logo

Cybersecurity Agencies Warn Ubiquiti EdgeRouter Users of APT28's MooBot Threat

ID: c553355f-644e-5329-9c46-565eb1d236bd

STIX ID: report--c553355f-644e-5329-9c46-565eb1d236bd

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-02-28

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A joint advisory warns that APT28 (MooBot) used compromised Ubiquiti EdgeRouters worldwide to deploy trojans and backdoors (including MASEPIE), harvest credentials (NTLMv2 digests), proxy traffic, and host phishing infrastructure; the group has exploited vulnerabilities such as CVE-2023-23397 and targeted multiple sectors and countries, with authorities recommending factory resets, firmware updates, credential changes, and firewall protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.