logo

Exploited SSH Servers Offered in the Dark web as Proxy Pools

ID: f72b3266-8188-53c6-978e-aa08bca525c8

STIX ID: report--f72b3266-8188-53c6-978e-aa08bca525c8

Feed Name: Aqua Security Blog

Threat Score
60/100

Date Published: 2023-10-19

Date Updated: 2026-04-26

...
...

Aqua Nautilus researchers detail an active campaign abusing compromised SSH servers in cloud environments: attackers (often via brute-force or lateral SSH movement) convert instances into proxy nodes using SSH tunneling to relay SMTP and other traffic for spam, fraud, cryptomining, and intelligence collection. The report documents large-scale automated activity observed in honeypots (~1,000 attacks/day on a single honeypot), examples of malicious behavior and domains contacted, and provides detection and mitigation guidance (strong authentication, MFA, disabling TCP forwarding, log monitoring, patching).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.