Malspace
On this episode, Chris Formosa and Steve Rudd of Lumen’s Black Lotus Labs share their research on a multi-year campaign targeting end-of-life (EoL) small home/small office (SOHO) routers and IoT devices, associated with an updated version of TheMoon malware. TheMoon, which emerged in 2014, has been operating quietly, while growing to over 40,000 bots from 88 countries in January and February of 2024. Show Notes * Darkside of TheMoon Blog Article [https://blog.lumen.com/the-darkside-of-themoon/] * Giving a Face to the Malware Proxy Service Faceless [https://krebsonsecurity.com/2023/04/giving-a-face-to-the-malware-proxy-service-faceless/] * IOCs on Github [https://github.com/blacklotuslabs/IOCs/blob/main/Moon_Faceless_IOCs.txt] * BSides Las Vegas Talk [https://www.youtube.com/live/ZY26xH9nim8?si=yTsNURAMLaZkmyPY&t=32042]
9 afleveringen
Reacties
0Wees de eerste die een reactie plaatst
Meld je nu aan en word lid van de Malspace community!