shadowv2
ShadowV2 is a Mirai-based IoT botnet variant active as of late 2025. It was observed leveraging the major AWS outage at the end of October 2025 as an apparent test run, with activity reported across 28 countries. ShadowV2 primarily targets routers and other IoT devices, including D-Link devices (via CVE-2024-10914 and CVE-2024-10915), as well as TP-Link and GeoVision devices. It has also been reported targeting Docker daemons and exploiting misconfigured Docker containers on AWS cloud instances to build DDoS capability, including use as a DDoS-for-hire service; one campaign is described as using a Go-based RAT in conjunction with these cloud/Docker misconfigurations. A cited C2 domain for ShadowV2 is connect.antiwifi.dev. Reported impacts include DDoS activity (including a case study involving a Singapore hotel) and broader Mirai-ecosystem surges in late 2025. No attribution to a specific nation-state or named threat group is provided in the source content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ShadowV2 is a Mirai variant that opportunistically exploited the October 2025 AWS outage to test its capabilities across 28 countries. It targets IoT devices using known vulnerabilities, focusing on D-Link, TP-Link, and GeoVision products, and is responsible for significant DDoS attacks, particularly in the technology and retail sectors.
ShadowV2 is a Mirai variant that opportunistically exploited the October 2025 AWS outage to infect IoT devices across 28 countries, focusing on D-Link, TP-Link, and GeoVision vulnerabilities, and launching DDoS attacks against technology and retail targets.
ShadowV2 is a botnet campaign targeting misconfigured Docker containers to deploy Go-based RATs for DDoS attacks, operating as a for-hire service.
Botnet-for-hire service targeting misconfigured AWS Docker containers to build a DDoS botnet using advanced attack methods.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.