logo

The evolution and abuse of proxy networks

ID: 7b9ed1fe-e61d-582b-ba93-bc4423b84894

STIX ID: report--7b9ed1fe-e61d-582b-ba93-bc4423b84894

Feed Name: Cisco Talos

Threat Score
82/100

Date Published: 2024-12-12

Date Updated: 2026-04-27

Author: Nick Biasini

...
...

This report outlines the growing abuse of proxy and proxyware networks—built from compromised SOHO routers, NAS, and IoT devices—by criminal and state-sponsored actors (e.g., VPNFilter, Cyclops Blink, Mirai-like botnets) to anonymize operations, conduct espionage, and launch large-scale attacks; it highlights recent enforcement actions (FBI takedown linked to China/Volt Typhoon), common exploitation methods (N-day vulnerabilities, weak credentials), and recommends stronger patching, credential hygiene, identity/behavioral controls, and managed-device enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.