IoT Reaper

Aliases: IoTroop, Reaper, iotreaper

First seen
2017-09-01 00:00:00
Malware type
botnet, ddos, worm
Family
Malware family
Profile updated
2026-07-07 14:26:07

Targeted industries: technology-and-telecommunications energy-and-utilities

Context

IoT Reaper, also known as IoTroop or Reaper, is a botnet malware that targets IoT devices. It exploits known vulnerabilities to conscript devices into a network used for DDoS attacks.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Reaper_Malicious_Lnk (yara-rule)
  • SEKOIA_Apt_Reaper_2Fa_Phishing_Webpage (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Iot Reaper (report)
  • blog.netlab.360.com — Iot Reaper A Rappid Spreading New Iot Botnet En (report)
  • krebsonsecurity.com — Reaper Calm Before The Iot Security Storm (report)
  • research.checkpoint.com — New Iot Botnet Storm Coming (report)

External references