c2.teamzeroday.net: a Mirai botnet host that offered manta files for routers and other small devices, and how to clean one
c2.teamzeroday.net is a host name on a domain registered on 20 September 2026 that URLhaus listed on 1 October 2026 for eleven files in a folder called bin, named manta.x86_64, manta.armv7l, manta.mipsel and so on, every one tagged Mirai.
Mirai enlists routers, cameras and other small Linux devices in attack botnets; it is not a Windows or Mac program. By 8 October all eleven files were offline and the server behind Cloudflare refused connections. If the name shows up in your logs, the device that asked for it is the one to clean.
Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a router, camera, server or other device that asked for files from c2.teamzeroday.net keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove c2.teamzeroday.net (Mirai manta files) yourself 4 steps, about 12 minutes, no software needed.
Start the steps
C2.teamzeroday.net (Mirai manta files): summary
| Type | A Mirai botnet host: eleven builds named manta.* for different processors, all tagged mirai, on a host called c2 |
|---|---|
| Risk | High for a router, camera or Linux device that fetched the files: it joins a botnet. Low if the name only appears in a log or feed |
| Symptoms | Usually none. A hot router, a slow or dropping connection and settings you did not make are the signs the FBI lists |
| How to get rid of it | Disconnect the device, restart it offline, set a new password, update the firmware, turn off remote admin, and replace it if unsupported |
| Our check (8 October 2026) | One plain request: Cloudflare error 521, the server behind the name refused the connection. That clears nothing |
| Running since / first seen | Domain registered 20 September 2026; files reported 1 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Linux routers, IP cameras, recorders, TV boxes and small servers. Not Windows, macOS or iPhone |
|---|---|
| Detection names | No detection name is known for these files because we did not open them. For Mirai on Linux Microsoft uses Backdoor:Linux/Mirai.B |
| Name | C2.teamzeroday.net |
| Domain registered | 20 September 2026 |
| Evidence | 11 write-ups by security sites; details still limited |
| First seen | 1 October 2026 |
| Distribution | Typically loaders, free VPN or "earn money" apps and cracked programs |
| Damage | Your internet connection used by others for attacks or fraud, blocklisting, slower internet |
| Facts checked | 8 October 2026 |
Facts checked on 8 October 2026 against the URLhaus data for c2.teamzeroday.net held in our database, RDAP for teamzeroday.net, one plain request from our server, and published material from CISA, the FBI, HKCERT, Akamai, ThaiCERT, Cloudflare, Microsoft, the USENIX Security 2017 Mirai study and SecurityWeek. We did not download the files and infected no device; the steps follow those sources and were not tried on a live infection.
What c2.teamzeroday.net is, and what the reports show
c2.teamzeroday.net is not something you install. It is a host name that the abuse.ch project URLhaus lists for eleven Mirai files offered over plain http. We found no researcher write-up about this host or about the name manta, so this page puts together the URLhaus rows, the registration record, our own request and what CISA, the FBI, HKCERT, Akamai and others have published on Mirai.
- 1
The eleven files
All sit in a folder called bin and share the name manta with a processor ending: armv6l, armv7l, aarch64, x86_64, i686, mips, mipsel, ppc, sh4, m68k and arc. URLhaus received them from the reporter BlinkzSec on 1 October 2026 between 13:48:15 and 13:48:34 UTC.
- 2
The four tags
Every file has the same four tags: elf, which is the program format of Linux; mirai, the malware family; ua-wget; and the host name itself. Our reading of ua-wget is that the reporter fetched the files with the wget tool, the way an infected device would, possibly because the server answered only that kind of request.
- 3
The host name
c2 is the common short form of command and control, the server that gives a botnet its orders. A download folder on a host called c2 suggests the same operator used the name for both jobs, but we did not see any control traffic and cannot confirm it.
- 4
What we cannot tell you
We did not fetch the files, so we do not know which Mirai variant manta is, which attack commands it carries or which device flaw was used to spread it. Manta does not appear as a family name in any report we read.
