HomeSecurityHacker group turns thousands of IoT devices into Proxies

Hacker group turns thousands of IoT devices into proxies

A group of hackers is monetizing vulnerable Internet-of-Things (IoT) devices by infecting them with malware and renaming them as home proxies  within minutes of exploitation, Trend Micro reports

See also: Which?: Chinese air fryers track users

hackers IoT devices

Detected as Water Barghest, the hacking group has compromised over 20,000 IoT devices to date, renting them out to other malicious actors who want to anonymize their activities.

Active for at least five years, Water Barghest has remained under the radar by relying heavily on automation, deleting logs to cover its tracks, and only accepting payments in cryptocurrency.

The threat actor acquires vulnerabilities in IoT devices, uses publicly available online scanners to identify vulnerable devices, and then attempts to exploit them from a set of data center IP addresses. The compromised devices quickly generate revenue in niche markets.

See also: Risks and ways to protect against vulnerabilities in IoT systems

As of October 2024, the hacker had created a botnet with more than 20,000 devices from Cisco, DrayTek, Fritz!Box, Linksys, Netgear, Synology, Tenda, Western Digital , and Zyxel, which were infected with the Ngioweb.

Hacker group turns thousands of IoT devices into proxies

Ngioweb, first observed in 2018 when it targeted Windows systems, began targeting Linux computers in 2019 and shifted its focus to IoT devices in 2020. A new variant of Ngioweb emerged this year.

According to Trend Micro, Water Barghest's activity was uncovered when the threat actor began targeting Cisco IOS XE last October from the same infrastructure it had been using for years in previous attacks.

See also: IoT technologies and security challenges

The cybersecurity firm also points out that botnets , such as the Water Barghest hacker group, typically remain active for years due to automation and improvements that help them evade detection.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS