Linux/Moose is malware sophisticated enough to carry out DNS violations, DDoS attacks, and net penetrations… But why is it wasting its time on scams on…Instagram and other popular social networks?
ESET security researchers have identified a new worm targeting Linux-based routers that does not exploit any known vulnerabilities in the devices, but instead steals weak passwords through brute-force attacks.
The malware, which researchers call Linux/Moose, can be used for a variety of purposes – including DNS hijacking, DDoS attacks, network infiltrations – but so far attackers appear to be using it only for social media scams.
Moose monitors unencrypted network traffic and its main payload is a proxy service. This worm could be adapted to perform any kind of illegal activity. However, so far, it seems to be used to intercept HTTP cookies on social networking sites, in order to then perform illegal activities on them. But nothing more than fake “likes”, “follows” and creating new accounts.
This fact seems to be troubling ESET researchers. “Why all the effort to simply gain followers on Instagram?” asks researcher Olivier Bilodeau.
The prevailing theory is that there's money in this. Businesses pay marketing companies to boost their reach and activity on social networking sites. Software like Moose could be a powerful tool in the hands of marketers looking for quick fixes.
However, this was not the only thing that surprised ESET researchers, as Moose also lacks a persistence mechanism.
“What we’re thinking is, there’s no need for that,” Bilodeau says. He explains that it’s either too easy for attackers to regain access to a target router through brute-force attacks – or they achieve their goals so quickly that they don’t need to go back.

