Mozi malware family
Mozi is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-08-14, most recently 2026-08-25.
Corpus statistics
- Publicly analyzed samples: 3
- First seen: 2026-08-14
- Last seen: 2026-08-25
- Verdicts: malicious 3
- File types: elf 3
Extracted command-and-control infrastructure
- http://upx.sf.net - 3 samples
Recent Mozi samples
- bf8d6f91eb7460fbbfcf60dfd21c9c82f36d16e68a04c1a058a9e70aa4c29a0e - malicious (2026-08-25)
- bd669660b3ae5ca94392a8b7e26e96e56fd4852fd48e47404a461fb20f97f352 - malicious (2026-08-24)
- 1abcd7e645621d0ed1c02b380a4e574a8cf6490d503043fb76789f4d3a3a5461 - malicious (2026-08-14)
Frequently asked about Mozi
- What is Mozi?
- Mozi is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-08-14, most recently 2026-08-25.
- How many Mozi samples have been analyzed?
- MalwareAnalyzer by Cyble holds 3 publicly analyzed samples attributed to Mozi, first seen 2026-08-14 and most recently 2026-08-25. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does Mozi use?
- Mozi samples in this corpus are distributed as elf (3).
- Does Mozi use command-and-control infrastructure?
- Yes. 1 distinct command-and-control indicator has been extracted from Mozi samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Mozi malicious?
- 3 of 3 analyzed Mozi samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends