Malspace

The Darkside of TheMoon


Listen Later

On this episode, Chris Formosa and Steve Rudd of Lumen’s Black Lotus Labs share their research on a multi-year campaign targeting end-of-life (EoL) small home/small office (SOHO) routers and IoT devices, associated with an updated version of TheMoon malware. TheMoon, which emerged in 2014, has been operating quietly, while growing to over 40,000 bots from 88 countries in January and February of 2024.


Show Notes

  • Darkside of TheMoon Blog Article
  • Giving a Face to the Malware Proxy Service Faceless
  • IOCs on Github
  • BSides Las Vegas Talk


  • ...more
    View all episodesView all episodes
    Download on the App Store

    MalspaceBy Julien