logo

U.S. Government Disrupts Russia-Linked Botnet Engaged in Cyber Espionage

ID: 565b8736-f1f1-525e-922a-f30636c421dc

STIX ID: report--565b8736-f1f1-525e-922a-f30636c421dc

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-02-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

*Executive summary:* The U.S. Department of Justice and FBI disrupted a MooBot/Mirai-based botnet used by the Russia-linked APT28 (GRU) to compromise Ubiquiti SOHO routers across the United States, turning them into proxies to mask actor locations, harvest credentials and NTLMv2 hashes, host spear-phishing pages, and persist via SSH implants; court-authorized actions (operation "Dying Ember") copied and removed stolen data and altered firewall rules to block the attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.