The evolution and abuse of proxy networks
ID: 7b9ed1fe-e61d-582b-ba93-bc4423b84894
STIX ID: report--7b9ed1fe-e61d-582b-ba93-bc4423b84894
Feed Name: Cisco Talos
This report outlines the growing abuse of proxy and proxyware networks—built from compromised SOHO routers, NAS, and IoT devices—by criminal and state-sponsored actors (e.g., VPNFilter, Cyclops Blink, Mirai-like botnets) to anonymize operations, conduct espionage, and launch large-scale attacks; it highlights recent enforcement actions (FBI takedown linked to China/Volt Typhoon), common exploitation methods (N-day vulnerabilities, weak credentials), and recommends stronger patching, credential hygiene, identity/behavioral controls, and managed-device enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
