The US Department of Justice announced today that the Federal Bureau of Investigation has taken down the network and infrastructure of a botnet called IPStorm.
See also: IPStorm botnet expands from Windows to Android, Mac and Linux

IPStorm allowed cybercriminals to carry out malicious traffic anonymously through Windows, Linux, Mac and Android around the world. In connection with the case, Sergei Makinin, of Russian-Moldovan origin, pleaded guilty to three counts of computer hacking and now faces a maximum sentence of 10 years in prison.
The DoJ announcement describes IPStorm as a proxy program that allows cybercriminals, fraudsters and others to avoid barriers and remain anonymous by routing their traffic through thousands of different devices that have infiltrated people's homes or offices.
IPStorm victims suffered the consequences of having their network speed hijacked by malicious actors and were at risk of receiving dangerous content at any time.
Makinin's proxying service is offered through the websites 'proxx.io' and 'proxx.net', where it is advertised as providing over 23,000 anonymous proxies worldwide.
See also: OracleIV DDoS Botnet Malware Targets Docker Engine API Instances
“According to court documents, from at least June 2019 to December 2022, Makinin developed and used malware to hack thousands of devices -connected internet around the world, including Puerto Rico,” the US Department of Justice said in a statement.

Makinin admitted that he had made at least $550,000 in profit from the proxy services he sold to others and agreed to hand over the cryptocurrencies he held from the proceeds of the criminal activity.
Law enforcement's operation to take down the IPStorm botnet has not extended to computers . Technical details about how IPStorm and its variants operate are available in a report from Intezer, which assisted the FBI with information on cybercriminal activity, which was originally published in October 2020.
See also: Socks5Systemz proxy botnet has infected over 10,000 devices
Signs of botnet infection
One of the first signs that a device is part of a botnet is an unexpected drop in performance. This can happen because the botnet's malicious servers are using the device's resources to perform malicious tasks, such as sending spam emails or DDoS.
Another sign is increased data traffic on the device. This could mean that the device is engaging in malicious activity, such as sending large amounts of data to other devices or servers.
Additionally, a device that is part of a botnet may exhibit unusual behavior, such as automatically installing or deleting applications, opening ports that users have not opened, or unwanted changes to device settings.
Finally, unexpected battery drain on portable devices, such as mobile phones or tablets, can be another sign that the device is part of a botnet. The botnet's malicious activities can consume a lot of power, causing the battery to drain quickly.
Source: bleepingcomputer
