IoT Reaper is an IoT botnet malware family first observed in 2017 that targets embedded Linux-based devices such as routers, network video recorders, IP cameras, and other internet-exposed appliances. It is widely characterized as borrowing elements from Mirai while diverging from Mirai’s classic weak-password propagation model by emphasizing exploitation of known vulnerabilities in exposed device services. Observed samples integrated multiple exploits against products including D-Link, Netgear, Linksys, AVTECH, GoAhead-based devices, JAWS-based devices, and Vacron NVR systems, and operators were noted for rapidly incorporating newly disclosed vulnerabilities.
The malware used a multi-component infrastructure that separated downloading, reporting, control, and loading functions. Infected or scanned devices were reported back to operator-controlled systems, and an automated loader was used to implant the bot on vulnerable targets. Telemetry associated with the botnet indicated large-scale expansion, with substantial queues of candidate vulnerable devices and large daily populations of active bots.
A notable feature of IoT Reaper was its integrated Lua execution environment, which enabled more flexible post-compromise logic than many earlier IoT botnets. Embedded Lua components included support consistent with distributed denial-of-service operations, including use of numerous open DNS resolvers that could facilitate amplification attacks. However, reporting from the period emphasized that observed operator activity was primarily focused on propagation and botnet growth rather than confirmed live DDoS deployment.
IoT Reaper is best understood as an exploit-driven IoT botnet and malware loader/backdoor hybrid derived in part from Mirai-era tradecraft, with emphasis on scalable compromise of vulnerable embedded devices and preparation for later botnet operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparative IoT botnet that used multiple exploits and borrowed some Mirai source code.
IoT botnet referenced for comparison as another multi-exploit malware that borrowed some Mirai source code.
An IoT botnet family that borrows some code from Mirai but does not perform password cracking. Instead, it focuses on exploiting IoT device vulnerabilities to infect devices, uses an integrated Lua execution environment for more complex attack scripting, and includes DNS open resolvers that could support DNS amplification attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.