Linux /Moose is a malware family that initially targeted Linux-based consumer routers, but is also responsible for infecting other Linux-based embedded systems.
Once infected, compromised devices are ready to steal unencrypted network traffic and provide proxy services to the botnet operator. More information on this phenomenon can be found in the in-depth report “Dissecting Linux/Moose” on WeLiveSecurity.com.
In practice, these malicious capabilities are used to steal HTTP cookies in order to carry out fraudulent actions on Facebook, Twitter, Instagram, YouTube and other web-sites, which include generating illegal "follows", "views" and "likes".
“Linux/Moose is an innovation, considering that most embedded threats these days are used to perform DDoS attacks,” explains Olivier Bilodeau, Malware Researcher at ESET.
Furthermore, according to ESET researchers, this type of malware has the ability to reroute DNS traffic, which allows for man-in-the-middle attacks on the Internet.
The threat also appears to have network penetration capabilities beyond what is common with other malware that attacks routers. Moose also has DNS hijacking capabilities and kills processes of other malware families that compete for the limited resources offered by the infected embedded system.
"Given the rudimentary techniques Moose uses to gain access to other devices, it is unfortunate that embedded device security does not seem to be taken seriously by networking product manufacturers. We hope that our efforts will help to better understand the ways in which malicious actors attack their devices," concludes Bilodeau.
More information about Linux/Moose in the relevant blogpost on WeLiveSecurity.com, as well as in Graham Cluley's article: https://www.welivesecurity.com/2015/05/26/moose-router-worm.