- Kind of threat
- A download host for Mirai builds: the files a hacked router, camera or other Linux device fetches to join a botnet
- Where the files were
- hxxp://c2[.]teamzeroday[.]net/bin/manta.<processor>, eleven builds
- Domain registered
- teamzeroday.net on 20 September 2026 through NICENIC International Group Co., Limited; status client delete prohibited and client transfer prohibited (RDAP, read 8 October 2026)
- URLhaus entries
- 11 file addresses, all on 1 October 2026, all tagged elf, mirai and ua-wget; all offline in our copy on 8 October 2026
- Our check
- 8 October 2026: HTTP 521 from Cloudflare, meaning the server behind Cloudflare refused the connection
- Platform
- Linux devices with these processors: routers, IP cameras, recorders, some TV boxes and small servers. Not Windows, macOS or iPhone
What c2.teamzeroday.net (Mirai manta files) does on an infected PC
What our request on 8 October 2026 found
We sent one plain request from our server, with no browser and no clicks.
It reached Cloudflare, which fronts the name, but not the machine behind it.
Our check, 8 October 2026
- Error 521 from CloudflareCloudflare says error 521 occurs when the origin web server refuses connections from Cloudflare. The real server was down or blocking Cloudflare when we asked.
- Why this does not clear the hostCloudflare keeps answering for a name even when the server behind it is gone. The operator can switch a new server in behind the same name at any moment, and the files can come back.
- URLhaus listingEleven Mirai builds for eleven processor families, all tagged mirai, reported on 1 October 2026 and all offline by 8 October 2026.
- RegistrationThe domain was eleven days old when the files were reported. A brand new domain used at once for malware is common, but age alone proves nothing.
- Files not examinedWe did not download any build. Their contents, their control server and their attack list are unknown to us.
Dangerous: treat it as a botnet host Our request saw only an error page, which says nothing about safety. The rating rests on eleven URLhaus reports tagged mirai and on a host name that points to command and control.
From registration to error page in eighteen days
The public record of this host is short.
Every date below comes from RDAP, URLhaus or our own request.

20 September 2026
The domain is registered
RDAP shows teamzeroday.net created at 11:59 UTC through NICENIC International Group Co., Limited, with locks against deletion and transfer that the registrar sets on request.
1 October 2026, 13:48 UTC
Eleven builds are reported
BlinkzSec reports manta.armv6l first at 13:48:15 UTC and manta.ppc, manta.arc and manta.armv7l last at 13:48:34 UTC. All eleven are tagged elf, mirai and ua-wget.
By 8 October 2026
The files go offline
Our copy of the URLhaus data marks every file offline.
8 October 2026
Our request
Cloudflare answers with error 521: the server behind the name refuses the connection. No page and no file comes back.
What this suggests: a fresh domain, a full shelf of builds and a quick disappearance is a pattern Spamhaus and Pulsedive describe for botnet infrastructure that keeps moving. It does not tell us how many devices were enrolled while the files were up.
How a router ends up fetching manta files
Nobody downloads these files on purpose.
A script running on a hacked device does it, usually seconds after the break in.
- 1
The break in
Bots try default passwords over Telnet, which CISA says gave the original Mirai hundreds of thousands of devices, or send a known exploit. Akamai reported in April 2026 a campaign that used CVE-2025-29635, a command injection flaw in D-Link DIR-823X routers retired in September 2025.
- 2
A move to a writable folder
In the Akamai sample the injected command moves to a folder the device can write to, such as /tmp, /var/run, /mnt, /root or the top folder.
- 3
The download
The device then tries busybox wget, curl, tftp and ftpget in turn to fetch a shell script, makes it executable and runs it. Symantec found that such a script downloads every build and runs each one until one fits the chip.
- 4
The bot starts
Only the matching build runs. Akamai's tuxnokill sample hid its strings with a simple XOR key and printed a fake crash message to look harmless.
- 5
The device takes orders
The bot connects to its controller and waits. Akamai lists flood methods over TCP, UDP, GRE and HTTP. Between attacks the bot looks for more devices to infect.
