logo

DOJ quietly removed Russian malware from routers in US homes and businesses

ID: ec8690e5-7f8a-50c7-972a-1beba1e30b3b

STIX ID: report--ec8690e5-7f8a-50c7-972a-1beba1e30b3b

Feed Name: Ars Technica Security

Threat Score
85/100

Date Published: 2024-02-16

Date Updated: 2026-04-19

Author: Kevin Purdy

...
...

More than 1,000 Ubiquiti EdgeOS routers that had not changed their default administrative passwords were infected with the Moobot malware and repurposed by Russian GRU-linked actors (Fancy Bear/APT28) into a botnet used for spearphishing and credential harvesting; in January 2024 the DOJ and FBI executed a court-authorized disruption (Operation Dying Ember) that removed the malware, copied and deleted botnet files, changed firewall rules to block remote management, and temporarily collected non-content routing information to expose GRU attempts to interfere.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.