logo

TheMoon Botnet Resurfaces, Exploiting EoL Devices to Power Criminal Proxy

ID: 89e2b75e-fa2b-5326-a298-9748923cfdab

STIX ID: report--89e2b75e-fa2b-5326-a298-9748923cfdab

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-03-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Lumen's Black Lotus Labs observed the TheMoon botnet regain activity and grow to over 40,000 compromised EoL SOHO routers and IoT devices, which are being funneled into the Faceless criminal residential proxy service; the threat actors deploy a loader that fetches an ELF, a worm module and a ".sox" proxy component, modify iptables, perform NTP checks, and use the infrastructure to obfuscate malicious traffic for activities like password spraying and data exfiltration targeting the financial sector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.