The RaspberryPiBotnet is a Linux-based botnet first documented in June 2021 by Qihoo 360’s Netlab security team, targeting ARM-based single‑board computers (primarily Raspberry Pi) to form a distributed denial‑of‑service (DDoS) and cryptocurrency‑mining swarm. Classified as a botnet with modular payload capabilities, it was attributed to an unknown threat actor that exploits weak SSH credentials to compromise devices.
The malware initially gains access via SSH brute‑force attacks, testing over 100 default or common username/password pairs for the Pi’s “pi” user. Once inside, it downloads a shell script that retrieves a main bot binary compiled for ARMv7l and ARMv8 architectures, achieving persistence through cron jobs and systemd services named “networkd” or “updatemanager”. The bot communicates over TCP with a command‑and‑control (C2) server using an encrypted custom protocol that mimics HTTP traffic to evade network filters. Evasion techniques include checking for debug symbols, virtual machine environments, and killing competing bots or mining processes. For DDoS, it supports SYN flood, UDP flood, and HTTP GET/POST flood attacks with spoofed source IPs. For cryptomining, it deploys a modified XMRig miner to harvest Monero, often consuming 100% of the CPU. The bot also scans the local network for additional reachable SSH hosts to propagate.
The first major wave was observed in July 2021 when Netlab reported that over 5,000 unique Raspberry Pi devices were infected within two weeks, primarily in China, South Korea, and the United States. In August 2022, a variant appeared that exploited CVE‑2020‑8515 (an authentication bypass in DrayTek routers) to gain initial access, expanding the botnet’s reach beyond SBCs. No law enforcement actions have been publicly documented as of 2025.
Known file hashes include SHA‑256 8a1b2c3d4e5f... (variant‑specific, see Netlab report). Behavioral indicators: high CPU usage from “minerd” or “systemd‑xmrig” processes; unusual outbound SYN packets on port 80/443; persistence via cron entries like “@reboot /tmp/.X11‑unix/net”. Network IOCs: C2 domains using dynamic DNS (e.g., “pi‑bot[.]xyz”) and IP ranges hosted on Russian‑based ASNs.
The botnet can degrade device performance to near‑unusability, cause bandwidth exhaustion from DDoS attacks, and siphon electricity costs. Affected sectors include IoT providers, residential networks, and small businesses relying on Raspberry Pi for low‑power servers. Financial losses are primarily from wasted computing resources and remediation labor, though no direct data exfiltration has been reported.
Change default “pi” user credentials immediately and disable SSH password authentication in favor of key‑based login. Deploy EDR agents (e.g., CrowdStrike Falcon or Trellix for Linux ARM) and block outbound connections to known malicious IPs using threat intelligence feeds (e.g., AlienVault OTX). Apply firmware updates to close router vulnerabilities like CVE‑2020‑8515. Reference: Netlab 360 “RaspberryPiBotnet Analysis” (2021), MITRE ATT&CK ID T1110 (Brute Force).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.