botnet
Pandora-Mirai
A Sora-fork Mirai derivative, built with an AI coding agent in the loop. Named by 2 reports, 3 detection rules, 1 IOC feed and 1 tracked actor.
Also written as: Pandora-Mirai-Variant, Pandora-Mirai variant. These are the spellings the rules, feeds and profiles use; the page collects all of them.
Reports
Detection rules
YARA rules whose family metadata names this family, by detection page.
Detection rules
Multi-Actor AI-Agent Framework Abuse (8 Operators)
MAL_Linux_Pandora_Mirai_Naku_Suite
Detection rules
Rovodev AI-Co-Authored Mirai Variant + Matrix C2 (87.106.143.220)
MAL_ELF_Naku_Pandora_Mirai_Family, MAL_Bash_Pandora_Dropper_Family
IOC feeds
Tracked actors
Designations whose profile lists this family as tooling.
- UTA-2026-014: DDoS-for-hire operator running an AI co-authored C2 framework over a Pandora-Mirai botnet
A family name here is the label the linked rule, feed or profile carries, normalised to one spelling by _data/families.yml. Where a report declines to name a family, this page does not either.