Moobot est un variant de Mirai, découvert en 2019 par Netlab 360. Il cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS.
MooBot
Moobot is a Mirai-derived Linux IoT botnet first identified in 2019.
Profile source: Mallory opens in a new tabMooBot
Family profile
Moobot is a Mirai-derived Linux IoT botnet first identified in 2019. It compromises poorly secured internet-facing networking equipment, routers, DVR/NVR systems, IP cameras, and other embedded devices, enrolling them into a command-and-control-managed botnet primarily used for distributed denial-of-service attacks. Supported attack modes include TCP SYN, UDP, ACK, and ACK-plus-PUSH flooding.
Moobot propagates through weak Telnet credentials and exploitation of publicly exposed command-injection and remote-code-execution vulnerabilities affecting IoT and networking products, including vulnerabilities in D-Link routers, Hikvision surveillance devices, LILIN DVR/NVR devices, and other embedded-device platforms. It uses architecture-specific ELF payloads to support diverse processor architectures common in embedded Linux environments. Variants have used obfuscated configuration data, altered packing signatures, DNS TXT-based command-and-control discovery, and SOCKS or Tor proxy infrastructure to complicate detection and infrastructure blocking. Some variants establish startup-based persistence and remove or rename deployed payloads after execution.
Recovered source code includes dormant functionality capable of downloading and executing an arbitrary ELF payload on an already compromised device, enabling operators to extend the botnet beyond its native DDoS capability. U.S. law enforcement disrupted a Moobot botnet in February 2024. The U.S. Department of Justice reported that cybercriminals operated Moobot and that APT28, a Russian GRU-linked threat actor, repurposed it on at least one occasion to deploy malware to previously compromised Ubiquiti EdgeOS routers, which were used to proxy malicious traffic in cyberespionage operations. Separately observed Moobot activity has been assessed as financially motivated DDoS-for-hire activity.
Capabilities
- Brute Force
- Ddos
- Defense Evasion
- Initial Access
- Persistence
- Scanning
Reported operators
Threat actors
4 named in public reportingMoobot est un variant de Mirai, découvert en 2019 par Netlab 360. Il cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS.
In February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by the Russian Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
Exploited software
Vulnerabilities linked to MooBot
16 CVEsMITRE ATT&CK