A group of hackers is monetizing vulnerable Internet-of-Things (IoT) devices by infecting them with malware and renaming them as home proxies within minutes of exploitation, Trend Micro reports
See also: Which?: Chinese air fryers track users

Detected as Water Barghest, the hacking group has compromised over 20,000 IoT devices to date, renting them out to other malicious actors who want to anonymize their activities.
Active for at least five years, Water Barghest has remained under the radar by relying heavily on automation, deleting logs to cover its tracks, and only accepting payments in cryptocurrency.
The threat actor acquires vulnerabilities in IoT devices, uses publicly available online scanners to identify vulnerable devices, and then attempts to exploit them from a set of data center IP addresses. The compromised devices quickly generate revenue in niche markets.
See also: Risks and ways to protect against vulnerabilities in IoT systems
As of October 2024, the hacker had created a botnet with more than 20,000 devices from Cisco, DrayTek, Fritz!Box, Linksys, Netgear, Synology, Tenda, Western Digital , and Zyxel, which were infected with the Ngioweb.

Ngioweb, first observed in 2018 when it targeted Windows systems, began targeting Linux computers in 2019 and shifted its focus to IoT devices in 2020. A new variant of Ngioweb emerged this year.
According to Trend Micro, Water Barghest's activity was uncovered when the threat actor began targeting Cisco IOS XE last October from the same infrastructure it had been using for years in previous attacks.
See also: IoT technologies and security challenges
The cybersecurity firm also points out that botnets , such as the Water Barghest hacker group, typically remain active for years due to automation and improvements that help them evade detection.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
