TheMoon malware infects 6,000 ASUS routers in 72 hours for proxy service
ID: 7d5d7be1-94b8-53db-9d3e-bc272840cbf9
STIX ID: report--7d5d7be1-94b8-53db-9d3e-bc272840cbf9
Feed Name: Bleeping Computer
A new variant of the TheMoon botnet is actively compromising end-of-life ASUS routers and other IoT devices worldwide to build the Faceless proxy service, with Black Lotus Labs observing over 6,000 ASUS targets in under 72 hours; the malware drops a payload (.nttpd), applies iptables rules to protect the device, performs NTP checks to detect sandboxes, connects to hardcoded C2s, and can fetch modules (worm scanner, proxying .sox files), while the proxy network is used by criminal operators and other malware families such as IcedID and SolarMarker.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
