Moobot is a Mirai-derived botnet first identified in 2019 that compromises exposed Linux-based networking and IoT devices, including routers, IP cameras, and digital video recorders. Primarily used for distributed denial-of-service attacks, it spreads through Telnet credential brute-forcing, weak or default administrator credentials, and exploitation of device vulnerabilities. Documented targets include D-Link routers, Hikvision surveillance devices, TP-Link Archer AX21 routers, LILIN recorders, and Ubiquiti EdgeRouters. Exploited vulnerabilities include CVE-2015-2051, CVE-2021-36260, and CVE-2023-1389.
Moobot payloads are compiled for multiple processor architectures and connect to command-and-control infrastructure to register infected devices, send heartbeats, and receive attack instructions. Supported DDoS methods include SYN, UDP, ACK, and ACK-plus-PUSH flooding. Observed variants encrypt configuration data, disguise or randomize process names, delete their executable after launch, and terminate competing bot processes. Moobot-associated EdgeRouter compromises have included trojanized OpenSSH servers that bypass authentication and maintain access; rebooting affected routers does not remove the infection. Recovered source code also contains dormant routines for downloading and executing arbitrary ELF payloads, although those routines were not active in the recovered implementation.
Moobot has been used by financially motivated operators, including the Scar rental botnet operation. Separately, Russia's GRU-linked APT28 accessed Ubiquiti EdgeRouters previously infected by criminal Moobot operators and deployed additional tooling. APT28 repurposed those routers as infrastructure for traffic proxying, spearphishing, credential harvesting, and stolen-data exfiltration rather than relying solely on Moobot's native DDoS functionality. This infrastructure supported espionage against governments, militaries, and organizations across multiple industries. Operation Dying Ember disrupted the APT28-controlled router botnet in January 2024, with the operation publicly announced in February.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In particular, MooBot and Enemybot Malware targeting D-Link routers (CVE-2015-2051).
A command injection vulnerability exists in LILIN DVR devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of FTP and NTP Server fields. Injected shell commands execute with elevated privileges during subsequent configuration syncs. The vulnerability was exploited in the wild by Moobot botnets.
FortiGuard Labs observed several attacking bursts targeting Cacti and Realtek vulnerabilities ... and then spreading ShellBot and Moobot malware. ... CVE-2021-35394 (Realtek) and CVE-2022-46169 (Cacti).
A prime example is CVE-2023-1389, a command injection affecting TP-Link Archer AX21 routers, which is part of CISA KEV since 2023 and has been exploited by botnets such as AGoent, Gafgyt, Moobot, Mirai and others.
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin/net_html.cgi endpoint. The vulnerability has been exploited in the wild in conjunction with other issues by botnets like FBot and Moobot.
CVE-2022-46169 is a command injection vulnerability that allows an unauthenticated user to execute arbitrary code on a server running Cacti. The vulnerability resides in the “remote_agent.php” file, which can be accessed without authentication.
The botnet has been observed spreading via vulnerabilities on several IoT devices such as Tenda (CVE-2020-10987, CVE-2018-14558, CVE-2017-17215, CVE-2014-8361). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The botnet has been observed spreading via vulnerabilities on several IoT devices such as Tenda (CVE-2020-10987, CVE-2018-14558, CVE-2017-17215, CVE-2014-8361). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The botnet has been observed spreading via vulnerabilities on ... D-Link routers (CVE-2015-2051, CVE-2018-6530, CVE-2022-26258, CVE-2022-28958). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The botnet has been observed spreading via vulnerabilities on ... Hikvision cameras (CVE-2021-36260). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The botnet has been observed spreading via vulnerabilities on several IoT devices such as Tenda (CVE-2020-10987, CVE-2018-14558, CVE-2017-17215, CVE-2014-8361). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The botnet has been observed spreading via vulnerabilities on ... D-Link routers (CVE-2015-2051, CVE-2018-6530, CVE-2022-26258, CVE-2022-28958). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The botnet has been observed spreading via vulnerabilities on several IoT devices such as Tenda (CVE-2020-10987, CVE-2018-14558, CVE-2017-17215, CVE-2014-8361). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The botnet has been observed spreading via vulnerabilities on ... D-Link routers (CVE-2015-2051, CVE-2018-6530, CVE-2022-26258, CVE-2022-28958). | APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
The vulnerabilities we observed using Moobot are as follows: ... CVE-2017-8225 ... The Wireless IP Camera (P2P) | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The vulnerabilities we observed using Moobot are as follows: ... CVE-2020-8515 ... DrayTek Vigor router | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The vulnerabilities we observed using Moobot are as follows: ... CVE_2020_5722 ... Grandstream UCM6202 | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The botnet was originally built by criminals using the MooBot malware. APT28 used it over in April 2022 and included the botnet into three distinct uses.
...there remain a lot of affected devices on the internet, which is somewhat surprising given years of exploitation by at least one botnet (Moobot).
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28 then leveraged Moobot to download their own malicious files into the victim routers and repurposed the botnet for espionage, conducting spearphishing and credential harvesting campaigns as well as exfiltrating stolen data.
Analysis of the Scar rental botnet confirmed that the group contains not only the new botnet family found this time, but also other botnet families Mirai and Moobot.
Moobot est un variant de Mirai, découvert en 2019 par Netlab 360. Il cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS.
In February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by the Russian Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product.
Un C2 actif est identifié : 162.141.92.192 (port TCP/14123) ... avec plus de 500 sessions d’attaque courtes observées en août 2026. Le panel StresD Pro+ repose sur un backend Node.js/Express sur WebSocket.
Moobot cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS. Le panel StresD Pro+ génère également du trafic d’attaque via un script Python implémentant un flooder Minecraft Bedrock Edition / RakNet.
316 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet IoT dérivé de Mirai qui compromet des équipements insuffisamment sécurisés, communique avec un serveur C2 et mène des attaques par déni de service distribué. Le code source exposé révèle aussi une capacité dormante de téléchargement et d'exécution de charges utiles.
An IoT botnet derived from Mirai that compromises low-security network devices, maintains persistent connections to C2 infrastructure, and launches network-flooding DDoS attacks. The recovered build also contains previously unreported but dormant functionality to download and execute arbitrary ELF payloads on compromised devices.
A botnet mentioned as prior context for threat actors targeting Ubiquiti devices; the content does not describe its functionality or connection to exploitation of the newly disclosed vulnerabilities.
A botnet composed of compromised Ubiquiti EdgeOS routers, used to proxy malicious traffic for GRU cyberespionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.