logo

Cybercriminals Exploit Linux SSH Servers to Install TinyProxy and Sing-box Proxies

ID: 3905fb26-a96a-5ec3-b15f-b84e540fa2f8

STIX ID: report--3905fb26-a96a-5ec3-b15f-b84e540fa2f8

Feed Name: Cyber Press

Threat Score
60/100

Date Published: 2025-07-02

Date Updated: 2026-04-19

Author: Mandvi

...
...

ASEC observed a surge of attacks against Linux SSH servers where adversaries brute-force weak credentials and deploy legitimate proxy software (TinyProxy and Sing-box) via automated bash scripts (downloaded with wget/curl) to turn hosts into open proxy nodes; attackers modify configuration to allow 0.0.0.0/0 access on common ports and use these nodes for anonymized attacks or resale. The report provides IOCs (two MD5 hashes and two URLs), notes the use of open-source tooling to evade detection, and recommends enforcing strong passwords, patching, network segmentation, and IOC-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.