216.73.217.22

Derailing the Raptor Train

· Published 20/09/2024 11:41 · Modified 20/09/2024 12:18

Export JSON

Essential information

Published
20/09/2024 11:41
Modified
20/09/2024 12:18
Tags
2024-09-20 botnet ddos iot raptor train
Related entities
1 vulnerabilities (cve), 198 observables, 1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 8 others

Description

A large, multi-tiered called , likely operated by Chinese threat actors Flax Typhoon, has been discovered. Consisting of over 60,000 compromised SOHO and devices at its peak, it's one of the largest Chinese state-sponsored botnets to date. The uses a sophisticated control system called Sparrow to manage its infrastructure and execute various tasks. While no attacks have been observed, the has targeted U.S. and Taiwanese entities in sectors like military, government, education, and telecommunications. The network architecture includes three tiers: compromised devices, exploitation and C2 servers, and management nodes. Campaigns have evolved over four years, showing increasing sophistication in tactics and scale.

External references