Researchers reported that newer variants of Linux/Moose continue to infect Linux-based consumer routers and other embedded Linux devices, where the malware steals unencrypted network traffic, harvests HTTP cookies, and abuses compromised systems as proxies to generate fraudulent social-media activity such as fake follows, views, and likes. The malware remains memory-resident, so a reboot stops execution, but it still propagates through Telnet credential brute-forcing against exposed devices.
The updated variants changed several operational details to hinder detection and analysis. Instead of embedding the command-and-control IP address directly in the binary, operators now pass it as an encrypted command-line argument, and the malware’s communications shifted from a binary protocol to an ASCII-printable format carried in HTTP headers. Researchers also observed a proxy listener change from TCP port 10073 to TCP port 20012, along with reduced password and whitelist lists compared with earlier versions, and published indicators of compromise including sample hashes, primary C2 infrastructure, and whitelist IP addresses.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
ESET released an updated analysis of Linux/Moose, including sample hashes, primary command-and-control IP addresses, and whitelist IP addresses for multiple versions.
The newer Linux/Moose proxy service changed its listening port from TCP 10073 used by previous variants to TCP 20012 while remaining memory-resident.
Compared with 2015 versions, the newer Linux/Moose samples cut their Telnet brute-force password list from around 300 pairs to about 10 and reduced the whitelist from about 50 IPs to about 10.
Newer Linux/Moose variants removed the command-and-control IP from the binary, passed it as an encrypted command-line argument, and shifted communications from a binary protocol to an ASCII-printable format embedded in HTTP headers.
A new Linux/Moose malware sample was obtained, indicating the malware family remained active after the earlier infrastructure disruption.
ESET published a whitepaper on the Linux/Moose malware family, documenting its targeting of Linux-based consumer routers and its use in traffic theft and social-media fraud.
After ESET published its 2015 whitepaper, the command-and-control servers associated with Linux/Moose went offline.
ESET and GoSecure collaborated for about a year to further investigate Linux/Moose, including its social-media fraud ecosystem that GoSecure called the "Ego Market."
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.