Why there are eleven files, and which devices each one fits
A botnet operator cannot know in advance what chip a hacked device has, so the server offers every common one.
The endings are the clue to which of your devices could be at risk.
| Ending | Processor family (our reading) | Where you find it |
|---|---|---|
| armv6l, armv7l | 32 bit ARM | Many home routers, IP cameras, older single board computers |
| aarch64 | 64 bit ARM | Newer routers, mesh systems, TV boxes, Raspberry Pi 3 and later |
| mips, mipsel | MIPS, big and little endian | Very common in home routers and modems |
| x86_64, i686 | 64 bit and 32 bit PC chips | Linux servers, network storage, virtual machines; a Windows PC has the chip but cannot run a Linux program |
| ppc | PowerPC | Older network gear and some storage boxes |
| sh4 | SuperH | Older set top boxes and recorders |
| m68k | Motorola 68000 | Rare legacy devices |
| arc | ARC cores | Some embedded network chips |
Mirai in 2026: an old family with many new names
Mirai's code has been public for ten years, which is why a new name like manta can appear without any new research behind it.
| Question | What the sources say | Source |
|---|---|---|
| What is it? | Malware that turns home routers, network cameras and digital video recorders into a botnet for denial of service attacks | CISA alert TA16-288A |
| Why so many versions? | Its source code was published at the end of September 2016 | CISA alert TA16-288A |
| How many versions now? | More than 116 Mirai variants and over 21,000 samples, with botnet control servers up 24% in the second half of 2025 | Spamhaus and Pulsedive, as reported by ThaiCERT, 27 March 2026 |
| How large can it get? | About 600,000 infected devices at the original botnet's peak | USENIX Security 2017 study |
| What is new lately? | Attacks on routers their makers no longer support, such as D-Link DIR-823X, TP-Link Archer AX21 and a ZTE ZXV10 model | Akamai, 21 April 2026; HKCERT, 23 April 2026 |
| Microsoft name | Backdoor:Linux/Mirai.B, a Linux threat, published 28 May 2017 | Microsoft Security Intelligence |
| Which variant is manta? | Not known. No report we read names it | Our reading |
What c2.teamzeroday.net (Mirai manta files) can steal or download
Mirai does not go after your photos or passwords.
It borrows your device and your internet line, and that has its own price.
- High
A router in someone else's hands
Whoever controls the router sits in front of every device in the home. Mirai uses it for floods, but the hole it came through stays open to others.
- High
A device that will never be fixed
Akamai notes the D-Link routers in its campaign were retired in September 2025. Such a device can be cleaned by a restart and taken again minutes later.
- Medium
Slow internet and a burned address
Flood traffic eats your upload, and an address seen in attacks can land on block lists, so some sites start to refuse or challenge you.
- Medium
Cameras and recorders
Mirai itself does not watch video, but the weak password or flaw that let it in can also let a person in.
- Low
Windows PCs, Macs and iPhones
These files are Linux programs for small devices. They do not run on those systems.
- Low
A name in a log
A blocked request or a block list entry is not an infection by itself.
Signs the FBI lists for a hacked router
- Overheating
- Connection problems
- Settings you did not change
How to check the PC for c2.teamzeroday.net (Mirai manta files)
Where people see the name c2.teamzeroday.net
Almost everyone who searches for this name saw it in a tool, not on a web page.
- 1
In a router or DNS filter log
Home routers with security features, Pi-hole style DNS filters and firewalls log blocked names. An entry means a device asked for the name; the log shows which device and when.
- 2
In a warning from your provider
Internet providers sometimes write to customers whose line sends attack traffic. Ask them for the time and kind of traffic so you can match it to one device.
- 3
On a server you run
On a Linux server, the name may show up in shell history, in a cron entry or in a web log next to a wget or curl command. That is a sign someone ran commands on the machine.
- 4
In a threat feed or block list
Security teams see it in feeds such as URLhaus. If it is only there, nothing on your side touched it.
