EXECUTIVE SUMMARY:
RapperBot is an active and evolving botnet family primarily targeting Internet of Things (IoT) devices such as network cameras and routers. Its operations have intensified, with thousands of infected bots observed and over a hundred targets attacked daily. Unlike typical botnets, RapperBot is notable not only for its widespread impact across multiple industries including public administration, social security, internet platforms, manufacturing, and financial services but also for its provocative behavior. The malware authors have embedded taunting messages and cultural references within the code, openly challenging analysts and even resorting to blackmailing victims for "protection money" to prevent distributed denial-of-service (DDoS) attacks. RapperBot propagates by exploiting weak Telnet credentials and known vulnerabilities, including CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581, making it especially dangerous to unpatched and exposed devices.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
RapperBot is an active and evolving botnet family primarily targeting Internet of Things (IoT) devices such as network cameras and routers. Its operations have intensified, with thousands of infected bots observed and over a hundred targets attacked daily. Unlike typical botnets, RapperBot is notable not only for its widespread impact across multiple industries including public administration, social security, internet platforms, manufacturing, and financial services but also for its provocative behavior. The malware authors have embedded taunting messages and cultural references within the code, openly challenging analysts and even resorting to blackmailing victims for "protection money" to prevent distributed denial-of-service (DDoS) attacks. RapperBot propagates by exploiting weak Telnet credentials and known vulnerabilities, including CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581, making it especially dangerous to unpatched and exposed devices.[emaillocker id="1283"]
RapperBot propagates mainly by exploiting weak Telnet credentials and known firmware vulnerabilities on IoT devices, including CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581. It generates multiple potential command-and-control (C2) domain names using a unique method that involves DNS-TXT record resolution. The botnet employs three distinct encryption algorithms for communication: initially Mirai’s algorithm, followed by a custom double-encrypted multi-byte XOR scheme, and an enhanced version of Mirai’s method switching between them across variants. These algorithms decrypt the TXT records to retrieve C2 domains dynamically. Network communications typically consist of a header, payload, and random data fields that vary slightly between versions, often including checksum fields and randomized non-zero fillers. Proxy functionality has been added to its DDoS capabilities, highlighting its evolving complexity.
RapperBot represents a persistent and adaptive threat targeting critical IoT infrastructure worldwide, with a concentration of infections in certain geographic regions. Its ability to exploit common security weaknesses in network devices such as those associated with CVE-2021-46229, CVE-2023-4473, CVE-2020-9054, and CVE-2020-24581 and its evolving encryption and communication techniques make it a significant concern. The addition of extortion tactics further escalates the risk to organizations across multiple industries. Continuous monitoring and timely remediation of vulnerable devices, alongside proactive domain registration efforts, remain crucial in mitigating the impact of this botnet.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Execution | T1204.002 | User Execution | Malicious File |
| Defense Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Discovery | T1082 | System Information Discovery | — |
| T1018 | Remote System Discovery | — | |
| Command and Control | T1071.004 | Application Layer Protocol | DNS |
| Impact | T1499 | Endpoint Denial of Service | — |
| T1498.001 | Network Denial of Service | Direct Network Flood |
MBC MAPPING:
| Objective | Behavior ID | Behavior |
| Anti-Behavioral Analysis | B0001 | Debugger Detection |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Command and Control | B0030 | C2 Communication |
| B0031 | Domain Name Generation | |
| Defense Evasion | B0025 | Conditional Execution |
| B0029 | Polymorphic Code |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]