TheMoon IoT Botnet
First observed in 2014, TheMoon is a modular Internet-of-Things (IoT) botnet targeting vulnerable routers within broadband networks.
Summary
First observed in 2014, TheMoon is a modular Internet-of-Things (IoT) botnet targeting vulnerable routers within broadband networks.
Affected platforms
The following platforms are known to be affected:
D-Link ADSL Router
Linksys routers- ASUS routers
- MikroTik routers
- D-Link routers
- GPON routers
Linksys E-Series routers
Threat details
The threat actors operating the botnet are scanning the Internet for insecure routers and performing brute-force attacks to gain access. Once compromised, TheMoon will deploy malware that can be installed on end devices connected to the network.
The developer of TheMoon has added a module which enables the botnet to turn devices using MIPS-based processors into SOCKS proxies. It is believed that threat actors are purchasing this proxy botnet as a service to be used in brute force attacks on websites, video advertisement fraud and traffic obfuscation.
Remediation steps
| Type | Step |
|---|---|
|
To avoid devices becoming part of an IoT botnet, organisations should:
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:45 pm