216.73.216.36

Dissecting RapperBot Botnet: From Infection to DDoS & More

· Published 03/09/2025 05:57 · Modified 03/09/2025 07:01

Export JSON

Essential information

Published
03/09/2025 05:57
Modified
03/09/2025 07:01
Tags
2025-09-03 botnet ddos dns encryption exploit infrastructure iot nvr rapperbot
Related entities
84 observables, 1 intrusion sets (apt), 11 techniques (mitre), 1 malware

Description

This report details the analysis of , a sophisticated targeting devices, particularly Network Video Recorders (NVRs). The malware exploits vulnerabilities in these devices to create a large-scale . The analysis covers the 's infection process, command and control mechanisms, and its evolution over time. Key features include the use of NFS for malware distribution, encrypted TXT records for C2 communication, and a wide range of supported device architectures. The report also discusses recent law enforcement actions against the and provides recommendations for protection against such threats.

External references