For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
MooBot
MooBot is a botnet malware family and Mirai variant used to compromise internet-exposed edge and IoT devices.
Profile source: Mallory opens in a new tabMooBot
Family profile
MooBot is a botnet malware family and Mirai variant used to compromise internet-exposed edge and IoT devices. The content directly associates it with compromised Ubiquiti EdgeOS/EdgeRouter devices, TP-Link Archer AX21 routers via CVE-2023-1389, LILIN DVR devices via a 0-day vulnerability chain, vulnerable Cacti servers, and exploitation activity tied to CVE-2021-36260. Reported behavior includes downloading and executing architecture-specific ELF payloads, using shell scripts to fetch binaries, removing traces after execution, and participating in botnet-based DDoS activity. MooBot has also been used to proxy malicious traffic.
The malware is notably linked to a botnet of hundreds of compromised Ubiquiti EdgeOS routers that was originally built by cybercriminals and later repurposed by Russia’s GRU Unit 26165, tracked as APT28, Fancy Bear, Sednit, and Forest Blizzard. According to the content, APT28 used the MooBot-based router infrastructure beginning in April 2022 for cyberespionage support functions including proxying malicious traffic, relaying stolen Microsoft Exchange/Outlook authentication hashes, hosting phishing pages on residential IP addresses, running custom Python scripts on hijacked routers, harvesting webmail credentials, stealing NTLMv2 digests, and redirecting phishing traffic through custom routing rules. Victims mentioned in connection with the GRU use of this infrastructure included U.S. and foreign governments, military entities, security organizations, corporate organizations, embassies, defense contractors, researchers, and political parties.
Law enforcement disrupted the MooBot botnet in February 2024 in the FBI-led Operation Dying Ember. The content states the FBI remotely accessed infected routers, deleted MooBot and other malicious files, and temporarily modified firewall rules to block further GRU access without disrupting normal router functionality or collecting user content.
Additional reporting in the content ties MooBot to broader botnet exploitation and DDoS ecosystems. It was observed among botnets exploiting TP-Link Archer AX21 routers through CVE-2023-1389, where MooBot fetched and executed scripts that downloaded ELF files, ran architecture-specific payloads, and removed traces. It was also observed in DDoS activity during the Russia-Ukraine conflict alongside Mirai, Gafgyt, IRCBot, and RipprBot, and in propagation through LILIN DVR vulnerabilities. The content also notes delivery of MooBot to internet-exposed Cacti servers through exploitation of CVE-2022-46169. Indicators and infrastructure explicitly mentioned include the registration bytes \x33\x66\x99, a MooBot C2 IP at 185.224.129.233, the domain goodpackets.cc, and the Moobot-related endpoint wor.wordtheminer.com:8725.
Reported operators
Threat actors
2 named in public reporting该组织重新利用了一个基于MooBot恶意软件构建的犯罪僵尸网络,于2022年4月控制了数百台Ubiquiti EdgeRouter路由器。
Exploited software
Vulnerabilities linked to MooBot
5 CVEsMITRE ATT&CK