Threats Tagged 'moobot'
View all threats tagged with 'moobot'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'moobot'
Click on any threat for detailed analysis and mitigation recommendations
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption 0 A misconfigured open directory on IP address 86.53.111[.]212:8080 exposed critical details of an active cybercrime operation, including Moobot botnet source code, denial of service tools with attack records, and a fraudulent Chinese identity verification service. The exposed directory also contained StresD Pro+, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the collection date. The recovered Moobot source code revealed a previously unknown dormant download-and-execute functionality that represents the most plausible mechanism behind APT28's repurposing of Moobot for deploying malware to compromised devices. Despite a 2024 court-authorized disruption by the U.S. Department of Justice, Moobot remains active as of August 2026, with one active C2 server observed conducting over 500 short-duration attacks throughout the month, consistent with DDoS-as-a-service operations. Join the discussion | AlienVault OTX General | 08/28/2026, 02:25:31 UTC Added: 08/28/2026, 08:52:30 UTC |
Showing 1 to 1 of 1 result