logo

TheMoon Malware Rises Again with Malicious Botnet for Hire

ID: d4674b35-377d-53a2-a3ff-cdbddafe0fa0

STIX ID: report--d4674b35-377d-53a2-a3ff-cdbddafe0fa0

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-03-29

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Researchers report that TheMoon has resurfaced with a botnet called Faceless — roughly 40,000 hijacked SOHO and IoT devices across 88 countries — being sold as a low-cost proxy service for cybercriminals to obscure traffic, facilitate data theft, and support DDoS and other attacks, representing a widespread risk to enterprises that leave such devices unmanaged.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.