20-Year-Old Proxy Botnet Taken Down After Weekly Exploitation of 1,000 Unpatched Devices
ID: d5016c66-33fc-5371-97aa-d624cb9db7d9
STIX ID: report--d5016c66-33fc-5371-97aa-d624cb9db7d9
Feed Name: Cyber Press
Lumen’s Black Lotus Labs, in coordination with U.S. and Dutch law enforcement, disrupted a sophisticated proxy botnet active since at least 2004 that hijacked thousands of unpatched IoT and EoL devices to sell residential IP proxies to criminals; researchers observed ~1,000 weekly active bots, primary C2 servers in Turkey, HTTP (port 80) and UDP (port 1443) communications, and easy-access monetization via cryptocurrency, highlighting persistent risks from unpatched consumer devices despite the takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
