Cybersecurity researchers began detecting a worrying increase in UDP flood in early April 2025, originating from compromised network video recorders (NVRs) and other edge devices, known as RapperBot.
See also: Cloudflare blocked the largest DDoS attack (11.5 Tbps)

Within milliseconds of infection, these devices were transformed into weapons to direct massive volumes of packets to unsuspecting targets, leading to service outages and massive bandwidth consumption.
Bitsight analysts identified this activity as the work of the new RapperBot botnet, noting the unusually fast chain of execution and the innovative use of old hardware limitations to evade detection.
The emergence of malware follows a familiar pattern: malicious actors scan the Internet for exposed web interfaces, brute force or exploit default credentials, and deliver a malicious payload disguised as a firmware update.
Once executed, RapperBot immediately initiates two separate actions: encrypted DNS TXT record queries to obtain command and control (C2) IP addresses and continuous UDP floods on port 80.
Impact assessments show individual device throughput exceeding 1 Gbps, with total botnet capacity peaking at over 7 Tbps during coordinated campaigns against major targets, including cloud-based search providers and social media platforms.
See also: BIND 9 vulnerabilities expose organizations to DoS attacks

Despite its power, the malware's behavior is elegantly simple: it mounts a remote NFS share to retrieve and execute architecture-specific binaries, then deletes itself to run entirely in memory.
Bitsight researchers noted that this strategy leverages the minimal BusyBox environment on many IoT devices, where typical download tools like curl or /dev/tcp are absent.
By exploiting the NVR's firmware update mechanism – specifically, a zero-day route to the web server followed by a binary recovery via NFS – RapperBot avoids the usual file system objects that trigger antivirus.
Internally, RapperBot's C2 discovery mechanism relies on encrypted TXT files hosted on OpenNIC such as iranistrash.libre and pool.rentcheapcars.sbs.
The malware constructs one of 32 predefined hostnames by randomly selecting from hard-coded lists of subdomains, domains, and TLDs, and then resolves these names against custom DNS servers (1.1.1.1, 8.8.8.8, and others).
See also: Cloudflare: DDoS attacks reach record rate of 7.3 Tbps
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The TXT response contains a list of encrypted IP addresses separated by pipes, which the bot decrypts with a custom algorithm followed by base 56 decoding.
