logo

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity

ID: 3ceccfc0-976c-5730-8bd4-7b8d37e02ca2

STIX ID: report--3ceccfc0-976c-5730-8bd4-7b8d37e02ca2

Feed Name: SecurityScorecard Blog

Threat Score
75/100

Date Published: 2026-08-05

Date Updated: 2026-08-06

...
...

SecurityScorecard STRIKE mapped a 633-node anonymization/proxy-for-hire network named CanOworms that routes malicious campaigns for diverse customers—including commodity malware families (Remcos, Quasar, NanoCore, NetWire, AsyncRAT, Loki) and suspected state-linked actors—across unrelated hosting providers and countries to evade blocklists and attribution; the team identified members using a shared self-signed TLS certificate corroborated with JARM and JA4X fingerprints, observed live attack-shaped traffic (credential spraying-like SSH activity targeting edge devices), and published the certificate and TLS fingerprints as indicators while warning defenders that IP-based controls have limited effectiveness against this disposable, rented infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.