Researchers detailed how the Linux/Moose botnet compromised Linux-based routers and embedded IoT devices, then used those systems as proxy nodes to run large-scale social media fraud. The malware primarily abused weak or default credentials rather than a software exploit, infected devices from vendors including Actiontec, Hik Vision, Netgear, Synology, TP-Link, ZyXEL, and Zhone, and automated actions such as creating fake accounts, following users, liking posts, and viewing videos while staggering activity to mimic human behavior. Analysis indicated Instagram was a major target, and the malware also removed competing malware from infected routers and scanned for additional devices to compromise.
A broader investigation linked Linux/Moose to the commercial supply chain behind fake likes and followers, highlighting bulk reseller panels and software panel sellers as key enablers of the fraud ecosystem. Researchers found a whitelist of seven IP addresses in the malware that likely supported centralized fake-account management, suggesting coordination by the same actor rather than unrelated resellers. The reports said customer-facing sellers likely captured the highest margins, while upstream panel operators depended on bulk volume, and warned that infected routers could also be repurposed for DDoS, network reconnaissance, eavesdropping, and DNS hijacking beyond social-media manipulation.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
On 17 July 2018, a RiskIQ PassiveTotal query found 977 domains hosted on an OVH IP address associated with a large cluster of social media fraud reseller panels. Many of the domains appeared to be SMF reseller panels, reinforcing the scale of the supporting infrastructure.
At VB2018 in 2018, Masarah Paquet-Clouston and Olivier Bilodeau presented research linking Linux/Moose botnet activity to the wholesale social media fraud ecosystem. Their analysis found the botnet primarily targeted Instagram and suggested the seven whitelisted IPs were likely controlled by the same actor rather than separate resellers.
Around the end of April 2016, researchers observed activity moving from one set of Linux/Moose whitelisted IP addresses to another. Overlap in the Instagram accounts followed across the old and new IP groups suggested an infrastructure change by the same operator rather than different resellers.
On May 26, 2015, ESET published a technical analysis of Linux/Moose, a worm affecting Linux-based routers and other devices. The report said the malware spread via weak Telnet credentials rather than a software vulnerability and was used for social media fraud such as creating bogus accounts and automating follows, likes, and views.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.