New Research Piece: Socks5Systemz: Lives On
Socks5Systemz lives on as ProxyBox, infecting Windows devices via pirated software to build a 31K+ IP address proxy network targeting enterprise financial sectors.
https://t.co/QNtOqwhgf0
Synthient Helps Disrupt World's Largest DDoS Botnet
The U.S. Department of Justice, in coordination with international law enforcement, has announced a major operation to disrupt the infrastructure of four of the world’s largest IoT botnets, including Aisuru and Kimwolf. Together, these botnets hijacked over three million devices worldwide to launch record-breaking Distributed Denial of Service (DDoS) attacks.
The Kimwolf botnet specifically targeted devices traditionally firewalled from the broader internet, enslaving them to act as proxy traffic for criminal networks and launch attacks reaching up to 30 Terabits per second.
Synthient is proud to have contributed to the DOJ's efforts. By identifying active exploitation, sharing malware samples, and coordinating disclosures with impacted parties, we helped neutralize this threat. We remain dedicated to making the web a safer place and are grateful to have played a role in this historic takedown.
Link: https://t.co/FUH7O82R5d
As part of our latest research we sent out 11 vulnerability disclosure notifications to the largest proxy providers. The scope involved millions of exposed devices, contributing to the growth of the worlds largest DDoS botnet.
https://t.co/FXYDYJEeB3
https://t.co/amWPj0XJnP
A look into the internals behind a large-scale proxy operation, from the sourcing of IPs to the platform itself. How proxy providers utilize everything from TV boxes to free software for building out a pool of unique proxies.
This has been an extraordinary set of data to process: 1.3B unique passwords, 2B unique email addresses (including mine 😭) and almost 3M of our @haveibeenpwned subscribers in there. It’s been weeks of processing to get this loaded, and finally, it’s done https://t.co/f5okTCYstn
With support from @synthient, we've just pushed out a corpus of 183M stealer log victims to @haveibeenpwned. We'd never seen 16.4M of those before, either, so there's a lot of new stuff in there, and that's just the first part. More here: https://t.co/S75hF4T1es
We collaborated with Have I Been Pwned in this latest piece of research to report several billion stolen credentials. Part 1 of the corpus is live on their platform and we've released a blogpost detailing our side of the research.
https://t.co/Df60qhTzpl
Also massive thanks to @g0njxa and his coverage of the LummaStealer // GhostSocks relationship. This contributed significantly to the research in this blogpost.
👻 New Blogpost: GhostSocks - From Initial Access to Residential Proxy
We dive into how GhostSocks evolved into a MaaS, its role in ransomware, residential proxies and the internals.
Read more here: https://t.co/YTyDKhNnim
Residential proxies pose a notorious risk to online platforms. Malicious actors frequently use them to obscure their fraudulent behavior. This latest release aims to rethink how we combat residential proxies.
https://t.co/fYgORu78bT