HomeSecurityHackers target their victims' internet connections

Hackers target their victims' internet connections

Hackers are now targeting their victims' Internet connections to quietly generate illegal revenue after malware infection.

On Tuesday, researchers from Cisco Talos said that “proxyware” is being perceived in the cybercrime ecosystem and, as such, is being spun for illicit purposes.

See also: The hacker who caused strokes says he stole 600 million crypto "for fun"!

Hacker

See also: The largest cryptocurrency theft by hackers! 600 million lost.

Proxyware, also known as Internet sharing applications, are legitimate services that allow users to share part of their Internet connection with other devices and may also include firewalls and antivirus programs.

Other apps will allow users to "host" an internet hotspot connection, providing them with cash every time a user connects to it.

It is this format, provided by legitimate services including PacketStream and Nanowire, that is used to generate passive income on behalf of cyber attackers and malware developers.

According to the researchers, proxyware is abused in the same way as legitimate cryptocurrency mining software: it is installed silently and with efforts made to stop the victim from noticing its presence, such as through resource usage control.

In cases documented by Cisco Talos, proxyware is included in multi-stage attacks. An attack chain begins with a legitimate software program that is accompanied by a Trojanized installer containing malicious code.

Illegal use of proxyware could allow hackers to hide the source of their attacks, not only giving them the ability to perform malicious actions by making it appear as if they are coming from legitimate homes or corporate networks, but also rendering network defenses that rely on IP-based blocklists ineffective.

See also: Hackers compromise private routers – List of vulnerable devices

The same mechanisms currently used to monitor Tor exit nodes, 'anonymous' proxies, and other common traffic control techniques are not found in the tracking nodes found in proxyware networks.

That's not all. Researchers have identified several techniques employed by hackers, including trojanized proxyware installers that allow information stealers and remote access trojans (RATs) to be secretly distributed without the victims' knowledge. In one case observed by Cisco Talos, hackers used proxyware applications to monetize victims' network bandwidth, as well as exploit the machine's CPU resources for cryptocurrency mining.

Another case involved a multi-stage malware campaign that resulted in personal data theft, cryptocurrency mining payloads, and proxyware software, highlighting the “variety of approaches available to adversaries,” who can generate revenue through more than one attack method.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS