The Justice Department said the botnet used the Moobot malware, which was initially installed by “non-GRU cybercriminals” on Ubiquiti Edge OS routers. Then, the feds say, Russia’s GRU Military Unit 26165, (aka APT28, Fancy Bear, and a few other names), repurposed the network to harvest credentials of “targets of intelligence interest to the Russian government.”
The FBI used the same malware to wipe the routers and disable remote access.

















