The Ngioweb botnet , which supplies more than 35,000 bots to the NSOCKS proxy service for cybercriminals , is being disrupted as security companies block traffic to and from both networks.
See also: Androxgh0st Botnet: Incorporates Mozi payloads to target IoT devices

After more than a year of research, the researchers identified the full architecture and traffic of the Ngioweb botnet proxy server, which was first observed in 2017.
As of late 2022, the proxy service on nsocks[.]net, provides home gateways for malicious activity under the name NSOCKS.
Many cybersecurity companies have reported that many of the proxies offered by NSOCKS came from the Ngioweb botnet, but not all of the command and control (C2) nodes were discovered.
In a recent report, researchers at Lumen's Black Lotus Labs looked at both active and historical C2 nodes and the architecture they form.
They note that in the NSOCKS[.] network “users route their traffic through more than 180 “backconnect” C2 nodes that serve as entry/exit points” to hide their identities.
See also: Chinese hackers use Quad7 botnet to steal credentials
According to the report, the Ngioweb botnet provides at least 80% of the 35,000 proxies provided by NSOCKS, which are spread across 180 countries.

The botnet has a payload network that redirects infected devices to a C2 server to retrieve and execute the ngioweb malware.
While it is unclear how the initial access is gained, Black Lotus Labs believes the threat actor relies on around 15 exploits for various n-day vulnerabilities.
In the second stage, the compromised device contacts C2 domains created using a domain generation algorithm (DGA) and determines whether the bot can be used for the proxy network.
These management C2s monitor and control the bot's capacity for traffic and also connect them to a “backconnect” server that makes them available for the NSOCKS proxy service.
Currently, both the Ngioweb and NSOCKS[.net] services are severely disrupted, as Lumen has identified the architecture and traffic. Together with industry partners such as The ShadowServer Foundation, the company is blocking traffic to and from known C2 nodes associated with both networks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Mirai-inspired Gorilla Botnet hits 0.3 million targets in 100 countries
Botnets are a significant and sophisticated threat to cybersecurity. Essentially, a botnet is a network of compromised computers or devices that are remotely controlled by an attacker, often without the knowledge of their owners. These networks can be used for a variety of malicious purposes, including launching distributed denial-of-service (DDoS) attacks, sending spam, or deploying additional malware. The insidious aspect of botnets lies in their ability to leverage the combined power and resources of multiple machines, making attacks more powerful and difficult to prevent.
Source: bleepingcomputer
