RapperBot is a Linux-based IoT botnet malware family associated with large-scale distributed denial-of-service operations and DDoS-for-hire activity. It has been active since at least 2021 and was publicly identified in 2022. The malware primarily compromises internet-exposed embedded devices and Linux systems, including routers, DVRs, network cameras, and other IoT equipment, and has also been observed abusing compromised SSH servers.
RapperBot is notable for combining Mirai-like botnet behavior with distinct propagation and persistence tradecraft. Early activity centered on brute-forcing SSH services using weak or default credentials, after which the malware exfiltrated valid credentials and modified SSH authorized key configuration to install operator-controlled public keys for durable access. This allowed continued access even after password changes or disabling password-based SSH authentication, and could also lock out legitimate administrators by removing existing authorized keys. Separate observed campaigns reused RapperBot’s command-and-control protocol while shifting propagation to Telnet brute forcing against IoT devices, using embedded default credentials and device-prompt fingerprinting to optimize login attempts.
Its core operational purpose is DDoS. Reported attack capabilities include multiple flood types across TCP, UDP, and GRE, with some variants tailored toward attacks on game servers. RapperBot has been linked to very large disruptive campaigns affecting victims in more than 80 countries and was described by authorities as one of the larger DDoS-for-hire botnets prior to takedown activity in 2025.
Later variants expanded monetization beyond DDoS by adding cryptojacking functionality. These versions targeted compromised Intel x64 Linux systems and deployed XMRig-based Monero mining, in some cases integrating mining and botnet functions into a single client and terminating competing miners. Reporting indicates these miner-enabled variants did not self-propagate directly and may have relied on externally delivered access derived from credentials harvested by other RapperBot components.
RapperBot has been tracked as targeting Linux and embedded architectures including common IoT processor families, while some miner-enabled variants specifically targeted x64 systems. The malware has been associated with campaigns against home and small-office edge devices as well as broader opportunistic exploitation of weakly secured internet-facing systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
new versions of the RapperBot DDoS botnet that incorporate cryptojacking functionality to profit off compromised Intel x64 systems by dropping a Monero crypto miner.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet used for large-scale distributed denial-of-service attacks across more than 80 countries.
A DDoS botnet used to conduct large-scale disruptive attacks against victims in more than 80 countries.
RapperBot is mentioned as an example of an IoT-related threat from prior research, but no further details are provided in this content.
IoT-focused DDoS botnet targeting DVRs and network cameras; propagates via multiple scanners and is controlled via C2 infrastructure used to issue DDoS commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.