Skip to content

MooBot

Moobot is a Mirai-derived Linux IoT botnet first identified in 2019.

Profile source: Mallory opens in a new tab

MooBot

Family profile

Moobot is a Mirai-derived Linux IoT botnet first identified in 2019. It compromises poorly secured internet-facing networking equipment, routers, DVR/NVR systems, IP cameras, and other embedded devices, enrolling them into a command-and-control-managed botnet primarily used for distributed denial-of-service attacks. Supported attack modes include TCP SYN, UDP, ACK, and ACK-plus-PUSH flooding.

Moobot propagates through weak Telnet credentials and exploitation of publicly exposed command-injection and remote-code-execution vulnerabilities affecting IoT and networking products, including vulnerabilities in D-Link routers, Hikvision surveillance devices, LILIN DVR/NVR devices, and other embedded-device platforms. It uses architecture-specific ELF payloads to support diverse processor architectures common in embedded Linux environments. Variants have used obfuscated configuration data, altered packing signatures, DNS TXT-based command-and-control discovery, and SOCKS or Tor proxy infrastructure to complicate detection and infrastructure blocking. Some variants establish startup-based persistence and remove or rename deployed payloads after execution.

Recovered source code includes dormant functionality capable of downloading and executing an arbitrary ELF payload on an already compromised device, enabling operators to extend the botnet beyond its native DDoS capability. U.S. law enforcement disrupted a Moobot botnet in February 2024. The U.S. Department of Justice reported that cybercriminals operated Moobot and that APT28, a Russian GRU-linked threat actor, repurposed it on at least one occasion to deploy malware to previously compromised Ubiquiti EdgeOS routers, which were used to proxy malicious traffic in cyberespionage operations. Separately observed Moobot activity has been assessed as financially motivated DDoS-for-hire activity.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Initial Access
  • Persistence
  • Scanning

Reported operators

Threat actors

4 named in public reporting
Unit 26165

Moobot est un variant de Mirai, découvert en 2019 par Netlab 360. Il cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS.

APT28

Moobot est un variant de Mirai, découvert en 2019 par Netlab 360. Il cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS.

GRU

For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.

Exploited software

Vulnerabilities linked to MooBot

16 CVEs

MITRE ATT&CK

MooBot in ATT&CK

33 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.