logo

20-Year-Old Proxy Botnet Taken Down After Weekly Exploitation of 1,000 Unpatched Devices

ID: d5016c66-33fc-5371-97aa-d624cb9db7d9

STIX ID: report--d5016c66-33fc-5371-97aa-d624cb9db7d9

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-05-12

Date Updated: 2026-04-19

Author: Mandvi

...
...

Lumen’s Black Lotus Labs, in coordination with U.S. and Dutch law enforcement, disrupted a sophisticated proxy botnet active since at least 2004 that hijacked thousands of unpatched IoT and EoL devices to sell residential IP proxies to criminals; researchers observed ~1,000 weekly active bots, primary C2 servers in Turkey, HTTP (port 80) and UDP (port 1443) communications, and easy-access monetization via cryptocurrency, highlighting persistent risks from unpatched consumer devices despite the takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.