s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.rapper_bot

📛 Threat Title

Malware family: RapperBot

Category: RapperBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.rapper_bot`. Printable name: RapperBot.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    RapperBot is an active and evolving botnet family primarily targeting Internet of Things (IoT) devices such as network cameras and routers. Its operations have intensified, with thousands of infected bots observed and over a hundred targets attacked daily.

  • web:blog.netmanageit.com

    This report details the analysis of RapperBot , a sophisticated botnet targeting IoT devices, particularly Network Video Recorders (NVRs). The malware exploits vulnerabilities in these devices to create a large-scale DDoS infrastructure. The analysis covers the botnet's infection process, command and control mechanisms, and its evolution over time.

  • web:blog.xlab.qianxin.com

    According to data analysis from XLAB's HUNTER system, RapperBot malware currently primarily infects IoT devices with public network access capabilities, especially network cameras, and home and enterprise-level routers. These devices usually have default weak passwords or firmware vulnerabilities, making them easy targets for attackers.

  • web:cyberpress.org

    The RapperBot botnet has orchestrated an aggressive campaign, executing more than 50,000 attacks against network edge devices globally.

  • web:cybersecuritynews.com

    The RapperBot botnet has reached unprecedented scale, with security researchers observing over 50,000 active bot infections targeting network edge devices across the globe. This sophisticated malware campaign represents one of the most persistent and evolving cyber threats currently plaguing internet-connected infrastructure, demonstrating remarkable adaptability and technical sophistication ...

  • web:hunt.io

    RapperBot is a malware family derived from the Mirai botnet source code, targeting IoT devices through brute-forcing SSH credentials instead of Telnet. This modification allows RapperBot to compromise a broader range of devices, including those with more secure configurations. Unique among Mirai variants, RapperBot incorporates persistence mechanisms, ensuring continued access to compromised ...

  • web:jsac.jpcert.or.jp

    Agenda Malware analysis Key specifications of RapperBot for the C2 command observation Outline of the python script for C2 command observation

  • web:undercodetesting.com

    Introduction: The RapperBot malware represents a sophisticated and persistent threat, recently leveraged in high-profile DDoS campaigns against major tech platforms. This article deconstructs the malware's infection chain, from initial compromise to its ultimate role in a botnet, providing a technical deep dive for security professionals to understand, detect, and mitigate this threat.

  • web:www.fortinet.com

    FortiGuard Labs is tracking a rapidly evolving IoT malware family known as RapperBot . Read to learn how this threat infects and persists on a victim's device.

  • web:www.kaspersky.com

    In December 2022, the Top-3 countries with the highest number of devices infected by RapperBot were Taiwan, South Korea, and the United States. Another new malware family described in the Kaspersky's blogpost is a CUEMiner, based on an open-source malware that first appeared on Github in 2021.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.