Find and check the device that asked
Begin with the log entry. Note the local address of the device and the time of the request, then match it to a device on your router's list of connected clients.
If the device turns out to be a Windows PC, it is not running these Linux files, but something on it made the request; use the plan further down this page for that PC.

- 1
Match the address to a device
Open the router's admin page and its list of connected devices. The local IP or MAC address from the log leads to a name such as a camera, a TV box or the router itself.
- 2
Read the router's settings
Look at remote management, port forwarding, UPnP, DNS servers and the admin user list. Write down every setting you did not make; the FBI names changed settings as a sign of compromise.
- 3
Check the model's support status
Find the exact model on the maker's support site. If it is marked end of life or the newest firmware is years old, plan to replace it.
- 4
On a Linux server, look for traces
Look in /tmp, /var/run and /mnt for files named manta or with processor endings, and in shell history, cron and web logs for wget, curl, tftp or ftpget commands you did not run. Akamai's sample used exactly those folders and tools.
- 5
Do not trust a normal look
Mirai runs from memory and often renames itself. A router page or process list that looks normal is not proof of a clean device.
How to remove c2.teamzeroday.net (Mirai manta files)
The PC was working for someone else, using your connection.
These steps remove the program and close what it changed.
Step 1: Uninstall a router, camera, server or other device that asked for files from c2.teamzeroday.net
A router, camera, server or other device that asked for files from c2.teamzeroday.net is removed like any other program, from the list of installed apps.
In Windows 11 that is Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and in both you can also use Control Panel > Programs and Features.
Select a router, camera, server or other device that asked for files from c2.teamzeroday.net, click Uninstall and follow the uninstaller to the end.
Then look at the entries just above and below it when the list is sorted by date: bundled programs install at the same minute.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 2: Delete scheduled tasks that bring it back
Programs like c2.teamzeroday.net add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 3: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of c2.teamzeroday.net that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
After removal: passwords, accounts and prevention
Clean a router or camera that fetched these files
These steps come from CISA, the FBI, HKCERT and Akamai.
We did not try them on an infected device.
- 1
Cut it off
Unplug the network cable or take the device off Wi-Fi. For a router, disconnect the line to the modem or the fibre box.
- 2
Restart it offline
CISA says Mirai lives in memory and a reboot clears it. Restart while the device is still disconnected.
- 3
Change the admin password before reconnecting
CISA warns that a device reconnected with the old password can be infected again. The FBI advises a unique, random password of 16 to 64 characters.
- 4
Reset it if settings were changed
If you found settings you did not make, do a factory reset and set the device up again by hand, without loading an old settings backup.
- 5
Install the latest firmware
Get the firmware from the maker's own site or the router's built in update page. HKCERT and Akamai both say to apply vendor updates promptly.
- 6
Close what you do not use
Turn off remote management, Telnet and UPnP. The FBI found router malware on devices with remote administration turned on, and CISA advises turning off UPnP unless it is needed.
- 7
Replace unsupported hardware
Akamai's first advice is to retire unsupported devices, and the FBI and HKCERT agree. A restart cannot fix a flaw that will never be patched.
- 8
Rebuild a hacked Linux server
If you found manta files or wget commands on a server, assume someone had a shell on it. Back up your data, reinstall the system, change every password and key that was on it, and close the way in before it goes back online.
Keep small devices out of botnets
The same handful of habits blocks most Mirai infections.
Do
- Change the admin password of every router, camera and recorder when you set it up.
- Turn on automatic firmware updates where the device has them.
- Keep remote management, Telnet and UPnP off unless you need them.
- Check the maker's support end date before you buy, and replace devices past it.
- Put cameras, TV boxes and other smart devices on a separate guest network.
- Look at your router's device list now and then for things you do not recognise.
Don't
- Do not open camera or recorder ports to the internet for remote viewing.
- Do not keep a router running after its maker stops updates.
- Do not restore a saved settings file onto a cleaned router.
- Do not take an error page or an offline file as proof the device is clean.
- Do not ignore a provider's warning about attack traffic from your line.
Questions about c2.teamzeroday.net (Mirai manta files)
What is c2.teamzeroday.net?
It is a host name on teamzeroday.net, a domain registered on 20 September 2026. On 1 October 2026 URLhaus listed eleven files on it, named manta with a processor ending, all tagged mirai.
The c2 in the name is the usual short form of command and control. Together that points to a server of a Mirai botnet.
Is c2.teamzeroday.net still active?
Not when we checked. On 8 October 2026 all eleven files were marked offline, and our request got Cloudflare error 521, which means the server behind the name refused the connection. The name is still registered, though, and a new server can be put behind it at any time, so keep it blocked.
What is manta?
Manta is the file name the operator chose for the builds. We found no report that describes a Mirai variant by that name. URLhaus tags every file mirai and elf, so they are Linux programs from the Mirai family, but which commands and attacks this version carries is not known to us.
Why are there eleven versions of the same file?
Each one is built for a different processor:
- ARM
- 64 bit ARM
- MIPS in two byte orders
- PC chips
- PowerPC
- SuperH
- Motorola 68000
- ARC
A script on a hacked device fetches them and runs the one that fits its chip. Symantec and Akamai describe the same approach. The other builds simply fail to start.
My router or DNS filter blocked c2.teamzeroday.net. Am I infected?
A device on your network asked for it, so check that device. The log entry shows its local address and the time.
If it is a router, camera or TV box, disconnect it, restart it offline, change its admin password and update it before you plug it back in. The block itself did its job.
Can these files run on my Windows PC or Mac?
No. They are Linux programs in the ELF format. A Windows PC or a Mac cannot run them, even the x86_64 build made for the same kind of chip. If a PC appears in your log asking for the name, something on that PC made the request, so check it with the plan on this page.
How do I remove Mirai from my router?
CISA says Mirai runs in memory, so a restart while the router is disconnected clears it. Before you reconnect, set a new long admin password, install the latest firmware and turn off remote management, Telnet and UPnP.
If settings were changed, do a factory reset first. Replace the router if the maker no longer supports it.
Should I replace an old router?
Yes, if the maker no longer sends updates. Akamai, the FBI and HKCERT all advise retiring unsupported devices, because attackers keep using flaws that will never be fixed.
The FBI says routers from 2010 or earlier are likely past their support date. Check your model on the maker's site. A new router with automatic updates is the lasting fix.
Who runs teamzeroday.net?
We do not know. RDAP shows only the registrar, NICENIC International Group Co., Limited, the creation date of 20 September 2026 and locks against deletion and transfer.
The site sits behind Cloudflare, which hides the real server. Abuse of a domain can be reported to the registrar and to Cloudflare.
Will Fortect remove c2.teamzeroday.net?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For c2.teamzeroday.net, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- CISA: Heightened DDoS Threat Posed by Mirai and Other Botnets, alert TA16-288A (14 October 2016, revised 17 October 2017) (read October 8, 2026)
- Akamai SIRT: CVE-2025-29635, Mirai Campaign Targets D-Link Devices, Kyle Lefton (21 April 2026) (read October 8, 2026)
- FBI IC3: Cyber Criminal Proxy Services Exploiting End of Life Routers, I-050725-PSA (7 May 2025) (read October 8, 2026)
- HKCERT: Botnet Alert, Mirai Botnet Targets End-of-Life D-Link Routers (23 April 2026) (read October 8, 2026)
- ThaiCERT: Hundreds of Mirai Variants Drive 24% Surge in Botnet Activity (27 March 2026, on a Spamhaus and Pulsedive report) (read October 8, 2026)
- Cloudflare Docs: Error 521 (read October 8, 2026)
- Microsoft Security Intelligence: Backdoor:Linux/Mirai.B (published 28 May 2017) (read October 8, 2026)
- Antonakakis and others: Understanding the Mirai Botnet, USENIX Security Symposium 2017 (read October 8, 2026)
- SecurityWeek: Cross-Platform Mirai Variant Leverages Open Source Project (23 August 2018, on Symantec research) (read October 8, 2026)