logo

Treasury Sanctions Creators of 911 S5 Proxy Botnet

ID: 37e81592-ede8-5c96-b77e-9de083022ebc

STIX ID: report--37e81592-ede8-5c96-b77e-9de083022ebc

Feed Name: Krebs on Security

Threat Score
78/100

Date Published: 2024-05-28

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

The U.S. Treasury and DOJ actions target operators of 911 S5, a botnet-powered residential proxy service that infected hundreds of thousands of Windows PCs and sold proxy access to cybercriminals; the service is tied to billions in fraudulent losses (including pandemic relief and EIDL fraud), money laundering via virtual currency and real estate, and was later observed resurfacing as Cloud Router/PaladinVPN.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.