Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption
released on 2026-08-28 @ 02:25:32 AM
A misconfigured open directory on IP address 86.53.111[.]212:8080 exposed critical details of an active cybercrime operation, including Moobot botnet source code, denial of service tools with attack records, and a fraudulent Chinese identity verification service. The exposed directory also contained StresD Pro+, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the collection date. The recovered Moobot source code revealed a previously unknown dormant download-and-execute functionality that represents the most plausible mechanism behind APT28's repurposing of Moobot for deploying malware to compromised devices. Despite a 2024 court-authorized disruption by the U.S. Department of Justice, Moobot remains active as of August 2026, with one active C2 server observed conducting over 500 short-duration attacks throughout the month, consistent with DDoS-as-a-service operations.