{"id":3864,"date":"2025-05-10T10:03:55","date_gmt":"2025-05-10T10:03:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/10\/20-years-old-proxy-botnet-network-dismantled-that-exploits-1000-unique-unpatched-devices-weekly\/"},"modified":"2025-05-10T10:03:55","modified_gmt":"2025-05-10T10:03:55","slug":"20-years-old-proxy-botnet-network-dismantled-that-exploits-1000-unique-unpatched-devices-weekly","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/10\/20-years-old-proxy-botnet-network-dismantled-that-exploits-1000-unique-unpatched-devices-weekly\/","title":{"rendered":"20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly"},"content":{"rendered":"<p>    20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In a coordinated effort, Lumen Technologies\u2019 Black Lotus Labs, the U.S. Department of Justice (DOJ), the Federal Bureau of Investigation (<a href=\"https:\/\/www.ic3.gov\/CSA\/2025\/250507.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">FBI<\/a>), and the Dutch National Police have dismantled a sophisticated criminal proxy network that has operated since 2004. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiz_Wz2wjuKidOFYiosh1aC_Ja3kLmvnuJZeKHXlN5M4dJSwZYgM0X9L3vCAxe2U9BVXqCRzAbMAmQUGM_hk42xkCAyE8w-3LoqQR1pMuRdYGjGUQs0febVq3bXSpOiIbv1-k5yUnhUJgzHG3ELX9atAlMgljhzAlXoviecKcjkhOLQKGVgAHj0JQnSlpiH\/s16000\/socks1.jpg?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\"><em>Proxy network homepage<\/em><\/figcaption><\/figure>\n<\/div>\n<p>The botnet, tracked by Black Lotus Labs for over a year, infected thousands of <a href=\"https:\/\/cybersecuritynews.com\/can-vpns-protect-smart-homes-and-connected-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">Internet of Things<\/a> (IoT) and end-of-life (EoL) devices, creating a veil of anonymity for malicious actors engaging in activities such as ad fraud, DDoS attacks, brute-forcing, and data exploitation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Botnet Operations and Infrastructure<\/strong><\/h2>\n<p>The botnet, powered by malware targeting unpatched IoT and small office\/home office (SOHO) devices in residential IP spaces, maintained an average of 1,000 unique bots weekly, communicating with command-and-control (C2) servers located in Turkey. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjSSXPcLPDJzvp2Kip0UnkS5lKbzAHf6pTGvp_HlisNrpOx-10yH_7t7ny_iFk8-SeKVZC0St3bJPc59RMKqGaOQg8MyFtBZGfuDqW7Km_LlxNgFvqekn-BnmcIcbj8vSec-K_eYzzgGmL98FA84YPnlORI5Lpp-y31yL-UzGBsTnT2mZI43pcAZ5dQ9ivP\/s16000\/socks3.jpg?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\"><em>Command and control infrastructure<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Over 50% of the infected devices were in the United States, with Canada and Ecuador following as significant infection hubs. The botnet\u2019s operators claimed a daily pool of 7,000 proxies, though Black Lotus Labs\u2019 telemetry suggests a smaller but highly effective network.<\/p>\n<p>The C2 infrastructure comprised five servers, four of which used HTTP port 80 for victim communication, while one leveraged UDP port 1443 for data collection. <\/p>\n<p>The botnet\u2019s longevity and low detection rate only 10% of its proxies were flagged by tools like VirusTotal stemmed from its focus on EoL devices, which lack vendor support and cannot be patched. <\/p>\n<p>By exploiting known vulnerabilities rather than zero-day flaws, the operators maintained bot lifecycles averaging over a week, ensuring stability and anonymity for users.<\/p>\n<p>According to the Lumen <a href=\"https:\/\/blog.lumen.com\/black-lotus-labs-helps-demolish-major-criminal-proxy-network\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a>, \u201ca wide variety of infected IoT device types, indicating this botnet is likely using several exploits to obtain new victims, though we do not assess the operators are using zero or one-day vulnerabilities at this time.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><strong>Proxy-as-a-Service Model<\/strong><\/h2>\n<p>The proxy service operated on a \u201crent-a-proxy\u201d model, accepting cryptocurrency payments and providing users with IP addresses and ports valid for 24 hours. <\/p>\n<p>Notably, the service required no authentication, allowing unrestricted access to proxies once discovered, a tactic reminiscent of other botnets like NSOCKS and Faceless.<\/p>\n<p> This open-access policy amplified the botnet\u2019s threat, enabling a wide range of malicious actors to exploit it for free. The operators also performed deny-list checks, ensuring proxies evaded common monitoring tools, further complicating detection.<\/p>\n<p>Lumen disrupted the botnet by null-routing all traffic to and from its <a href=\"https:\/\/cybersecuritynews.com\/cloudsorcerer-apt-cloud-services\/\" target=\"_blank\" rel=\"noreferrer noopener\">C2 servers<\/a> across its global backbone, effectively dismantling the known infrastructure. <\/p>\n<p>The operation was supported by intelligence from Spur and built on earlier findings from CERT Orange Polska\u2019s 2023 report. Black Lotus Labs has published indicators of compromise (IoCs) and C2 details on its <a href=\"https:\/\/github.com\/blacklotuslabs\/IOCs\/blob\/main\/socks_IOCs.txt\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitHub page<\/a> to aid defenders.<\/p>\n<p>Proxy botnets exploiting residential IPs remain a persistent threat, particularly as EoL devices and IoT adoption grow. <\/p>\n<p>Black Lotus Labs highlighted the challenge of detecting such traffic, which blends seamlessly with legitimate residential activity. The firm recommends that corporate defenders monitor for suspicious login attempts, block known proxy IPs, and deploy advanced countermeasures.<\/p>\n<p>For consumers, best practices include rebooting routers, applying security updates, replacing EoL devices, and securing management interfaces.<\/p>\n<p class=\"has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><code><strong>Are you from the SOC and DFIR Teams? \u2013 Analyse Real time Malware Incidents with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/app.any.run\/?utm_source=csn_may&amp;utm_medium=article&amp;utm_campaign=mamona_analysis&amp;utm_term=090525&amp;utm_content=linktoregistration#register\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/p>\n<p>Lumen commended the FBI and Dutch National Police for their roles in the takedown and emphasized ongoing collaboration with law enforcement to target similar networks.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/20-years-old-proxy-botnet-network-dismantled\/\">20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Balaji N<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/20-years-old-proxy-botnet-network-dismantled\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly In a coordinated effort, Lumen Technologies\u2019 Black Lotus Labs, the U.S. Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), and the Dutch National Police have dismantled a sophisticated criminal proxy network that has operated since 2004. Proxy network homepage [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-3864","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3864"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3864"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3864\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}