Moobot is a Mirai-derived Linux IoT botnet first identified in 2019. It compromises poorly secured internet-facing networking equipment, routers, DVR/NVR systems, IP cameras, and other embedded devices, enrolling them into a command-and-control-managed botnet primarily used for distributed denial-of-service attacks. Supported attack modes include TCP SYN, UDP, ACK, and ACK-plus-PUSH flooding.
Moobot propagates through weak Telnet credentials and exploitation of publicly exposed command-injection and remote-code-execution vulnerabilities affecting IoT and networking products, including vulnerabilities in D-Link routers, Hikvision surveillance devices, LILIN DVR/NVR devices, and other embedded-device platforms. It uses architecture-specific ELF payloads to support diverse processor architectures common in embedded Linux environments. Variants have used obfuscated configuration data, altered packing signatures, DNS TXT-based command-and-control discovery, and SOCKS or Tor proxy infrastructure to complicate detection and infrastructure blocking. Some variants establish startup-based persistence and remove or rename deployed payloads after execution.
Recovered source code includes dormant functionality capable of downloading and executing an arbitrary ELF payload on an already compromised device, enabling operators to extend the botnet beyond its native DDoS capability. U.S. law enforcement disrupted a Moobot botnet in February 2024. The U.S. Department of Justice reported that cybercriminals operated Moobot and that APT28, a Russian GRU-linked threat actor, repurposed it on at least one occasion to deploy malware to previously compromised Ubiquiti EdgeOS routers, which were used to proxy malicious traffic in cyberespionage operations. Separately observed Moobot activity has been assessed as financially motivated DDoS-for-hire activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Internal Alien Labs research has identified new Moobot, a Mirai variant botnet, infrastructure scanning for known but uncommon vulnerabilities in Tenda routers.
Hikvision is a CVE CNA and quickly assigned the CVE number, CVE-2021-36260 and released a patch for the vulnerability on the same day as the threat researcher’s disclosure... During our analysis, we observed numerous payloads attempting to leverage this vulnerability... One payload in particular caught our attention. It tries to drop a downloader that exhibits infection behavior and that also executes Moobot... CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product. | It tries to drop a downloader that exhibits infection behavior and that also executes Moobot, which is a DDoS botnet based on Mirai.
The vulnerabilities exploited include: CVE-2022-28958: D-Link Remote Command Execution Vulnerability... The exploit targets a remote command execution vulnerability in the /shareport.php component. The component does not successfully sanitize the value of the HTTP parameter value, which can lead to arbitrary command execution. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
The vulnerabilities exploited include: CVE-2022-26258: D-Link Remote Command Execution Vulnerability... The exploit targets a command injection vulnerability in the /lan.asp component. The component does not successfully sanitize the value of the HTTP parameter DeviceName, which in turn can lead to arbitrary command execution. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
The vulnerabilities exploited include: CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability... The exploit works due to the older D-Link router's unsanitized use of the “service” parameters in requests made to the SOAP interface. The vulnerability can be exploited to allow unauthenticated remote code execution. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link... The vulnerabilities exploited include: CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability... The exploit targeting the older D-Link routers takes advantage of vulnerabilities in the HNAP SOAP interface. An attacker can perform code execution through a blind OS command injection. | The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.
The vulnerabilities we observed using Moobot are as follows: ... CVE-2017-8225 ... The Wireless IP Camera (P2P) | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The vulnerabilities we observed using Moobot are as follows: ... CVE-2020-8515 ... DrayTek Vigor router | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The vulnerabilities we observed using Moobot are as follows: ... CVE_2020_5722 ... Grandstream UCM6202 | Overview Moobot is a Mirai based botnet. We first discovered its activity in July 2019.
The botnet was originally built by criminals using the MooBot malware. APT28 used it over in April 2022 and included the botnet into three distinct uses.
Tracked as CVE-2023-1389, the flaw is a high-severity unauthenticated command injection problem in the locale API reachable through the TP-Link Archer AX21 web management interface. | Recently, we observed multiple attacks focusing on this year-old vulnerability, spotlighting botnets like Moobot, Miori, the Golang-based agent "AGoent," and the Gafgyt Variant.
"...allowing threat actors to breach internet-exposed Cacti servers to deliver botnet malware such as MooBot and ShellBot."
...there remain a lot of affected devices on the internet, which is somewhat surprising given years of exploitation by at least one botnet (Moobot).
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Moobot est un variant de Mirai, découvert en 2019 par Netlab 360. Il cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS.
Moobot est un variant de Mirai, découvert en 2019 par Netlab 360. Il cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS.
In February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by the Russian Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2021-36260 results from insufficient input validation, allowing unauthenticated users to inject malicious content into a <language> tag to trigger a command injection attack on a Hikvision product.
Un C2 actif est identifié : 162.141.92.192 (port TCP/14123) ... avec plus de 500 sessions d’attaque courtes observées en août 2026. Le panel StresD Pro+ repose sur un backend Node.js/Express sur WebSocket.
Moobot cible des équipements IoT à faible sécurité, se connecte à un serveur C2 et exécute des attaques DDoS. Le panel StresD Pro+ génère également du trafic d’attaque via un script Python implémentant un flooder Minecraft Bedrock Edition / RakNet.
245 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet IoT dérivé de Mirai qui compromet des équipements insuffisamment sécurisés, communique avec un serveur C2 et mène des attaques par déni de service distribué. Le code source exposé révèle aussi une capacité dormante de téléchargement et d'exécution de charges utiles.
An IoT botnet derived from Mirai that compromises low-security network devices, maintains persistent connections to C2 infrastructure, and launches network-flooding DDoS attacks. The recovered build also contains previously unreported but dormant functionality to download and execute arbitrary ELF payloads on compromised devices.
A botnet mentioned as prior context for threat actors targeting Ubiquiti devices; the content does not describe its functionality or connection to exploitation of the newly disclosed vulnerabilities.
A botnet composed of compromised Ubiquiti EdgeOS routers, used to proxy malicious traffic for GRU cyberespionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.