MooBot is a Mirai-based botnet malware family active since at least 2019 that targets internet-exposed Linux-based routers, DVR/NVR appliances, IP cameras, and other embedded networking devices. It is primarily used to conscript compromised devices into a distributed denial-of-service botnet, and multiple campaigns have shown it spreading through both exploitation of public-facing vulnerabilities and brute forcing of weak credentials on exposed management services.
MooBot has been observed exploiting a broad set of known and, at times, previously undisclosed command-injection and remote-code-execution flaws in edge devices from multiple vendors, including D-Link routers, Hikvision products, TP-Link routers, Tenda routers, Ubiquiti EdgeRouter devices, LILIN DVR/NVR systems, UNIX-based CCTV DVR/NVR devices, GPON equipment, AVTECH devices, Huawei HG532 routers, DrayTek routers, Grandstream appliances, TVT OEM devices, ThinkPHP deployments, and exposed Android Debug Bridge services. Campaigns have also used Telnet, SSH, and default or weak credentials for propagation. Delivery commonly involves a shell-script or small downloader that retrieves architecture-specific ELF payloads for a wide range of CPU types.
Behaviorally, MooBot retains strong lineage with Mirai, including embedded credential lists, bot registration and heartbeat logic, and command parsing for attack execution, while introducing family-specific changes such as alternate configuration obfuscation and distinctive registration markers. Samples have been documented deleting their original executable, renaming or masquerading processes to appear legitimate, killing competing botnet processes, removing traces, altering firewall rules to hinder remote recovery, and in some cases establishing persistence through startup scripts or scheduled tasks. Some variants have used packing, modified UPX markers, encrypted resources, DNS TXT-based command-and-control discovery, SOCKS or Tor proxying, and Tor-based command-and-control channels to complicate analysis and detection.
The malware’s core operational purpose is DDoS. Observed attack support includes multiple TCP, UDP, GRE, HTTP, DNS, and amplification-style flooding methods, with reporting linking MooBot to attacks against government, military, financial, and commercial targets. It has also been associated with large-scale exploitation waves against vulnerable routers and IoT devices and with scanning activity for uncommon router vulnerabilities.
Beyond criminal botnet use, MooBot has also been repurposed in state-linked operations. Public reporting states that APT28, also known as Fancy Bear or Forest Blizzard and attributed to Russia’s GRU, took over a criminal MooBot-based botnet of compromised Ubiquiti EdgeRouter devices in 2022 and used it to proxy malicious traffic, relay stolen authentication material, host phishing infrastructure, and support cyber-espionage activity. That router botnet was later disrupted by law enforcement in 2024. Overall, MooBot is best understood as a long-running Mirai-derived Linux botnet family focused on rapid exploitation of exposed edge devices and flexible DDoS operations, with occasional reuse as covert infrastructure by higher-end threat actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Hikvision is a CVE CNA and quickly assigned the CVE number, CVE-2021-36260 and released a patch for the vulnerability on the same day as the threat researcher’s disclosure... During our analysis, we observed numerous payloads attempting to leverage this vulnerability... One payload in particular caught our attention. It tries to drop a downloader that exhibits infection behavior and that also executes Moobot... CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product. | It tries to drop a downloader that exhibits infection behavior and that also executes Moobot, which is a DDoS botnet based on Mirai.
The vulnerabilities exploited include: CVE-2022-28958: D-Link Remote Command Execution Vulnerability... The exploit targets a remote command execution vulnerability in the /shareport.php component. The component does not successfully sanitize the value of the HTTP parameter value, which can lead to arbitrary command execution. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
The vulnerabilities exploited include: CVE-2022-26258: D-Link Remote Command Execution Vulnerability... The exploit targets a command injection vulnerability in the /lan.asp component. The component does not successfully sanitize the value of the HTTP parameter DeviceName, which in turn can lead to arbitrary command execution. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
The vulnerabilities exploited include: CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability... The exploit works due to the older D-Link router's unsanitized use of the “service” parameters in requests made to the SOAP interface. The vulnerability can be exploited to allow unauthenticated remote code execution. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link... The vulnerabilities exploited include: CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability... The exploit targeting the older D-Link routers takes advantage of vulnerabilities in the HNAP SOAP interface. An attacker can perform code execution through a blind OS command injection. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
The vulnerabilities we observed using Moobot are as follows: ... CVE-2017-8225 ... The Wireless IP Camera (P2P) | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The vulnerabilities we observed using Moobot are as follows: ... CVE-2020-8515 ... DrayTek Vigor router | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The vulnerabilities we observed using Moobot are as follows: ... CVE_2020_5722 ... Grandstream UCM6202 | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The botnet was originally built by criminals using the MooBot malware. APT28 used it over in April 2022 and included the botnet into three distinct uses.
Tracked as CVE-2023-1389, the flaw is a high-severity unauthenticated command injection problem in the locale API reachable through the TP-Link Archer AX21 web management interface. | Recently, we observed multiple attacks focusing on this year-old vulnerability, spotlighting botnets like Moobot, Miori, the Golang-based agent "AGoent," and the Gafgyt Variant.
"...allowing threat actors to breach internet-exposed Cacti servers to deliver botnet malware such as MooBot and ShellBot."
...there remain a lot of affected devices on the internet, which is somewhat surprising given years of exploitation by at least one botnet (Moobot).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2024-12-31 ⋅ Maverits ⋅ APT28 the long hand of Russian interests MooBot STEELHOOK MASEPIE HATVIBE CredoMap Headlace OCEANMAP
For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product.
After getting the C2 server (life.zerobytes[.]cc) from its configuration, it starts sending heartbeat (\x00\x00) packets and then waits for the next control command from the C2 server.
Once the victim system receives the command, it starts a DDoS attack to a specific IP address and port number.
232 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware used to compromise SOHO routers, particularly Ubiquiti EdgeRouter devices, enabling DNS hijacking, credential harvesting, persistence via firmware modification, and use of the router as a proxy/C2 node.
Named malware/tool listed as part of APT28 operations; exact function is not described in the provided content.
A botnet composed of compromised Ubiquiti Edge OS routers and designed to proxy malicious traffic.
A botnet composed of compromised Ubiquiti Edge OS routers, used to proxy malicious traffic in cyberespionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.