Feds dismantle Russian GRU botnet built on 1,000-plus home, small biz routers
ID: 0317c430-fadb-5f09-9a0c-7e69b8b2a061
STIX ID: report--0317c430-fadb-5f09-9a0c-7e69b8b2a061
Feed Name: The Register (Security)
Threat Score
US authorities executed a court-authorized disruption of the Moobot botnet, a Mirai-derived malware network that Russian GRU-linked actors (APT28/Fancy Bear) used for phishing, spying, credential harvesting, and data theft against governments and strategic organizations; the FBI cleaned infected routers (well over a thousand), altered firewall rules to prevent re-hijacking, and temporarily collected routing metadata to trace GRU attempts to interfere.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
