Threat Advisory

RapperBot Botnet Exploiting Default Credentials on Network Edge Devices

Threat: Malware Campaign
Targeted Region: Global
Targeted Sector: Technology & IT, Finance & Banking, Critical Infrastructure, Government & Defense
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

RapperBot is an active and evolving botnet family primarily targeting Internet of Things (IoT) devices such as network cameras and routers. Its operations have intensified, with thousands of infected bots observed and over a hundred targets attacked daily. Unlike typical botnets, RapperBot is notable not only for its widespread impact across multiple industries including public administration, social security, internet platforms, manufacturing, and financial services but also for its provocative behavior. The malware authors have embedded taunting messages and cultural references within the code, openly challenging analysts and even resorting to blackmailing victims for "protection money" to prevent distributed denial-of-service (DDoS) attacks. RapperBot propagates by exploiting weak Telnet credentials and known vulnerabilities, including CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581, making it especially dangerous to unpatched and exposed devices.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

RapperBot is an active and evolving botnet family primarily targeting Internet of Things (IoT) devices such as network cameras and routers. Its operations have intensified, with thousands of infected bots observed and over a hundred targets attacked daily. Unlike typical botnets, RapperBot is notable not only for its widespread impact across multiple industries including public administration, social security, internet platforms, manufacturing, and financial services but also for its provocative behavior. The malware authors have embedded taunting messages and cultural references within the code, openly challenging analysts and even resorting to blackmailing victims for "protection money" to prevent distributed denial-of-service (DDoS) attacks. RapperBot propagates by exploiting weak Telnet credentials and known vulnerabilities, including CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581, making it especially dangerous to unpatched and exposed devices.[emaillocker id="1283"]

RapperBot propagates mainly by exploiting weak Telnet credentials and known firmware vulnerabilities on IoT devices, including CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581. It generates multiple potential command-and-control (C2) domain names using a unique method that involves DNS-TXT record resolution. The botnet employs three distinct encryption algorithms for communication: initially Mirai’s algorithm, followed by a custom double-encrypted multi-byte XOR scheme, and an enhanced version of Mirai’s method switching between them across variants. These algorithms decrypt the TXT records to retrieve C2 domains dynamically. Network communications typically consist of a header, payload, and random data fields that vary slightly between versions, often including checksum fields and randomized non-zero fillers. Proxy functionality has been added to its DDoS capabilities, highlighting its evolving complexity.

RapperBot represents a persistent and adaptive threat targeting critical IoT infrastructure worldwide, with a concentration of infections in certain geographic regions. Its ability to exploit common security weaknesses in network devices such as those associated with CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581 and its evolving encryption and communication techniques make it a significant concern. The addition of extortion tactics further escalates the risk to organizations across multiple industries. Continuous monitoring and timely remediation of vulnerable devices, alongside proactive domain registration efforts, remain crucial in mitigating the impact of this botnet.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1204.002 User Execution Malicious File
Defense Evasion T1027.002 Obfuscated Files or Information Software Packing
Discovery T1082 System Information Discovery
T1018 Remote System Discovery
Command and Control T1071.004 Application Layer Protocol DNS
Impact T1499 Endpoint Denial of Service
T1498.001 Network Denial of Service Direct Network Flood

 

MBC MAPPING:

Objective Behavior ID Behavior
Anti-Behavioral Analysis B0001 Debugger Detection
Anti-Static Analysis B0032 Executable Code Obfuscation
Command and Control B0030 C2 Communication
B0031 Domain Name Generation
Defense Evasion B0025 Conditional Execution
B0029 Polymorphic Code

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu