logo

GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations

ID: f15292eb-f9cb-55d7-9a0f-c8364fdccb8d

STIX ID: report--f15292eb-f9cb-55d7-9a0f-c8364fdccb8d

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Mayura Kathir

...
...

This report details an operational pivot by GRU-linked APT28 that weaponizes compromised CPE devices (Ubiquiti EdgeRouters and other home/SMB routers) and the MooBot botnet to create a resilient, geographically distributed edge platform for credential harvesting, proxying authentication flows (including OAuth and Net-NTLMv2 capture via zero-click Outlook chains), DNS/DHCP hijacking (FrostArmada), and lightweight on-router tooling; telemetry from vendors and joint advisories documents large scale impact (tens of thousands of unique IPs and hundreds of organizations) and persistent callbacks despite law enforcement takedowns, with recommendations to secure CPE, monitor anomalous DNS/NTLM behavior, and coordinate across vendors and CERTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.