Botnet fueling residential proxies disrupted in cybercrime crackdown
ID: 485f9215-af61-5442-b802-45dab4743cff
STIX ID: report--485f9215-af61-5442-b802-45dab4743cff
Feed Name: Bleeping Computer
Lumen’s Black Lotus Labs mapped the Ngioweb botnet and found it provides roughly 80% of the ~35,000 proxies sold by the NSOCKS.net criminal proxy service across ~180 countries; the report describes a loader network, DGA-based C2s (with DNS TXT defenses), backconnect proxy servers, targeted vulnerable devices (Zyxel, Reolink, Alpha, increasing Netgear presence), and widespread abuse for DDoS, credential stuffing, phishing, and even by APT28. Industry partners are actively blocking known C2s and publishing IOCs to disrupt the operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
