216.73.216.233

PROXY.AM Powered by Socks5Systemz Botnet

· Published 04/12/2024 10:17 · Modified 04/12/2024 10:26

Export JSON

Essential information

Published
04/12/2024 10:17
Modified
04/12/2024 10:26
Tags
2024-12-04 botnet proxy socks5 socks5systemz
Related entities
43 observables, 1 intrusion sets (apt), 10 techniques (mitre), 8 malware, 9 others

Description

The , active since 2013, has been operating under the radar by integrating with other malware as a SOCK5 module. Recently, it has grown to 250,000 compromised systems globally. The powers .AM, a service providing exit nodes for criminal activities. Originally sold as standalone malware, was adapted for use in Andromeda, Smokeloader, and Trickbot. The 's size fluctuates, with recent estimates ranging from 85,000 to 100,000 daily active bots. .AM, registered in 2016, offers 'elite, private and anonymous proxies' for various purposes, including account brute-forcing. The malware has undergone recent updates, including new infrastructure and obfuscation techniques.

External references