Moobot is an IoT-focused botnet operator associated with sustained exploitation of internet-exposed embedded devices, particularly Xiongmai-based video surveillance systems such as DVRs, NVRs, and IP cameras. The actor is linked to campaigns that abuse known vulnerabilities and weak/default credentials to gain initial access, deploy ELF malware across multiple CPU architectures, and conscript devices into distributed denial-of-service infrastructure. Moobot has been described as highly active and has been associated with malware branches including LeetHozer and a likely related later botnet referred to as Matryosh. Operationally, Moobot is tied to Linux/ELF bot malware that reuses elements of the Mirai ecosystem while diverging in command-and-control design and propagation. Reported Moobot-linked tooling has used Android Debug Bridge for propagation in some campaigns, targeted Android-like and other embedded Linux devices, and supported multiple processor architectures common in IoT environments. Observed command structures and attack modules indicate a primary emphasis on DDoS operations rather than data theft or espionage. Infrastructure and protocol design associated with Moobot-linked activity has included TOR-mediated command and control, including use of proxy relays and onion services, with similarities noted across related branches. The actor has been linked to exploitation of Xiongmai device vulnerabilities, including command-execution paths that enable follow-on access by starting remote administration services on compromised devices. Reporting also connects Moobot to exploitation patterns involving long-lived access on vulnerable surveillance hardware, making such devices useful both as botnet nodes and as footholds for further activity. Based on the available evidence, Moobot is best characterized as a financially or operationally motivated botnet actor focused on building and maintaining DDoS-capable IoT botnets rather than a nation-state espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
125 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet explicitly cited as exploiting Xiongmai devices over multiple years; associated in this write-up with exploitation of the port 34567 upgrade interface leading to command execution and opening telnetd for follow-on access.
Botnet explicitly cited as exploiting Xiongmai devices over multiple years; associated in this write-up with exploitation of the port 34567 upgrade interface leading to command execution and opening telnetd for follow-on access.
A botnet group suspected of developing the Matryosh botnet, using TOR-based C2 infrastructure and conducting DDoS-focused operations against Android-like devices via ADB propagation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.