SECURITY Signal 348
Exposed Directory Leaks Moobot Source Code and DDoS Tools Despite 2024 Court Disruption
Illustration only Photo by Elite Door And Glass on Unsplash
An open web directory exposed the source code for Moobot, a Mirai DDoS malware variant, alongside other DDoS tools and a suspected fraudulent ID verification service.
Security teams should be aware that Moobot remains active despite a court-authorized disruption in 2024. The exposure of its source code could lead to new variants or increased attack activity. This information comes from a single feed, so corroboration is currently lacking.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
An open web directory exposed the source code for Moobot, a variant of the Mirai DDoS malware.
The directory also contained additional DDoS tools and a suspected fraudulent Chinese ID verification service.
Attack logs indicate ongoing activity despite a court-authorized disruption in 2024.
THE CLUSTER