logo

Botnet fueling residential proxies disrupted in cybercrime crackdown

ID: 485f9215-af61-5442-b802-45dab4743cff

STIX ID: report--485f9215-af61-5442-b802-45dab4743cff

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-19

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Lumen’s Black Lotus Labs mapped the Ngioweb botnet and found it provides roughly 80% of the ~35,000 proxies sold by the NSOCKS.net criminal proxy service across ~180 countries; the report describes a loader network, DGA-based C2s (with DNS TXT defenses), backconnect proxy servers, targeted vulnerable devices (Zyxel, Reolink, Alpha, increasing Netgear presence), and widespread abuse for DDoS, credential stuffing, phishing, and even by APT28. Industry partners are actively blocking known C2s and publishing IOCs to disrupt the operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.