MooBot is a botnet malware family and Mirai variant used to compromise internet-exposed edge and IoT devices. The content directly associates it with compromised Ubiquiti EdgeOS/EdgeRouter devices, TP-Link Archer AX21 routers via CVE-2023-1389, LILIN DVR devices via a 0-day vulnerability chain, vulnerable Cacti servers, and exploitation activity tied to CVE-2021-36260. Reported behavior includes downloading and executing architecture-specific ELF payloads, using shell scripts to fetch binaries, removing traces after execution, and participating in botnet-based DDoS activity. MooBot has also been used to proxy malicious traffic.
The malware is notably linked to a botnet of hundreds of compromised Ubiquiti EdgeOS routers that was originally built by cybercriminals and later repurposed by Russia’s GRU Unit 26165, tracked as APT28, Fancy Bear, Sednit, and Forest Blizzard. According to the content, APT28 used the MooBot-based router infrastructure beginning in April 2022 for cyberespionage support functions including proxying malicious traffic, relaying stolen Microsoft Exchange/Outlook authentication hashes, hosting phishing pages on residential IP addresses, running custom Python scripts on hijacked routers, harvesting webmail credentials, stealing NTLMv2 digests, and redirecting phishing traffic through custom routing rules. Victims mentioned in connection with the GRU use of this infrastructure included U.S. and foreign governments, military entities, security organizations, corporate organizations, embassies, defense contractors, researchers, and political parties.
Law enforcement disrupted the MooBot botnet in February 2024 in the FBI-led Operation Dying Ember. The content states the FBI remotely accessed infected routers, deleted MooBot and other malicious files, and temporarily modified firewall rules to block further GRU access without disrupting normal router functionality or collecting user content.
Additional reporting in the content ties MooBot to broader botnet exploitation and DDoS ecosystems. It was observed among botnets exploiting TP-Link Archer AX21 routers through CVE-2023-1389, where MooBot fetched and executed scripts that downloaded ELF files, ran architecture-specific payloads, and removed traces. It was also observed in DDoS activity during the Russia-Ukraine conflict alongside Mirai, Gafgyt, IRCBot, and RipprBot, and in propagation through LILIN DVR vulnerabilities. The content also notes delivery of MooBot to internet-exposed Cacti servers through exploitation of CVE-2022-46169. Indicators and infrastructure explicitly mentioned include the registration bytes \x33\x66\x99, a MooBot C2 IP at 185.224.129.233, the domain goodpackets.cc, and the Moobot-related endpoint wor.wordtheminer.com:8725.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The botnet was originally built by criminals using the MooBot malware. APT28 used it over in April 2022 and included the botnet into three distinct uses.
The botnet is likely using CVE-2021-36260 to infect these targets... VulnCheck tracks 23 public exploits for this vulnerability, including a Metasploit module... included in CISA’s Known Exploited Vulnerabilities Catalog (KEV)... actively detected in the Shadow Server and GreyNoise honeypot networks.
Tracked as CVE-2023-1389, the flaw is a high-severity unauthenticated command injection problem in the locale API reachable through the TP-Link Archer AX21 web management interface. | Recently, we observed multiple attacks focusing on this year-old vulnerability, spotlighting botnets like Moobot, Miori, the Golang-based agent "AGoent," and the Gafgyt Variant.
"...allowing threat actors to breach internet-exposed Cacti servers to deliver botnet malware such as MooBot and ShellBot."
...there remain a lot of affected devices on the internet, which is somewhat surprising given years of exploitation by at least one botnet (Moobot).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Cybercriminals not linked with the GRU (Russian Military Intelligence) first infiltrated Ubiquiti Edge OS routers and deployed the Moobot malware, targeting Internet-exposed devices with widely known default administrator passwords.
Mirai variant: Downloads a script that subsequently fetches ELF files, which are compressed using UPX. Monitors and terminates packet analysis tools to avoid detection.
The binary protocol used by Condi to communicate with the C2 server is a modified version of that initially implemented in Mirai.
the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
Russian state-sponsored threat actors have also been observed enlisting compromised Ubiquiti Edge OS routers into a botnet designed to proxy malicious traffic.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet composed of compromised Ubiquiti Edge OS routers and designed to proxy malicious traffic.
A botnet composed of compromised Ubiquiti Edge OS routers, used to proxy malicious traffic in cyberespionage operations.
Malware used to build a criminal botnet that compromised routers and was later repurposed by APT28 for relaying stolen authentication hashes, hosting phishing pages, and running custom Python scripts on hijacked routers.
用于构建犯罪僵尸网络并控制路由器的恶意软件,被APT28重新利用以中继被盗认证哈希、托管钓鱼页面并运行自定义Python脚本。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.