One forgotten server setting gave a rare opportunity to look inside the existing criminal infrastructure when Censys specialists discovered in the open catalog the source code of the Moobot botnet, attack logs and tools of its operators. The finding showed that the malicious network continues to operate two years after the American authorities neutralized some of its infrastructure.
Moobot appeared in 2019 as one of the many variants of Mirai. The malicious program infects poorly protected network devices, connects them to the command server and allows you to use the resulting network for DDoS attacks. In February 2024, the U.S. Department of Justice announced the liquidation of part of the Moobot infrastructure, which the APT28 group adapted for its own operations.
Then the American authorities found that the operators of APT28 used infected routers Ubiquiti EdgeOS, on which the owners left standard administrator passwords. Through Moobot, attackers uploaded their own scripts and files to devices, turning other people's routers into cyber espionage infrastructure. During the operation, FBI officers removed malicious data and changed the rules of the firewall to temporarily block remote access.
The new find helps to understand how infected devices could receive additional malware. In the source code, Censys discovered a previously unknown feature that downloads and runs ELF files from a given server. In the found version of Moobot, the function was not used, but the developers provided the ability to transfer the command to download and execute an arbitrary file to infected devices.
Censys experts consider such a mechanism to be the most likely explanation for how APT28 could install its own components through Moobot. There is no direct evidence that the group used the function found. It is also unknown whether APT28 has received control through the vulnerability of the botnet infrastructure or agreed with its operators. The directory contained instructions for assembling Moobot in Chinese, so the source code was probably distributed between several groups.
Traces of activity show that Moobot did not disappear after surgery in 2024. In August 2026, Censys observed an active command server associated with the found infrastructure. During the month, the server handed over 500 short tasks for network attacks on various purposes. According to Censys, the current activity is connected with financially motivated intruders, and signs of communication of existing operators with state structures specialists did not find.
The open catalogue revealed other parts of the criminal infrastructure. Among the files was the StresD Pro+ panel with 16 registered accounts. The magazines have information about 32 attacks from six customers per day. The panel operated independently of Moobot and generated malicious traffic directly from the server, using a separate tool to overload the Minecraft Bedrock Edition servers.
On the same server, Censys found a fake Chinese service that tested the identity of users, decorated as a state system. The service transferred the names and numbers of identity cards to a third-party API, and through the section where it was possible to appeal the decision, could collect complete copies of user documents. The totality of the found tools shows that the open directory belonged not to an abandoned server with an archive code, but to an infrastructure that continued to serve existing criminal services in the summer of 2026.
Moobot appeared in 2019 as one of the many variants of Mirai. The malicious program infects poorly protected network devices, connects them to the command server and allows you to use the resulting network for DDoS attacks. In February 2024, the U.S. Department of Justice announced the liquidation of part of the Moobot infrastructure, which the APT28 group adapted for its own operations.
Then the American authorities found that the operators of APT28 used infected routers Ubiquiti EdgeOS, on which the owners left standard administrator passwords. Through Moobot, attackers uploaded their own scripts and files to devices, turning other people's routers into cyber espionage infrastructure. During the operation, FBI officers removed malicious data and changed the rules of the firewall to temporarily block remote access.
The new find helps to understand how infected devices could receive additional malware. In the source code, Censys discovered a previously unknown feature that downloads and runs ELF files from a given server. In the found version of Moobot, the function was not used, but the developers provided the ability to transfer the command to download and execute an arbitrary file to infected devices.
Censys experts consider such a mechanism to be the most likely explanation for how APT28 could install its own components through Moobot. There is no direct evidence that the group used the function found. It is also unknown whether APT28 has received control through the vulnerability of the botnet infrastructure or agreed with its operators. The directory contained instructions for assembling Moobot in Chinese, so the source code was probably distributed between several groups.
Traces of activity show that Moobot did not disappear after surgery in 2024. In August 2026, Censys observed an active command server associated with the found infrastructure. During the month, the server handed over 500 short tasks for network attacks on various purposes. According to Censys, the current activity is connected with financially motivated intruders, and signs of communication of existing operators with state structures specialists did not find.
The open catalogue revealed other parts of the criminal infrastructure. Among the files was the StresD Pro+ panel with 16 registered accounts. The magazines have information about 32 attacks from six customers per day. The panel operated independently of Moobot and generated malicious traffic directly from the server, using a separate tool to overload the Minecraft Bedrock Edition servers.
On the same server, Censys found a fake Chinese service that tested the identity of users, decorated as a state system. The service transferred the names and numbers of identity cards to a third-party API, and through the section where it was possible to appeal the decision, could collect complete copies of user documents. The totality of the found tools shows that the open directory belonged not to an abandoned server with an archive code, but to an infrastructure that continued to serve existing criminal services in the summer of 2026.