logo

DoJ Breaks Russian Military Botnet in Fancy Bear Takedown

ID: 5cab073f-ca3c-5050-a7fd-206efcf2bee1

STIX ID: report--5cab073f-ca3c-5050-a7fd-206efcf2bee1

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-02-15

Date Updated: 2026-04-21

Author: Becky Bracken, Editor, Dark Reading

...
...

The Department of Justice disrupted a global botnet of hundreds of Ubiquiti Edge OS routers infected with Moobot that Russian GRU-affiliated actors (Fancy Bear/APT28) repurposed for espionage—conducting spear-phishing, credential harvesting, and other operations. Law enforcement temporarily removed malicious files, copied and deleted stolen data, and recommends affected users factory-reset routers and change default administrator passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.