Raptor Train is a large, multi-tier botnet linked by U.S. authorities to the China-nexus Flax Typhoon activity cluster and to Chengdu-based Integrity Technology Group. Active from at least May 2020 until its 2024 disruption, it compromised more than 200,000 network-connected devices globally, including SOHO routers, modems, firewalls, IP cameras, network video recorders, digital video recorders, and network-attached storage appliances. Its primary payload was Nosedive, a variant of Mirai. Raptor Train used an enterprise-style, three-tier architecture for tasking, payload delivery and exploitation, and command-and-control management. Operators exploited vulnerabilities affecting more than 20 device types, including both known and previously unknown flaws; infected edge devices generally remained enrolled only briefly because the payload lacked persistence. The botnet supported reconnaissance and scanning against military, government, telecommunications, higher-education, defense-industrial-base, and IT targets, particularly in the United States and Taiwan, and was associated with exploitation attempts against exposed enterprise applications and remote-access appliances. Nosedive has distributed-denial-of-service functionality, and Raptor Train operators conducted a denial-of-service attack during U.S. disruption operations. The FBI's court-authorized operation seized botnet infrastructure and removed malware from compromised devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The FBI and cybersecurity researchers have disrupted a massive Chinese botnet called “Raptor Train” that infected over 260,000 networking devices to target critical infrastructure in the US and in other countries.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Raptor Train botnet, disrupted by the United States, offers a clear illustration of this contractor model. It was attributed to Chengdu-based Integrity Technology Group, found responsible for developing the botnet and therefore held partly accountable for intrusion activities attributed to Flax Typhoon.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Since May 2020, over 200,000 devices, including SOHO routers, NVR/DVR devices, NAS servers, and IP cameras, have been compromised and added to the Raptor Train botnet.
For example, China's Integrity Technology Group controlled and managed the so-called Raptor Train network, which in 2024 infected more than 200,000 devices worldwide, including small office home office (SOHO) routers, internet-connected web cameras and video recorders, plus firewalls and network-attached storage (NAS) devices.
The Raptor Train botnet, disrupted by the United States, offers a clear illustration of this contractor model. It was attributed to Chengdu-based Integrity Technology Group, found responsible for developing the botnet and therefore held partly accountable for intrusion activities attributed to Flax Typhoon.
The malware connected these thousands of infected devices into a botnet, controlled by Integrity Technology Group, which was used to conduct malicious cyber activity disguised as routine internet traffic from the infected consumer devices.
A majority of China-linked threat actors are using compromised routers and IoT devices worldwide, turning this gear into proxy networks to carry out further intrusions, steal sensitive data, and disrupt victim organizations’ operations.
...used to conduct malicious cyber activity disguised as routine internet traffic from the infected consumer devices... For the second time this year, we have disrupted a botnet used by PRC proxies to conceal their efforts to hack into networks in the U.S. and around the world...
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison example of a campaign using shared external infrastructure; no operational details are provided.
Mentioned only in related content as another botnet.
A botnet developed by Integrity Technology Group and linked to intrusion activity attributed to Flax Typhoon, illustrating the role of private contractors in Chinese cyber operations.
A large covert network/botnet of compromised routers, cameras, recorders, firewalls, and NAS devices used to provide proxy infrastructure for China-linked intrusion activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.