Post

Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption

Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption

Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption

A misconfigured open directory on 86.53.111[.]212:8080 exposed critical details of an active cybercrime operator, including the Moobot botnet source code, other denial of service (DoS) tools with attack records, and a fraudulent identity verification service. This open web directory, exposed on 30 July 2026, held the source code for Moobot, a variant of the Mirai DDoS malware, alongside additional DDoS tools and a suspected fraudulent Chinese ID verification service. Moobot was first seen in 2019; in February 2024, it was the subject of a court-authorized disruption led by the U.S. Department of Justice. According to the U.S. Department of Justice, the Moobot botnet was run by cybercriminals and on at least one occasion was repurposed by APT28, attributed to Unit 26165 of the Russian intelligence service. Based on identified infrastructure and C2 monitoring, Censys ARC assesses that Moobot remains active in August 2026. 🚀

The code recovered from the open directory is unmistakably Moobot. Two signatures from prior research appear verbatim in the source: the C2 registration magic 0x336699 packet header and a 32-character seed, w5q6he3dbrsgmclkiu4to18npavj702f. Moobot’s supported commands critically add new functionality for deploying additional payloads, previously unknown before this source code disclosure. Two such routines are present in the recovered source; both are dormant. When this command is issued, it will task infected systems to send an HTTP GET /< ARCH> request to a hardcoded IP address and then write as executable, rename, fork, and execute the returned ELF file.

Also present on the host is “StresD Pro+”, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the day of collection. Despite sharing the same host as the Moobot source, StresD Pro operates independently. attack.py is a purpose-built Minecraft Bedrock Edition server flooder. Further analysis reveals deliberate monitoring of the panel’s own users; the frontend will capture each customer’s client IP, user-agent, screen resolution, CPU core count, and browser fingerprint. A Chinese government-themed web service, 公安身份核验系统 (“public security identity verification system”), was also present on TCP/3000 of the same host. This tool acts as a reseller wrapper around a third-party identity lookup API at api.cemg[.]xyz. An admin account created during installation used credentials identical to those hardcoded into StresD Pro.

The open directory on 86.53.111[.]212 provided a rare level of visibility into a live operation, presenting a snapshot of an active operation as of late July 2026. Recovered attack logs show activity on the day of collection, with customers connecting from Chinese IP addresses and directing attacks at China Mobile ranges. At the time of writing, Censys observes one active Moobot C2 server linked to this operation: 162.141.92[REDACTED BY DNB EDITORS TO GET PAST GOOGLE FILTERS, hosted on DeluxHost in Amsterdam. Throughout August 2026, over 500 short-duration attack tasking from this C2 server was observed; behavior consistent with DDoS-as-a-service operations. The dormant download-and-execute functionality represents the most plausible mechanism for APT28’s reported repurposing of Moobot. The current observed Moobot activity appears to be operated by a financially motivated actor with no assessed nexus to state-sponsored activity. 💻

Read full article\n

This post is licensed under CC BY 4.0 by the author.