Security News TheMoon malware infects 6,000 ASUS routers in 72 hours for proxy service

vtqhtr413

Level 26
Thread author
Verified
Top Poster
Well-known
Aug 17, 2017
1,492
A new variant of "TheMoon" malware botnet has been spotted infecting thousands of outdated small office and home office (SOHO) routers and IoT devices in 88 countries.

TheMoon is linked to the "Faceless" proxy service, which uses some of the infected devices as proxies to route traffic for cybercriminals who wish to anonymize their malicious activities.

Black Lotus Labs researchers monitoring the latest TheMoon campaign, which started in early March 2024, have observed 6,000 ASUS routers being targeted in under 72 hours.

The threat analysts report that malware operations such as the IcedID and SolarMarker currently use the proxy botnet to obfuscate their online activity.
 
Mar 10, 2024
339

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,114

Jonny Quest

Level 16
Verified
Top Poster
Well-known
Mar 2, 2023
794
Thanks @vtqhtr413 for posting this timely thread, as I just bought a new Asus router on Amazon yesterday and that was one of the things I considered, if it was still a new enough model to be supported with firmware updates, which it is. Thanks also for the affirming follow-up replies, Practical Response and oldschool :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top