Security researchers reported that the Reaper IoT botnet, also tracked as IoTroop, was spreading by exploiting known vulnerabilities in Internet-connected routers and cameras instead of relying mainly on default passwords as Mirai did. Check Point said the malware had already compromised roughly one million organizations, while Netlab 360 described its scanning as more selective and stealthy than Mirai’s, raising concern that Reaper could assemble a significantly larger botnet for future DDoS attacks or other malicious operations.
The malware was linked to exploits for at least nine published flaws affecting devices from vendors including Linksys, Netgear, D-Link, AVTECH, and products using vulnerable custom GoAhead-based camera software. Referenced weaknesses included older Linksys router vulnerabilities and severe camera flaws such as the WIFICAM issues assigned CVE-2017-8221 through CVE-2017-8225, which enabled pre-authentication compromise and root-level code execution. Researchers warned that large numbers of exposed, unpatched IoT devices remained reachable from the Internet, creating conditions for another Mirai-scale disruption unless organizations rapidly patch, isolate, or replace affected systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Netlab 360 published research on the malware it called Reaper, describing it as more deliberate and stealthy in scanning than Mirai and noting it borrowed some Mirai code while differing in key behaviors. The research also provided indicators of compromise, control-network locations, and vendor-specific patch information.
Check Point said it had been tracking a large new IoT botnet it called IoTroop and warned it represented a rapidly spreading global campaign. The company estimated the malware had already infected about one million organizations and was exploiting known IoT vulnerabilities rather than mainly default credentials.
Pierre Kim reported multiple severe vulnerabilities in OEM Chinese P2P/WIFICAM IP cameras affecting more than 1,250 models sold under many brands. The advisory described a chain leading to pre-authentication remote code execution as root and noted roughly 185,000 vulnerable cameras indexed by Shodan.
A Mirai variant was used in the attack on Dyn, disrupting access to major online services including Twitter, SoundCloud, Spotify, and Reddit. The incident highlighted the Internet-scale risk posed by IoT botnets.
KrebsOnSecurity was struck by the first known Mirai botnet in a 620 Gbps distributed denial-of-service attack. The attack became one of the early high-profile demonstrations of Mirai's impact.
An advisory covering multiple vulnerabilities in Linksys E1500/E2500 devices was published. Krebs later cited Linksys among vendors whose flaws were exploited by Reaper.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourceresearch.checkpoint.com
Open sourcepierrekim.github.io
Open sources3cur1ty.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.