U.S. Government Disrupts Russia-Linked Botnet Engaged in Cyber Espionage
ID: 565b8736-f1f1-525e-922a-f30636c421dc
STIX ID: report--565b8736-f1f1-525e-922a-f30636c421dc
Feed Name: The Hacker News
Threat Score
*Executive summary:* The U.S. Department of Justice and FBI disrupted a MooBot/Mirai-based botnet used by the Russia-linked APT28 (GRU) to compromise Ubiquiti SOHO routers across the United States, turning them into proxies to mask actor locations, harvest credentials and NTLMv2 hashes, host spear-phishing pages, and persist via SSH implants; court-authorized actions (operation "Dying Ember") copied and removed stolen data and altered firewall rules to block the attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
