Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
ID: 3ceccfc0-976c-5730-8bd4-7b8d37e02ca2
STIX ID: report--3ceccfc0-976c-5730-8bd4-7b8d37e02ca2
Feed Name: SecurityScorecard Blog
SecurityScorecard STRIKE mapped a 633-node anonymization/proxy-for-hire network named CanOworms that routes malicious campaigns for diverse customers—including commodity malware families (Remcos, Quasar, NanoCore, NetWire, AsyncRAT, Loki) and suspected state-linked actors—across unrelated hosting providers and countries to evade blocklists and attribution; the team identified members using a shared self-signed TLS certificate corroborated with JARM and JA4X fingerprints, observed live attack-shaped traffic (credential spraying-like SSH activity targeting edge devices), and published the certificate and TLS fingerprints as indicators while warning defenders that IP-based controls have limited effectiveness against this disposable, rented infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
