IoT Reaper is an IoT botnet first observed in September 2017. It reuses elements of Mirai code but propagates by scanning for and exploiting vulnerabilities in internet-exposed embedded devices rather than by brute-forcing weak credentials. It targeted vulnerable routers, network video recorders, IP cameras, and related IoT products, including devices using D-Link, Netgear, Linksys, AVTECH, Vacron NVR, GoAhead, and JAWS components. The botnet used separated controller, downloader, reporting, and loader functions; infected devices reported potentially vulnerable systems, and loader infrastructure deployed bot payloads to them. IoT Reaper incorporated a Lua execution environment, enabling flexible operator-supplied scripting. Its Lua functionality included support for DDoS activity and embedded DNS resolvers that could facilitate DNS-amplification attacks, although observed operator commands during its early expansion focused on downloading malware and increasing botnet size rather than launching DDoS attacks. Operators rapidly added newly disclosed IoT exploits, and the botnet grew to thousands of simultaneously active compromised devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
downloader : 162.211.183.192, samples can be downloaded from this server... controller : 27.102.101.121, which can control bots, send commands
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparative IoT botnet that used multiple exploits and borrowed some Mirai source code.
IoT botnet referenced for comparison as another multi-exploit malware that borrowed some Mirai source code.
An IoT botnet family that borrows some code from Mirai but does not perform password cracking. Instead, it focuses on exploiting IoT device vulnerabilities to infect devices, uses an integrated Lua execution environment for more complex attack scripting, and includes DNS open resolvers that could support DNS amplification attacks.
An IoT botnet first observed on 2017-09-13 that propagates by exploiting embedded vulnerabilities rather than brute-forcing weak passwords. It incorporates nine IoT exploits, uses distinct downloader/controller/reporter/loader infrastructure, and embeds a Lua execution environment that can support complex scripts. It also embeds approximately 100 open DNS resolvers, enabling potential DNS-amplification DDoS attacks, though no active DDoS command was observed in this report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.