Linux/Moose is a Linux malware family and IoT botnet that primarily targets consumer routers and other embedded Linux devices, especially MIPS- and ARM-based systems. It spreads mainly by brute-forcing weak or default Telnet credentials, with reporting also describing brute-force activity against SSH in related observations. The malware is memory-resident rather than persistent across reboot, but infected devices can be rapidly reinfected if exposed services and weak credentials remain in place.
Once installed, Linux/Moose turns compromised devices into proxy nodes and traffic interception points. It provides authenticated proxy services, including SOCKS and HTTP or HTTPS relaying, with access restricted to operator-controlled infrastructure through whitelisting. It also performs reconnaissance and scanning across the public Internet, nearby address space, and local networks, enabling lateral spread behind firewalls and NAT traversal into otherwise less reachable environments. The malware has been observed killing competing malware on infected devices to preserve limited system resources.
A core operational use of Linux/Moose has been social media fraud. Operators used infected residential and small-office devices as reputable-looking egress points to create fake accounts and automate follows, likes, views, and similar engagement on platforms including Instagram and other major social networks. Activity was designed to mimic human behavior and reduce platform detection. Linux/Moose has also been used to steal unencrypted network traffic and harvest HTTP cookies associated with social-network sessions, supporting session abuse and fraudulent account activity.
The malware’s command-and-control design evolved over time. Earlier variants used hardcoded infrastructure and a binary protocol, while later variants moved to encrypted command-line configuration and ASCII-printable data embedded in HTTP headers. Configuration could enable or disable functions such as scanning, sniffing, proxying, process killing, and DNS manipulation. Linux/Moose has been associated with consumer router compromises across multiple vendors and is notable for combining worm-like propagation, proxy infrastructure, traffic interception, and social-media abuse in a single embedded Linux threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The first thing we noticed when we got the new sample was that there was no more command and control (C&C) IP address inside the binary... The value is XORed with a static value... This config is encrypted by a simple XOR loop... also encoded in order to be printable in the HTTP headers.
We concluded that the botnet operator(s) are most likely using a tool to randomly spoof the User-Agents in the HTTP headers and that this tool is used consistently throughout all whitelisted IP addresses.
Every hour, it goes through every process entry under /proc/<pid>/ and searches thoroughly through the cmdline file... it will send a kill signal to any process that matches any of the blacklisted strings.
the malware could potentially be used for other activities - such as distributed denial-of-service attacks, targeted network exploration (where it works hard to dig deep past firewalls) and eavesdropping
Linux/Moose infects embedded Linux systems of MIPS or ARM architectures, specifically avoiding x86, such as routers and IoT devices. Just like other well-known IoT botnets, it has a worm-like behaviour, brute forcing Telnet credentials with simple combinations of usernames and passwords.
If there is no connection possible to TCP port 10073 ... it tries to connect to the Telnet service of that IP (TCP port 23). It will attempt to bruteforce the login prompt. | The commands are usually a 'download and execute' procedure... Moose will unscramble the commands and send them to the victim through the Telnet connection.
This whitelist controls who can interact with the bots’ proxy and is provided in the regular beacon messages between infected hosts and the command-and-control (C&C) servers.
Its main payload is a proxy service that can do SOCKSv4/v5, HTTP, HTTPS, using the infected devices to relay traffic. This allows the botnet operator(s) to hide behind thousands – if not hundreds of thousands – of clean IP addresses.
We’ve witnessed two main class of commands sent to perform the infection. The first one is a classic download and execute using wget.
infecting routers in order to commit social networking fraud, hijacking victims' internet connections in order to "like" posts and pages, "view" videos and "follow" other accounts.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux malware referenced as a behavioral comparison for credential brute-forcing and propagation.
Mentioned as a comparative Linux worm that spread by attacking Telnet logins.
Mentioned as a comparative example of a Linux worm spreading via credential attacks.
A Linux malware family targeting consumer routers and embedded devices. It steals unencrypted network traffic, harvests HTTP cookies from social networking sites, performs social-media fraud such as fake follows/views/likes, spreads via Telnet brute-forcing, and provides proxy services to the operator.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.