Researchers reported multiple fast-moving IoT/Linux botnet campaigns built from Mirai and Gafgyt code that aggressively targeted embedded devices through known vulnerabilities and, in some cases, credential brute forcing. Palo Alto Networks said the campaigns—linked to evolutions of Omni, Okane, and Hakai—combined as many as 11 exploits in a single sample and introduced new distributed denial-of-service techniques, while related Gafgyt malware added an HTTPCF Layer 7 attack command aimed at Cloudflare-protected URLs. One newly adopted vector was the unauthenticated remote command execution flaw in D-Link DSL-2750B routers, which attackers incorporated shortly after public exploit tooling became available.
The activity mirrors earlier reporting on IoT_reaper, a rapidly spreading botnet that also favored exploit-driven propagation over Mirai-style weak-password attacks. Netlab 360 said Reaper integrated at least nine exploits across products from D-Link, Netgear, Linksys, AVTECH, GoAhead, JAWS, and Vacron, maintained multiple command-and-control components, and at one point showed more than 10,000 daily active bot IPs on a tracked server, with millions of vulnerable devices queued for infection. Together, the reports show botnet operators quickly weaponizing public disclosures and modules to compromise internet-exposed routers and cameras at scale, then repurposing those infections for DDoS and broader botnet operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On June 19, Okane samples hosted on the server were stripped of their exploit code and returned to brute-force propagation followed by dropping a shell script.
On June 13, some Okane samples temporarily replaced their normal payload source with the Cloudflare DNS server address 1.1.1.1.
A Metasploit module for the D-Link DSL-2750B OS command injection vulnerability became available, enabling easier weaponization of the flaw.
Newer Hakai samples incorporated exploitation of the D-Link DSL-2750B OS command injection flaw shortly after the Metasploit module was published, and also changed payload sourcing to 178.128.185.250.
By the end of May 2018, three IoT/Linux malware campaigns based on Mirai and Gafgyt source code had emerged, with some samples combining up to eleven known exploits against embedded devices.
As of October 19, one tracked IoT_reaper command-and-control server was seeing more than 10,000 unique active bot IP addresses per day.
Researchers reported another IoT_reaper update on October 16, further indicating active development of the malware during its expansion phase.
The report says the attacker added additional exploits in an update on October 12 as the botnet continued expanding its propagation capabilities.
The IoT_reaper operators incorporated a Vacron NVR remote exploit that had been disclosed on October 8, showing they were rapidly updating the botnet's exploit arsenal.
Researchers observed a new malicious IoT-targeting sample and identified the emerging botnet family later named IoT_reaper. The malware relied on exploiting device vulnerabilities rather than weak-password brute forcing.
A Full Disclosure post described a remote command execution vulnerability affecting D-Link DSL-2750B firmware versions 1.01 to 1.03 that required no authentication.
Related Gafgyt samples associated with the Omni infrastructure at 213.183.53.120 introduced an HTTPCF command that invoked a SendHTTPCloudflare function to target URL paths commonly used by Cloudflare-protected sites. This represented a new DDoS capability beyond the exploit-propagation behavior already documented for the campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
researchcenter.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourceblog.netlab.360.com
Open sourceblog.netlab.360.com
Open sourceseclists.org
Open sourceblogs.securiteam.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.