RapperBot is a Linux-focused IoT botnet and DDoS-for-hire malware family active since at least 2021 and publicly identified in 2022. It primarily compromises internet-exposed SSH services through brute-force attacks using weak or default credentials, targeting IoT devices, DVRs, network cameras, and other embedded Linux systems. It has also used Telnet-based self-propagation in related activity, with device-prompt fingerprinting and architecture-specific payload deployment across multiple embedded CPU architectures.
RapperBot shares implementation similarities with Mirai but notably targets SSH and includes a persistence mechanism that installs an operator-controlled SSH public key on compromised hosts. This enables continued remote access after password changes, disabling SSH password authentication, rebooting, or removal of the malware binary; the modification can also remove legitimate authorized keys and deny legitimate administrators key-based access. The malware obtains credential lists remotely and reports successfully acquired credentials to its command-and-control infrastructure.
The botnet supports multiple network-layer DDoS methods, including UDP, TCP, GRE, and game-server-oriented flooding attacks. Some variants added Monero cryptojacking functionality on compromised Intel x64 systems, initially deploying separate mining and botnet components and later integrating the mining functionality into the bot client. These variants can terminate competing cryptocurrency miners. U.S. law enforcement disrupted RapperBot infrastructure in August 2025 after attributing more than 370,000 DDoS attacks against approximately 18,000 victims in more than 80 countries to the service.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets. The exploit is included in some version of rapperbot and exploited in 2026. | “The exploit is included in some version of rapperbot and exploited in 2026.”
16 distinct techniques documented for this family, organized by ATT&CK tactic.
RapperBot campaigns have primarily focused on brute-forcing IoT devices with weak or default SSH or Telnet credentials
KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device.
Vulnerable KGUARD DVR firmware exposes a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device.
new versions of the RapperBot DDoS botnet that incorporate cryptojacking functionality to profit off compromised Intel x64 systems by dropping a Monero crypto miner.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet for which a version reportedly includes an exploit for the vulnerable KGUARD DVR command-execution service; the exploit was used in 2026.
A botnet with a version reported to include an exploit for the vulnerable KGUARD DVR command-execution service; it was reportedly used to exploit the issue in 2026.
A botnet used for large-scale distributed denial-of-service attacks across more than 80 countries.
A DDoS botnet used to conduct large-scale disruptive attacks against victims in more than 80 countries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.