Malware

Russian RSocks botnet disrupted by US

0

The U.S. Department of Justice has announced the disruption of the Russian RSocks malware botnet used to hijack millions of computers, Android smartphones, and IoT (Internet of Things) devices worldwide for use as proxy servers.

The law enforcement operation involved the FBI and police forces in Germany, the Netherlands, and the United Kingdom, where the botnet maintained parts of its infrastructure.

The RSocks botnet was used to convert residential computers into proxy servers, allowing the botnet’s customers to use them for malicious activity or to appear as coming from a residential IP address.

The services provided includes phishing operations, credential stuffing, account takeover attempts, etc. Also, by using a proxy service, the threat actors cannot be easily tracked by law enforcement, especially when those IP addresses belong to people unaware their devices were hijacked.

RSocks was also promoted for use by shopping bots, such as sneaker bots, that benefit from using residential IP addresses, which are usually not banned from online retailers.

FBI agents started to map the RSocks infrastructure in an undercover operation where they purchased to access a large number of proxies in 2017.

According to the United State Department of Justice, the cost for accessing RSocks proxy pools ranged from $30 per day for 2,000 proxies to $200 per day for 90,000 proxies.

During that time, the investigators identified 325,000 compromised devices, most of which were located in the United States. RSocks allegedly compromised these devices by brute-forcing their passwords and installing software on the breached computers to turn them into proxy servers.

Numerous entities have become victims of the RSocks botnet, including a university, a hotel, a television studio, and an electronics manufacturer, as well as home businesses and individuals.

At three of the victim locations, the investigators replaced the compromised devices with government-controlled computers (i.e., honeypots), and all three were subsequently compromised by RSocks.

Even though RSocks operation was severely disrupted due to the international law enforcement operation, no arrests have been announced this time.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Hermit Android spyware used in Kazakhstan, Syria and Italy

Previous article

QNAP NAS devices hit by eCh0raix ransomware attacks

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *