The U.S. Department of Justice disrupted a botnet of thousands of compromised Ubiquiti EdgeRouters controlled by Russia’s GRU-linked APT28, also known as Fancy Bear, in the court-authorized Operation Dying Ember. The operation took place in January 2024 and was announced on February 15. APT28 commandeered routers previously infected by Moobot, a Mirai-derived criminal botnet, to support cyber operations worldwide as early as 2022. A subsequent joint advisory detailed credential harvesting, NTLM relay attacks, traffic proxying, spear-phishing infrastructure, stolen-data exfiltration, and command-and-control for MASEPIE malware. APT28 also exploited the Microsoft Outlook vulnerability CVE-2023-23397 to obtain NTLMv2 authentication material, including after a patch became available.
The disruption did not eliminate the need for owners to remediate compromised routers. Authorities recommended hardware factory resets, firmware upgrades, replacement of default credentials, and WAN-side firewall restrictions, alongside Outlook patching and protections against NTLM relay. Forescout separately recorded 4,815 login attempts using the default Ubiquiti username “ubnt” over approximately one year, underscoring persistent credential-based attacks on exposed devices. Security teams should inventory internet-facing routers, verify remediation, harden administrative access, and segment networks to reduce the risk of criminal IoT infrastructure being repurposed for state-sponsored operations.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
On February 27, 2024, the FBI, NSA, U.S. Cyber Command, and international partners published advisory JCSA-20240227-001, attributing the operations to Russia's GRU 85th Main Special Service Center. The advisory disclosed malware indicators and router exploitation techniques, and urged owners to factory-reset compromised devices, upgrade firmware, replace default credentials, and restrict remote management.
On February 15, 2024, the Justice Department announced Operation Dying Ember, revealing the January disruption of the router botnet controlled by Russia's APT28. APT28 had leveraged existing Moobot infections to install its own malicious files and support spear-phishing, credential harvesting, and stolen-data exfiltration.
During the first half of February 2024, Forescout observed 77 Moobot samples distributed through several IP addresses and nguyennghi[.]info. The samples contacted more than 480 IP addresses and several potentially malicious domains.
The U.S. Department of Justice conducted a disruption of the APT28-controlled botnet in January 2024. The botnet comprised thousands of hijacked Ubiquiti Edge OS routers repurposed as a global espionage platform.
APT28 wrote MASEPIE in December 2023, a Python backdoor capable of executing arbitrary commands on victim systems. The actor repeatedly used compromised EdgeRouters as command-and-control infrastructure for the malware.
In early 2023, APT28 developed and uploaded custom Python scripts to compromised Ubiquiti routers to collect and validate webmail credentials stolen through cross-site scripting and browser-in-the-browser spear-phishing campaigns. The scripts used an external CAPTCHA-solving service to automate login attempts.
The FBI found that APT28 exploited CVE-2023-23397 as early as 2022 to collect NTLMv2 authentication material from targeted Outlook accounts. The actor continued exploiting the vulnerability after Microsoft released a patch.
As early as 2022, APT28 used compromised Ubiquiti EdgeRouters against governments, militaries, and organizations across multiple sectors and countries. The actor accessed routers previously infected by the criminal Moobot botnet and repurposed them for credential harvesting, traffic proxying, and spear-phishing infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
forescout.com
Open sourcejustice.gov
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.