
TheMoon malware has infected thousands of ASUS routers, with 6,000 routers compromised in 72 hours for a proxy service. The malware enrolls infected devices into Faceless, a service for anonymizing illicit activities. Around 80% of Faceless bots are in the United States, potentially engaging in criminal activities like password spraying and data exfiltration, especially targeting the financial sector. TheMoon botnet, previously inactive, has resurfaced, infecting over 40,000 routers and IoT devices to power Faceless, a criminal proxy service used for data theft, financial system attacks, and spreading malware like SolarMarker and IcedID.
TheMoon Botnet Resurfaces, Exploiting EoL Devices to Power Criminal Proxy https://t.co/JrO94bfbca
TheMoon Botnet Resurfaces, Exploiting EoL Devices to Power Criminal Proxy: https://t.co/69d3s6CQch by The Hacker News #infosec #cybersecurity #technology #news
🚨 ALERT: TheMoon botnet, previously thought to be inactive, is back. Over 40,000 hijacked routers & IoT devices power Faceless, a criminal proxy service used to steal data, attack financial systems, & spread malware like SolarMarker & IcedID. Read ➟ https://t.co/VynrRNz5sN
