old.” This distinction describes the samples in their analysis; it should not be generalized to every Mirai-family sample.

Comparison Original Mirai description Wicked in FortiGuard’s 2018 analysis
Reported access method Traditional brute-force attempts against device credentials, as summarized in the Mirai retrospective Known exploits used by the analyzed scanner
Targets and ports The cited retrospective does not provide a directly comparable Wicked target-and-port mapping SYN scans on ports 8080, 8443, 80 and 81, mapped to specific targets below
Scale evidence USENIX Association’s 2017 seven-month retrospective reported Mirai’s peak at 600,000 infections No Wicked-specific infection count is established in the cited reporting

The 600,000 figure belongs to Mirai’s reported peak, not Wicked. Likewise, FortiGuard’s later report of nearly 4,700 Telnet connections over three weeks, nearly 4,000 identified as Mirai-related, describes a 2021 honeypot observation—not Wicked’s 2018 campaign.

Which devices did Wicked target?

FortiGuard reported SYN scans on four ports and associated each with the following targets or access paths:

Port Target or access path reported
8080 Exploits targeting Netgear DGN1000 and DGN2200 v1 routers
8443 Command injection on Netgear R7000 and R6400 routers via CVE-2016-6277
81 A remote-code-execution exploit targeting CCTV-DVR equipment
80 Invoker shells on web servers that had already been compromised

These are targets documented in a 2018 malware analysis, not a list of products to buy or proof that every device of a named model was vulnerable in every configuration. The report describes the observed exploit paths; it does not establish that the same infrastructure or activity remains operational.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did FortiGuard find about Wicked’s delivery trail?

The configuration string SoraLOADER initially suggested that Wicked would deliver a Sora payload. FortiGuard said the hosting directory observed by its researchers had delivered Owari samples, which were later replaced by Omni. Based on an interview and hosting evidence, the researchers linked Wicked, Sora, Owari and Omni to the same pseudonymous author. That attribution is FortiGuard’s; the reporting does not identify the person’s real-world identity.

How can you secure a router and connected devices?

CISA’s general guidance recommends changing default passwords, installing security patches, replacing unsupported devices and monitoring exposed assets. Its home guidance specifically advises changing factory-set credentials on routers and other devices. These steps reduce common risks but do not guarantee protection against every vulnerability or exploit.

  • Replace factory credentials: Change default router and connected-device passwords to unique credentials. Use the device maker’s instructions and avoid reusing passwords.
  • Install supported updates: Check the manufacturer’s support and update instructions for your exact model and hardware revision. Apply security updates where available.
  • Check support status: If a device no longer receives security updates and is exposed to the internet, consider replacing it. CISA recommends replacing unsupported exposed devices; it does not endorse a particular model.
  • Review exposure: Monitor internet-facing devices and services, and disable remote access or services you do not need where the manufacturer’s guidance allows it.

These are general hardening measures, not a claim that one password change or update would have blocked every exploit described in the historical Wicked report.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and not known—about Wicked today?

FortiGuard’s May 17, 2018 analysis is the primary source for Wicked’s technical behavior. SecurityWeek and TechTarget published contemporaneous summaries, but their coverage does not constitute separate technical confirmation of the findings. The cited reporting does not provide a Wicked-specific infection count, establish current prevalence, or confirm that the 2018 infrastructure remains active. The later FortiGuard honeypot statistics concern Mirai-related Telnet activity in a different observation period and should not be treated as a measure of Wicked.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.