The RapperBot botnet, which is based on Mirai, reappeared through a new campaign that infects IoT devices for DDoS (Distributed Denial of Service) attacks against game servers.
Last August, Fortinet researchers found malware that infected Linux servers via SSH brute-forcing.
Researchers found that RapperBot has been active since May 2021, but it is difficult to understand its specific targets.
See also: CISA: Iranian hackers breached organization with Log4Shell exploit

The newer version of this virus uses a Telnet self-propagation mechanism, which resembles the original malicious software Mirai more.
Also, the motivation of the current campaign is more apparent, as the DoS commands in the latest variant are tailored for attacks against servers hosting online games.
See also: Leader of JabberZeus hacking group arrested in Geneva
What exactly is RapperBot
Fortinet analysts were able to sample the new variant using C2 communication artifacts collected in previous campaigns, suggesting that this part of the botnet's operation remained unchanged.
The analysts discovered that the new variant included several changes, such as support for Telnet brute-forcing, via these commands:
- Register (used by the client)
- Stay idle/Do nothing
- Stop all DoS attacks and terminate the client
- Execute a DoS attack
- Stop all DoS attacks
- Restart the Telnet brute forcing
- Stop the Telnet brute forcing
The malware attempts to gain access to devices using common weak credentials from a hardcoded list, instead of pulling the information from the C2 as it did in the past.
After successfully finding the credentials, it reports this to the C2 via port 5123 and then attempts to retrieve and install the correct version of the primary payload binary for the detected device architecture .
See also: CommonSpirit Health: Ransomware attack likely affects millions of Americans

It is likely that the same entities are involved
Fortinet discovered that all RapperBot campaigns are controlled by the same individuals, as newer variants show that they have access to the malware's source code
Moreover, the C2 communication protocol has not changed since August 2021 and the breach attempts have used the same credentials. Also, there is no evidence that different campaigns are collaborating at this time.
The best way to protect IoT devices from botnet infections is to keep the firmware up to date, change the default credentials to a difficult and unique password, and place them behind a firewall whenever possible.
Information source: bleepingcomputer.com
