Authorities dismantle global proxy network built on infected devices

US authorities have dismantled a global malicious proxy service that let criminals route their traffic through compromised devices to hide their identity. The service, known as Anyproxy and 5socks, had operated for years and gave paying customers access to thousands of infected computers and routers worldwide. Prosecutors say the network was built using malware that turned internet-connected devices into proxies, used for fraud, credential theft and other attacks. The domains have been seized and several individuals charged.

What this means for your business

The relevant point is not the service that was shut down but where the devices came from. A forgotten router at a warehouse or an unpatched device in a home office can be rented out as an anonymisation node without anyone noticing. That routes unwanted traffic through your IP addresses, with the reputational and follow-up costs that brings.

Berigo recommends

  • Build a current inventory of network equipment, including devices at small sites and with employees working from home.
  • Set fixed routines for firmware updates on routers and other network gear, and retire equipment no longer receiving security updates.
  • Close management interfaces to the internet and replace all default passwords.
  • Monitor unexpected outbound traffic from devices that should never initiate connections.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch