Skip to content

RapperBot

RapperBot is a Linux-focused IoT botnet and DDoS-for-hire malware family active since at least 2021 and publicly identified in 2022.

RapperBot

Family profile

RapperBot is a Linux-focused IoT botnet and DDoS-for-hire malware family active since at least 2021 and publicly identified in 2022. It primarily compromises internet-exposed SSH services through brute-force attacks using weak or default credentials, targeting IoT devices, DVRs, network cameras, and other embedded Linux systems. It has also used Telnet-based self-propagation in related activity, with device-prompt fingerprinting and architecture-specific payload deployment across multiple embedded CPU architectures.

RapperBot shares implementation similarities with Mirai but notably targets SSH and includes a persistence mechanism that installs an operator-controlled SSH public key on compromised hosts. This enables continued remote access after password changes, disabling SSH password authentication, rebooting, or removal of the malware binary; the modification can also remove legitimate authorized keys and deny legitimate administrators key-based access. The malware obtains credential lists remotely and reports successfully acquired credentials to its command-and-control infrastructure.

The botnet supports multiple network-layer DDoS methods, including UDP, TCP, GRE, and game-server-oriented flooding attacks. Some variants added Monero cryptojacking functionality on compromised Intel x64 systems, initially deploying separate mining and botnet components and later integrating the mining functionality into the bot client. These variants can terminate competing cryptocurrency miners. U.S. law enforcement disrupted RapperBot infrastructure in August 2025 after attributing more than 370,000 DDoS attacks against approximately 18,000 victims in more than 80 countries to the service.

Capabilities

  • Brute Force
  • Credential Theft
  • Crypto Theft
  • Ddos
  • Exfiltration
  • Persistence
  • Scanning

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Exploited software

Vulnerabilities linked to RapperBot

1 CVEs

MITRE ATT&CK

RapperBot in ATT&CK

16 distinct techniques