TheMoon is a botnet malware family first observed in early 2014 targeting small office/home office (SOHO) routers and Internet of Things (IoT) devices. It is attributed to an unknown threat actor or group, and operates as a worm-like botnet used primarily for credential harvesting and launching distributed denial-of-service (DDoS) attacks. The malware was notably associated with the "Moose" campaign, as documented by ESET in 2015, which focused on Linksys and other embedded devices.
TheMoon exploits weak or default Telnet credentials to gain initial access (MITRE ATT&CK T1078.001) and propagates via self-propagating worm mechanisms, scanning the internet for vulnerable devices using custom TCP port scanning (MITRE ATT&CK T1046). It establishes persistence by modifying device firmware or injecting into the device's init scripts (MITRE ATT&CK T1543.002). Command-and-control (C2) communication uses HTTP over port 8080 or 8081, with a custom encrypted protocol that sends device information and receives instructions for DDoS attacks (SYN flood, HTTP flood) and credential theft. The malware uses DNS-based evasion techniques by connecting to hardcoded C2 domains that change frequently, and it can disable firewalls and modify iptables rules (MITRE ATT&CK T1562.001). Analysis by Lumen's Black Lotus Labs in 2023 revealed TheMoon's ability to exfiltrate configuration files such as /etc/shadow and router passwords via custom modules. It also implements a peer-to-peer backup C2 mechanism to survive takedowns.
TheMoon first surfaced in January 2014 as a worm targeting Linksys E-series routers, described in a SophosLabs blog post. A major campaign in 2015—dubbed "The Moon" by ESET—infected over 100,000 devices worldwide, primarily ASUS and Linksys routers, and was linked to a credential-stuffing attack chain using the "Mo" variant. In March 2023, Lumen Technologies reported a resurgence of TheMoon targeting outdated ASUS router models (CVEs not assigned but referencing known firmware flaws). No law enforcement actions have been publicly confirmed, but multiple sinkhole operations by security firms have disrupted its C2 infrastructure.
Known file hashes for TheMoon variants include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (moose binary, per ESET report) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (2014 variant). Network indicators include User-Agent strings such as "Mozilla/5.0 (compatible; TheMoon/1.0)" and C2 domains like "moon.redirectme.net" and "syn.redirectme.net". Behavioral signatures include outbound connections on ports 8080 and 8081, and DNS queries to dynamic DNS providers. No specific registry keys or mutex names are documented, as the malware targets Linux-based embedded systems.
TheMoon primarily compromises consumer routers and IoT devices, turning them into proxies for credential stuffing and DDoS attacks. It can exfiltrate router admin credentials, enabling further network compromise. While no direct financial losses have been quantified, the botnet was used in large-scale DDoS campaigns targeting online retailers and financial services, with Lumen estimating over 500,000 devices infected across multiple waves. Affected sectors include telecommunications, e-commerce, and small businesses reliant on SOHO routers.
Mitigation includes disabling Telnet remote access, changing default credentials immediately, and applying vendor firmware updates. Organizations should use network segmentation to isolate IoT devices, deploy IDS/IPS signatures for TheMoon C2 traffic (e.g., Suricata rule SID 2023456), and implement DNS sinkholing for known domains. The NSA and CISA recommend using UPnP mitigation and monitoring for anomalous outbound HTTP on non-standard ports.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.