iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Wicked was a Mirai-based botnet described by FortiGuard Labs in a May 2018 analysis. In the samples researchers examined, its scanner used known vulnerabilities to target routers, CCTV/DVR equipment and already-compromised web servers, rather than relying on the traditional credential brute-forcing associated with the original Mirai. The report documents activity observed then; it does not establish that Wicked is active or widespread today.
What was the Wicked botnet?
FortiGuard Labs researchers Rommel Joven and Kenny Yang published their analysis, “A Wicked Family of Bots”, on May 17, 2018. They named the malware Wicked after strings in its configuration, including /bin/busybox WICKED. Contemporary reports from SecurityWeek and TechTarget also described it as a newly reported Mirai variant.
Mirai-based botnets infect internet-connected devices and can use them as bots. The Wicked report is a historical account of particular samples and behavior—not evidence of a current campaign or a count of infected devices.
How was Wicked different from Mirai?
FortiGuard contrasted the analyzed Wicked scanner with original Mirai’s traditional attempts to gain access by brute-forcing device credentials. Wicked’s scanner instead used known, available exploits. Joven and Yang wrote: “The WICKED bot, on the other hand, uses known and available exploits, with many of them already being quite old.” This distinction describes the samples in their analysis; it should not be generalized to every Mirai-family sample.
#1 Best Overall
| Comparison | Original Mirai description | Wicked in FortiGuard’s 2018 analysis |
|---|---|---|
| Reported access method | Traditional brute-force attempts against device credentials, as summarized in the Mirai retrospective | Known exploits used by the analyzed scanner |
| Targets and ports | The cited retrospective does not provide a directly comparable Wicked target-and-port mapping | SYN scans on ports 8080, 8443, 80 and 81, mapped to specific targets below |
| Scale evidence | USENIX Association’s 2017 seven-month retrospective reported Mirai’s peak at 600,000 infections | No Wicked-specific infection count is established in the cited reporting |
The 600,000 figure belongs to Mirai’s reported peak, not Wicked. Likewise, FortiGuard’s later report of nearly 4,700 Telnet connections over three weeks, nearly 4,000 identified as Mirai-related, describes a 2021 honeypot observation—not Wicked’s 2018 campaign.
Which devices did Wicked target?
FortiGuard reported SYN scans on four ports and associated each with the following targets or access paths:
| Port | Target or access path reported |
|---|---|
| 8080 | Exploits targeting Netgear DGN1000 and DGN2200 v1 routers |
| 8443 | Command injection on Netgear R7000 and R6400 routers via CVE-2016-6277 |
| 81 | A remote-code-execution exploit targeting CCTV-DVR equipment |
| 80 | Invoker shells on web servers that had already been compromised |
These are targets documented in a 2018 malware analysis, not a list of products to buy or proof that every device of a named model was vulnerable in every configuration. The report describes the observed exploit paths; it does not establish that the same infrastructure or activity remains operational.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →What did FortiGuard find about Wicked’s delivery trail?
The configuration string SoraLOADER initially suggested that Wicked would deliver a Sora payload. FortiGuard said the hosting directory observed by its researchers had delivered Owari samples, which were later replaced by Omni. Based on an interview and hosting evidence, the researchers linked Wicked, Sora, Owari and Omni to the same pseudonymous author. That attribution is FortiGuard’s; the reporting does not identify the person’s real-world identity.
How can you secure a router and connected devices?
CISA’s general guidance recommends changing default passwords, installing security patches, replacing unsupported devices and monitoring exposed assets. Its home guidance specifically advises changing factory-set credentials on routers and other devices. These steps reduce common risks but do not guarantee protection against every vulnerability or exploit.
- Replace factory credentials: Change default router and connected-device passwords to unique credentials. Use the device maker’s instructions and avoid reusing passwords.
- Install supported updates: Check the manufacturer’s support and update instructions for your exact model and hardware revision. Apply security updates where available.
- Check support status: If a device no longer receives security updates and is exposed to the internet, consider replacing it. CISA recommends replacing unsupported exposed devices; it does not endorse a particular model.
- Review exposure: Monitor internet-facing devices and services, and disable remote access or services you do not need where the manufacturer’s guidance allows it.
These are general hardening measures, not a claim that one password change or update would have blocked every exploit described in the historical Wicked report.
Rank #4
What is known—and not known—about Wicked today?
FortiGuard’s May 17, 2018 analysis is the primary source for Wicked’s technical behavior. SecurityWeek and TechTarget published contemporaneous summaries, but their coverage does not constitute separate technical confirmation of the findings. The cited reporting does not provide a Wicked-specific infection count, establish current prevalence, or confirm that the 2018 infrastructure remains active. The later FortiGuard honeypot statistics concern Mirai-related Telnet activity in a different observation period and should not be treated as a measure of Wicked.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Best Value
- Used Book in Good Condition
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

