logo

That home router botnet the Feds took down? Moscow's probably going to try again

ID: 9033a90e-90c0-5b2f-91fc-0e296c06ee2e

STIX ID: report--9033a90e-90c0-5b2f-91fc-0e296c06ee2e

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-02-28

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

A multinational advisory warns that Russia’s GRU (APT28/Fancy Bear) compromised Ubiquiti EdgeRouter devices using Moobot (a Mirai variant) to assemble ~1,000 routers into a botnet and deployed a custom Python backdoor, MASEPIE, to execute arbitrary commands, exfiltrate data, and establish reverse SSH tunnels; the advisory provides IoCs and urges owners to factory-reset devices, update firmware, change credentials, and apply WAN-side firewall rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.