Raptor Train is a China-linked botnet associated with the state-sponsored threat actor Flax Typhoon and developed and managed by Integrity Technology Group. Active from at least May 2020 until its disruption in September 2024, it recruited compromised small-office/home-office routers, modems, firewalls, IP cameras, video recorders, and network-attached storage devices worldwide. The FBI identified more than 260,000 actively infected devices in June 2024, including approximately 126,000 in the United States. The network supported cyberespionage by relaying malicious traffic through compromised devices to conceal operators’ locations and infrastructure.
Its principal payload, Nosedive, is a Mirai variant deployed through exploitation of known and zero-day vulnerabilities across more than 20 device types. Raptor Train used a three-tier architecture separating infected devices, exploitation and payload-delivery infrastructure, and management systems. Operators controlled the network through an application called Sparrow, which provided web-based management and supporting payload-generation and exploitation tooling. Nosedive lacked persistence, and infected first-tier devices typically remained enrolled for approximately 17 days. The payload included distributed denial-of-service capabilities, although researchers did not observe routine DDoS deployment during their tracking; the FBI reported a DDoS attack against its infrastructure during the disruption operation.
Raptor Train supported reconnaissance, vulnerability scanning, and exploitation attempts against strategic targets, particularly in the United States and Taiwan. Targeted sectors included government, military, telecommunications, higher education, information technology, critical infrastructure, and the defense industrial base. Its infrastructure supported MicroScan reconnaissance, and researchers observed scanning of U.S. government and military networks and exploitation attempts against Atlassian Confluence and Ivanti Connect Secure systems. In September 2024, a court-authorized FBI operation took control of botnet infrastructure and removed malware from infected devices, while Lumen’s Black Lotus Labs blocked traffic to known operational infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The FBI and cybersecurity researchers have disrupted a massive Chinese botnet called “Raptor Train” that infected over 260,000 networking devices to target critical infrastructure in the US and in other countries.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Претходно, групата беше поврзана со ботнетот Raptor Train, составен од илјадници компромитирани уреди што се користат во мали канцеларии и домашни мрежи (SOHO), како и IoT-уреди.
Flax Typhoon was previously attributed to a botnet called Raptor Train that comprised thousands of compromised small office/home office (SOHO) and IoT devices.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Since May 2020, over 200,000 devices, including SOHO routers, NVR/DVR devices, NAS servers, and IP cameras, have been compromised and added to the Raptor Train botnet.
For example, China's Integrity Technology Group controlled and managed the so-called Raptor Train network, which in 2024 infected more than 200,000 devices worldwide, including small office home office (SOHO) routers, internet-connected web cameras and video recorders, plus firewalls and network-attached storage (NAS) devices.
The Raptor Train botnet, disrupted by the United States, offers a clear illustration of this contractor model. It was attributed to Chengdu-based Integrity Technology Group, found responsible for developing the botnet and therefore held partly accountable for intrusion activities attributed to Flax Typhoon.
The malware connected these thousands of infected devices into a botnet, controlled by Integrity Technology Group, which was used to conduct malicious cyber activity disguised as routine internet traffic from the infected consumer devices.
A majority of China-linked threat actors are using compromised routers and IoT devices worldwide, turning this gear into proxy networks to carry out further intrusions, steal sensitive data, and disrupt victim organizations’ operations.
...used to conduct malicious cyber activity disguised as routine internet traffic from the infected consumer devices... For the second time this year, we have disrupted a botnet used by PRC proxies to conceal their efforts to hack into networks in the U.S. and around the world...
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet built from routers, cameras, and storage devices and powered by an unnamed Mirai variant. Used to conceal espionage activity rather than primarily conduct DDoS. The article reports more than 260,000 devices and an FBI disruption in 2024.
An IoT and SOHO-device botnet associated with Flax Typhoon and operated by Integrity Technology Group. It used a Mirai variant and was managed through Sparrow. On June 5, 2024, more than 260,000 devices were actively infected, approximately 126,000 of them in the United States. It was disrupted in September 2024.
Integrity Technology Group's botnet, mentioned as background to the current disruption. The article states that US authorities disrupted it in 2024 but provides no further technical details.
Botnet of compromised SOHO and IoT devices associated with Flax Typhoon. It was disrupted through a U.S. court-authorized operation in September 2024. The article describes Integrity Technology Group's botnet infrastructure as supporting reconnaissance and vulnerability scanning.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.