TheMoon Botnet Resurfaces, Exploiting EoL Devices to Power Criminal Proxy
ID: 89e2b75e-fa2b-5326-a298-9748923cfdab
STIX ID: report--89e2b75e-fa2b-5326-a298-9748923cfdab
Feed Name: The Hacker News
Lumen's Black Lotus Labs observed the TheMoon botnet regain activity and grow to over 40,000 compromised EoL SOHO routers and IoT devices, which are being funneled into the Faceless criminal residential proxy service; the threat actors deploy a loader that fetches an ELF, a worm module and a ".sox" proxy component, modify iptables, perform NTP checks, and use the infrastructure to obfuscate malicious traffic for activities like password spraying and data exfiltration targeting the financial sector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
