Reaper, also known as IoTroop or IoT Troop, is an IoT botnet malware family publicly identified in October 2017. It compromises internet-connected devices, including consumer routers, IP cameras, and digital video recorders, and recruits them into a botnet. Reaper incorporates portions of Mirai source code but differs from the original Mirai by propagating through known software and firmware vulnerabilities rather than relying primarily on default-password attacks.
Analyzed samples contained exploits for at least nine vulnerabilities affecting devices from manufacturers including AVTECH, D-Link, Linksys, and Netgear, as well as devices using GoAhead embedded web-server software. Reaper scans the internet for susceptible systems and uses remote code execution and command-injection flaws to install and execute its payload. Its embedded Lua engine and accompanying scripts provide an extensible framework for attack logic and additional functionality. Its scanning is less aggressive than Mirai's. Early observations established device recruitment and propagation, but did not establish destructive attacks or an operational DDoS campaign.
This IoT malware family is distinct from the macOS SHub infostealer variant also named Reaper and from the historical Reaper program developed to remove Creeper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Reaper OS Command Injection CVE-2013-2678 Linksys E2500 | The vulnerability table lists 'Reaper Remote Code Execution CVE-2011-4723' for D-Link DIR-300 and 'Reaper OS Command Injection CVE-2013-2678' for Linksys E2500.
Reaper Remote Code Execution CVE-2011-4723 D-Link DIR-300 | The vulnerability table lists 'Reaper Remote Code Execution CVE-2011-4723' for D-Link DIR-300 and 'Reaper OS Command Injection CVE-2013-2678' for Linksys E2500.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The updated build, now called Reaper, spreads through fake websites that impersonate popular software... It uses a fake webpage to silently open your Mac’s Script Editor, pre-loaded with malicious code, and all a user has to do is click one button to unknowingly launch the infection.
Known as “IoT Troop” or “Reaper”, this threat targets IoT devices by exploiting vulnerabilities on internet-connected devices such as IP cameras and consumer grade routers.
Reaper drops a highly persistent User LaunchAgent script onto the host... The native LaunchAgent configuration is designed to trigger this GoogleUpdate beacon script automatically every 60 seconds, logging system details and checking in with the C2 server’s /api/bot/heartbeat endpoint.
the fake websites use a specific internet link format ( applescript:// ) to automatically open the built-in macOS Script Editor app. The hackers hide the malicious code inside the app by using extensive ASCII art and arbitrary whitespace injection to obfuscate the functional script sequences below the visible scroll boundary
The hackers hide the malicious code inside the app by using extensive ASCII art and arbitrary whitespace injection to obfuscate the functional script sequences below the visible scroll boundary of the graphical user interface.
the campaign distributing an updated version of SHub Stealer under the build tag Reaper... attackers used fake download pages for popular apps such as WeChat and Miro to target victims.
If the server returns a “code” payload, the script decodes it, writes it to /tmp/.c.sh , runs it with the current user’s privileges, and then deletes it.
Once the script runs, it displays a fake Apple security update message to trick the user into typing in their system password.
Earlier builds could already steal browser data, macOS Keychains, iCloud account data, and Telegram session information. The new version goes much further, now targeting Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion browsers, along with their extensions.
IoT malware spreads by scanning the Internet for other vulnerable devices... according to research released Oct. 20 by Chinese security firm Netlab 360, the scanning performed by the new IoT malware strain ... is not very aggressive, and is intended to spread much more deliberately than Mirai.
The malware also carries an AMOS-style Filegrabber that hunts through Desktop and Documents folders for valuable files, including .docx, .wallet, .key, .csv, .xls, and .json formats.
Once the script runs, it displays a fake Apple security update message to trick the user into typing in their system password.
Files are staged in /tmp/shub_random/ before being split into 10MB chunks and uploaded to the attacker’s server via curl.
These archives are transmitted via standard curl commands to an external command-and-control server at hebsbsbzjsjshduxbs.xyz/gate/chunk.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early program designed to detect and remove Creeper; often described as an early antivirus tool. Its authorship is not reliably established in the content.
The article lists Reaper among Mirai variants. It provides no Reaper-specific technical details or campaign information.
A macOS SHub variant that uses fake WeChat and Miro installers delivered via a typo-squatted Microsoft-themed domain, executes via AppleScript/Script Editor, establishes persistence through a fake Google Keystone LaunchAgent, steals files, browser credentials, developer keystrokes, and cryptocurrency wallet data, and maintains a persistent remote execution channel through heartbeat-delivered shell scripts.
A macOS infostealer variant that spoofs trusted brands, steals credentials, password manager data, browser data, crypto wallet data, developer files, Keychain/iCloud and Telegram data, grabs business/financial documents, injects cryptocurrency wallet applications for continued theft, and establishes persistence via a GoogleUpdate-themed LaunchAgent backdoor that can beacon to C2 and execute remote code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.