Artificial Intelligence | News | Insights | AiThority
[bsfp-cryptocurrency style=”widget-18″ align=”marquee” columns=”6″ coins=”selected” coins-count=”6″ coins-selected=”BTC,ETH,XRP,LTC,EOS,ADA,XLM,NEO,LTC,EOS,XEM,DASH,USDT,BNB,QTUM,XVG,ONT,ZEC,STEEM” currency=”USD” title=”Cryptocurrency Widget” show_title=”0″ icon=”” scheme=”light” bs-show-desktop=”1″ bs-show-tablet=”1″ bs-show-phone=”1″ custom-css-class=”” custom-id=”” css=”.vc_custom_1523079266073{margin-bottom: 0px !important;padding-top: 0px !important;padding-bottom: 0px !important;}”]

TheMoon Illustrates Evolving Threat of IoT Botnets

CenturyLink Threat Research Labs uncovers new module of botnet targeting ISPs

Botnets continue to find new ways to exploit the growing cache of internet-connected devices. According to new threat intelligence from CenturyLink, Inc., TheMoon is one of the latest examples of how far these threats have evolved. TheMoon is a modular botnet that targets vulnerabilities in routers within broadband networks. In recent months, CenturyLink Threat Research Labs discovered an undocumented module of TheMoon designed to allow the botnet to be leveraged as a service by other malicious actors.

Read More: NICE Actimize Announces IFM-X Integrated Fraud Management Platform Powered by Augmented Intelligence

“TheMoon is a stark reminder that the threat from IoT botnets continues to evolve,” said Mike Benjamin, head of CenturyLink’s Threat Research Labs. “Not only does TheMoon demonstrate the ability to distribute malicious modules of differing functionality, but it’s designed to function like a botnet as a service, enabling other malicious actors to use it for credential brute forcing, video advertisement fraud and general traffic obfuscation, among other uses.”

Read More: Unity Technologies Will Launch Artificial Intelligence Challenge Designed to Push Limits of Intelligent Systems

Key Takeaways

  • CenturyLink Threat Research Labs identified an undocumented module of TheMoon that is only deployed on MIPS devices, a common microprocessor architecture typically found in residential gateways and modems.
  • TheMoon’s new module turns an infected device into a SOCKS proxy, a service that can be used maliciously to circumnavigate internet filtering or obscure the source of internet traffic, allowing the botnet author to sell its proxy network as a service to others.
  • CenturyLink Threat Research Labs observed a video ad fraud operator leveraging TheMoon as a proxy service, impacting 19,000 unique URLs on 2,700 unique domains from a single server over a six-hour period.
  • CenturyLink blocked TheMoon infrastructure on its network to mitigate the risk to customers, in addition to notifying other network owners of potentially infected devices to help protect the internet.
  • As many recent exploits have used known vulnerabilities that only worked on machines or devices that were not patched in a timely manner, CenturyLink encourages consumers to regularly update their home router firmware and to check with their ISPs to determine when their routers should be replaced.

Read More: Interview With Sven Lubek, Managing Director at WeQ

4 Comments
  1. Copper recycling center says

    Copper alloy composition analysis Copper scrap product development Scrap metal repackaging
    Copper cable scrap properties, Scrap metal reclamation, Scrap copper procurement

  2. Scrap iron management says

    Scrap metal recovery plant Ferrous metal separation Iron salvage operations

    Ferrous material stakeholder engagement, Iron and steel waste disposal, Transport regulations for scrap metal handling

  3. Copper slab scrap procurement says

    Copper scrap product development Copper scrap pricing strategies Scrap metal market analysis
    Copper cable dealer, Metal recycling and repurposing, Copper scrap licensing

  4. Iron and steel recycling plant says

    Metal recovery and reclaiming solutions Ferrous material lean practices Iron scrap recycling depot

    Ferrous material recycling investment, Iron scrap inventory, Scrap metal logistics solutions

Leave A Reply

Your email address will not be published.