Cybercriminals Exploit Linux SSH Servers to Install TinyProxy and Sing-box Proxies
ID: 3905fb26-a96a-5ec3-b15f-b84e540fa2f8
STIX ID: report--3905fb26-a96a-5ec3-b15f-b84e540fa2f8
Feed Name: Cyber Press
ASEC observed a surge of attacks against Linux SSH servers where adversaries brute-force weak credentials and deploy legitimate proxy software (TinyProxy and Sing-box) via automated bash scripts (downloaded with wget/curl) to turn hosts into open proxy nodes; attackers modify configuration to allow 0.0.0.0/0 access on common ports and use these nodes for anonymized attacks or resale. The report provides IOCs (two MD5 hashes and two URLs), notes the use of open-source tooling to evade detection, and recommends enforcing strong passwords, patching, network segmentation, and IOC-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
