That home router botnet the Feds took down? Moscow's probably going to try again
ID: 9033a90e-90c0-5b2f-91fc-0e296c06ee2e
STIX ID: report--9033a90e-90c0-5b2f-91fc-0e296c06ee2e
Feed Name: The Register (Security)
Threat Score
A multinational advisory warns that Russia’s GRU (APT28/Fancy Bear) compromised Ubiquiti EdgeRouter devices using Moobot (a Mirai variant) to assemble ~1,000 routers into a botnet and deployed a custom Python backdoor, MASEPIE, to execute arbitrary commands, exfiltrate data, and establish reverse SSH tunnels; the advisory provides IoCs and urges owners to factory-reset devices, update firmware, change credentials, and apply WAN-side firewall rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
