TheMoon Botnet Powers Faceless Proxy Service with 40,000 Compromised SOHO Routers Across 88 Countries

Researchers at Lumen Technologies Black Lotus Labs have identified a multi-year campaign linking the resurgent TheMoon botnet — first identified in 2014 and previously thought dormant — to the criminal proxy service Faceless, which provides anonymizing infrastructure to cybercriminals including operators of botnets like SolarMarker and IcedID. As of January and February 2024, TheMoon had grown to over 40,000 bots across 88 countries, with the network expanding at nearly 7,000 new Faceless users per week.

Infection Chain: EoL SOHO Routers as Proxy Nodes

TheMoon targets end-of-life small home/small office (SOHO) routers and IoT devices — hardware that rarely receives security updates and is frequently internet-exposed. The infection begins with a lightweight loader that checks for shell availability (/bin/bash, /bin/ash, or /bin/sh) before decrypting, dropping, and executing the main payload .nttpd. The payload sets iptable rules restricting inbound traffic to specific CIDR ranges controlled by the actors, then contacts NTP servers to verify internet connectivity and avoid sandbox detection before checking in with hardcoded C2 IPs on port 15194.

Two modular components extend the compromise: a worm module (.scz/.scn) that scans IP ranges for vulnerable web servers on ports 80 and 8080 and attempts to write the payload via echo commands; and a .sox proxy module that routes internet traffic from Faceless users through the infected device to the internet.

TheMoon to Faceless: The Proxy Pipeline

The .sox module initially contacts a hardcoded IP (assessed to be a decoy or legacy C2), then waits for the Moon C2 to deliver a .sox.twn file. Four bytes at a hardcoded offset within this file are read and used to replace the C2 address — resolving to a known Faceless C2 at 195.3.147[.]73. The bot then polls this address on a random port between 4210–4217 every five seconds until receiving a response, after which the Faceless C2 begins forwarding user requests through the infected device on port 501x.

Statistical analysis of Lumen's telemetry confirms the relationship: in a ten-day observation window, approximately 80% of bots communicating with Faceless C2s were also seen communicating with the Moon C2. Multiple Faceless C2s showed 90% bot overlap with TheMoon, and 40% of newly infected TheMoon bots contacted a Faceless C2 on the same day of infection.

A High-Profile March 2024 Campaign

In the first week of March 2024, Black Lotus Labs identified a campaign that targeted over 6,000 ASUS routers in less than 72 hours — a pace that illustrates the operational scale at which TheMoon's operators can expand the Faceless proxy pool on demand. Lumen has blocked all traffic to and from the dedicated infrastructure associated with both Faceless and TheMoon across its global network and has published IoCs to support broader disruption efforts.

Read the full analysis on IntelFusions