TheMoon is an IoT-focused malware family and botnet associated primarily with the compromise of consumer and small-office routers, especially Linux-based embedded devices from vendors including Linksys and ASUS. First observed in the wild in 2013 and publicly documented in 2014, it is one of the older router malware families but has continued to evolve through updated variants and renewed operational use.
The malware is known for exploiting exposed router vulnerabilities to gain unauthenticated remote code execution and install architecture-specific payloads on embedded Linux systems. Reported exploitation has included flaws affecting Linksys routers and ASUS routers, with variants tailored to specific vulnerabilities and device families. TheMoon has also been linked to large-scale abuse of compromised routers as proxy infrastructure, including criminal residential proxy services built from infected edge devices.
Once installed, TheMoon can establish and preserve control of infected devices through defensive firewall manipulation. A notable behavior is the installation of iptables rules intended to block competing malware operators and prevent reinfection through the same exposed services. Some variants also open or manage ports needed for botnet communications and use peer-to-peer style message passing to relay registration and tasking information among infected nodes. Documented variants have included modules for time maintenance, network communications, and retrieval and execution of additional payloads.
TheMoon has been observed downloading and executing follow-on components, functioning as a router bot that can receive commands and fetch additional binaries for execution. Communications in at least some analyzed variants were unencrypted, while botnet control relied in part on restricting access at the firewall layer rather than on strong cryptographic authentication. The malware has also been described as continuing to receive updates that improve operational effectiveness and evasion.
The family has been associated with campaigns targeting vulnerable IoT devices broadly, including routers and IP-camera ecosystems, and has been observed competing with other IoT malware families for control of exposed devices. More recently, compromised routers running TheMoon were tied to proxy services such as 5socks, Anyproxy, and infrastructure linked to Faceless, underscoring its role not only as a classic botnet but also as an enabler of covert relay and proxy operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
we discussed the active detection of vulnerability CVE-2014-9583 in ASUS routers since June of this year... Figure 1 Exploitation of CVE-2014-9583 | This bot belongs to the TheMoon family of malware... Conclusion The TheMoon family was first discovered by SANS ISC in 2014. This family targets routers and installs malware by exploiting their vulnerabilities.
the next request hits /tmUnblock.cgi, a CGI endpoint in Linksys E-series routers carrying a critical command injection vulnerability (CVE-2025-34037). While documented since 2013 and historically exploited by "TheMoon" worm, this vulnerability continues to be actively weaponized by modern botnets. | .../tmUnblock.cgi, a CGI endpoint in Linksys E-series routers carrying a critical command injection vulnerability (CVE-2025-34037). While documented since 2013 and historically exploited by "TheMoon" worm, this vulnerability continues to be actively weaponized by modern botnets...
12 distinct techniques documented for this family, organized by ATT&CK tactic.
ttcp_ip=-h `" . $payload . "`& ... build_packet ( $host , $port , $vuln , "/tmp/c0d3z" ) | msfpayload linux/mipsle/shell_bind_tcp LPORT=4444 ... Attempting to get a shell... fsockopen ( $host , 4444
Embedded JavaScript code is extracted and sent to the command and control (C&C) server. The C&C server will execute JavaScript code and respond with a result... Bot sends a request to the C&C URL and gets a valid (shared) Google reCAPTCHA response token.
TheMoon ... >P2P Communication (Multi C&C) >External Socks5 Module >Support Plug-In
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm historically known for exploiting the Linksys /tmUnblock.cgi vulnerability on E-series routers.
Malware infecting older Linksys and Cisco routers and used to turn them into residential proxy infrastructure.
AryStinger follows the same pattern seen in campaigns such as AVrecon, SocksEscort, and TheMoon.
Referenced historically as malware used to turn routers into residential proxies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.