Linux SSH Servers Compromised to Deploy Proxies (Campaign)
ID: 04483e50-1bb0-5844-a8fa-4d18264853f9
STIX ID: report--04483e50-1bb0-5844-a8fa-4d18264853f9
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-06-30
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
AhnLab observed attackers compromising Linux SSH servers to deploy proxy services. Attackers used scripts hosted on 0x0.st and GitHub to install TinyProxy and Sing-box via apt/yum/dnf, altered configurations (Allow 0.0.0.0/0) to expose services (e.g., port 8888), and performed system reconnaissance before installation, indicating misuse of legitimate proxy tools for illicit anonymized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
