Foreign-controlled proxy network "DSLRoot" has deployed hardware in 300+ U.S. homes across 20+ states-including military residences.
Full investigation now live: https://t.co/WbpiTsittX
Infrawatch identified 87 SIM farms across 17 countries, 24 commercial proxy providers, 35 cellular providers, 94 phone-farm locations across North America, Europe & South America, including a distributed presence across 19 U.S. states.
Report coming tomorrow.. 👀🚜📱
👀 NEW FROM US: Infrawatch identified 87 SIM farms across 17 countries.
SIM farms are now for sale, to anyone. We’ve uncovered a service that enables anyone, regardless of technical skill, to operate their own SIM farm.
https://t.co/Nfj2c6I0Du
Following today’s NCSC + U.S. DOJ disclosures on APT28 DNS hijacking activity, Infrawatch identified at least 18.6K likely victims across 87 countries.
We’ve published a victimology dashboard with victim breakdowns and a public IP checker:
https://t.co/YTKaMKqKxN
Infrawatch researchers look into DSLRoot, a distributed residential proxy network across U.S. infrastructure, using hardware deployed in at least 20 states. https://t.co/dFC6FQV9Su
Foreign-controlled proxy network "DSLRoot" has deployed hardware in 300+ U.S. homes across 20+ states-including military residences.
Full investigation now live: https://t.co/WbpiTsittX
New research Tuesday: How is a Belarus company convincing US military personnel to install network devices in their homes?
Our investigation into DSLRoot reveals Americans are unknowingly helping foreign actors build proxy infrastructure on US soil.
A sneak peek at our dashboard 👀
Hunt threats across VPN, malware, residential proxy and internet-scanning data in real-time. Get instant context across the entire internet.
🥇 Be among the first - BETA access still accepting applications: https://t.co/cfLtGS7Eca
Infrawatch researchers explore GhostSocks, a Golang-based SOCKS5 backconnect proxy malware, detailing its integration with LummaC2 and its command-and-control infrastructure. https://t.co/DoZUtb8d02
GhostSocks: A SOCKS5 backconnect malware enhancing LummaC2 infections.
Our latest analysis covers its technical details, infrastructure, and how it improves credential fraud success.
Learn more about about GhostSocks here 👉🏻
https://t.co/OPN58phCy8
No more waiting on predefined scans from third-party tools.
Customise probes, target specific IPv4/IPv6 ranges, ASNs, countries, or the entire 🌎 - and act immediately.
Probe deeper into the internet.
👉🏻 https://t.co/EHtZjgSRXq