Skip to main content
RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining operation cover
COMING SOONIntermediatePRO

RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining

A Mirai-derived DDoS botnet brute-forces SSH on an internet-exposed Linux edge gateway, persists an attacker SSH key in root's authorized_keys, pulls a Bash stager, and drops a single merged binary that fuses the RapperBot DDoS client with an embedded XMRig Monero miner. The bot registers with a hardcoded C2 over a custom binary protocol, floods an external victim with UDP/TCP/HTTP traffic, and quietly mines Monero through two proxy pools hosted on the C2 IP itself. Reconstruct the chain from SIEM, endpoint XDR, and perimeter firewall telemetry.

1h
7 tasks
50 points
Pro

Launches in 3 days

Aug 18, 2026

Tuesday, August 18, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

FirewallSIEMXDR

What you'll investigate

7 objectives unlock when this operation goes live.

1Incident brief
2Pin down the brute-force foothold
3Find the persistence the attacker left behind
4Recover the dropped payload's hash
5Separate the flood from the rest of the traffic
6Expose where the mining traffic really went
7Classify the dual impact technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 18, 2026, you can jump straight in.

Get Started Free