Skip to main content
News

Cyber News Rundown: 40,000 outdated devices infected by TheMoon botnet

Cyber News Rundown: 40,000 outdated devices infected by TheMoon botnet
Forum|alt.badge.img+7
  • Threat Research Analyst
  • 4 replies

Since the beginning of the year, researchers have been tracking the infection spread of TheMoon botnet, which has compromised over 40,000 routers and IoT devices across 88 different countries. In the first week of March alone, more than 6,000 outdated ASUS routers were impacted by TheMoon in the span of just 72 hours. The botnet enables the use of Faceless, an anonymous proxy that allows cybercriminals to conduct their operations without a trace.

Thousands of Microsoft Exchange servers exposed

Officials for the German Federal Office for Information Security have identified 17,000 Microsoft Exchange servers that are exposed to the Internet and have at least one known security vulnerability. Of the vulnerable servers discovered, 12% of them are running outdated versions of Exchange that have not received any security updates in at least a year. These findings revealed that 37% of all Microsoft Exchange servers in Germany are vulnerable and are being used actively across a broad range of industries.

 Hundreds of fraudsters arrested in UK crackdown

In a recent law enforcement crackdown, named Operation Henhouse, UK police have arrested more than 400 individuals that have been charged with various forms of financial fraud. According to law enforcement statistics, 40% of all known crime in the UK is related to fraud and amounts to over £6.8 billion in financial losses. Along with the individual arrests, the UK police have also seized millions in cash and several high-value assets, including a new Porsche and a new BMW.

Panera suffers extended IT outages

For the last few days, Panera bread company officials have been facing an extended outage to all their internal IT systems, forcing all store locations to complete cash transactions only. All customer-facing messages indicate that it is an unexpected outage, leading many to believe that it was caused by a cyberattack, though it has not been confirmed. Along with knocking out the POS systems, the company is unable to receive any incoming calls or complete online orders.

StrelaStealer campaign affects hundreds of organizations around the world

Researchers have been monitoring a new campaign from the email credential stealing malware, StrelaStealer, which has recently targeted organizations across the US and Europe. The campaign is initiated by sending out spam emails with malicious attachments to victim organizations, which deploys a JScript file upon downloading the attachment, then begins searching for email credentials while obfuscating itself to avoid detection.

Did this help you find an answer to your question?

7 replies

ProTruckDriver
Moderator

It looks like the miscreants never ending story. I’m glad they caught a few of them. Lock them up and throw away the key. Thanks for posting @ConnorM 


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 9223 replies
  • March 29, 2024

Thanks @ConnorM 


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Thank you @ConnorM 


Forum|alt.badge.img+1
  • New Member
  • 56 replies
  • April 1, 2024

Good information cheers Connor 


russell.harris
Popular Voice
Forum|alt.badge.img+5

Thanks as always @ConnorM 


tasystems
New Voice
Forum|alt.badge.img+8
  • New Voice
  • 156 replies
  • April 2, 2024

So, TheMoon botnet has been on the go since 2014 and more interestingly, you can hire the thing out so I have read for less than a dollar a day… I often wonder what great and useful things the creators of these could do for us all, instead of writing destructive things… but then, that’s probably a bit harder to do...

 


Robis
New Member
Forum|alt.badge.img+1
  • New Member
  • 74 replies
  • April 2, 2024

Thanks a lot Connor.