logo

Malware Surge via Proton66

ID: 9306fccc-4a28-51ea-84d3-e40f2d886c7e

STIX ID: report--9306fccc-4a28-51ea-84d3-e40f2d886c7e

Feed Name: Canary Trap

Threat Score
75/100

Date Published: 2025-04-28

Date Updated: 2026-05-13

Author: Canary Trap

...
...

Trustwave SpiderLabs observed that Proton66, a Russian bulletproof hosting provider, has been abused since January 2025 to host C2 servers, phishing pages and multi-stage malware delivery chains that distribute GootLoader, SpyNote, XWorm, StrelaStealer and the WeaXor ransomware; attacks include mass scanning, credential brute-forcing and exploitation of vulnerabilities in PAN-OS, FortiOS, D-Link NAS and Mitel MiCollab, and use compromised WordPress sites to redirect Android users to fake Google Play phishing pages — organizations are advised to block Proton66 and affiliated CIDR ranges to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.