

After hacking millions of devices, DoJ operation shuts down RSocks botnet | Tech...
source link: https://www.techspot.com/news/94995-department-justice-shuts-down-rsocks-botnet.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

After hacking millions of devices, DoJ operation shuts down RSocks botnet
The botnet, disguised as a proxy service, infiltrated millions of devices around the world
By Jimmy Pezzone 10 minutes ago
The big picture: The U.S. Department of Justice (DoJ) recently disclosed a worldwide effort to dismantle the infrastructure of RSOCKS, a large Russian-based botnet disguised as a proxy service. The DoJ worked with law enforcement from the U.K., Germany, and the Netherlands in the coordinated effort to disrupt the organization's operations. The botnet, which sold the IPs of hacked devices to users of its proxy service, included millions of devices around the world ranging from garage door openers to IoT devices. The seizure is the result of investigations dating back to 2017.
The RSOCKS botnet originally targeted IoT devices such as industrial control systems, clocks, streaming devices, etc. As the botnet grew, it expanded to include standard desktop, laptop, and Android-based devices. IPs from these devices were collected, stored, and sold to any hacker willing to pay the asking price via a Web-based storefront. Using this storefront, RSOCKS hackers were charged anywhere from $30 on the low end to $200 per day for access to 2,000 to 90,000 proxies, respectively.
Once purchased, the hackers were given the opportunity to download a list of IP addresses used to route malicious traffic across legitimate devices, allowing them to hide the traffic's true origination point. The site has since been seized by the DoJ and now redirects users to the following message and link for additional information.

The Federal Bureau of Investigation (FBI) began investigating RSOCKS and conducted several undercover purchases in early 2017. The purchases provided the investigators with access to the RSOCKS botnet, leading them to identify 325,000 devices that were compromised via brute force attacks. The impacted devices included large entities such as a university, hotel, television station, and an electronics manufacturer as well as numerous small businesses and individuals. Several identified victims were contacted and later worked with Federal investigators to replace their compromised devices with honeypots to further aid the investigation efforts.
Botnets are large pools of infected devices used to carry out any number of attacks against legitimate targets. Infected devices, also referred to as zombies, provide hackers with the ability to read and write data, obtain personal data, monitor activity, search for additional vulnerabilities, and install & run other applications on the device, all without the owner's consent. The infected devices can also be used to distribute malicious traffic while hiding the information's true origin point.

The FBI continues to actively identify, investigate, and counter cyber threats by partnering with enforcement agencies around the world. Any victims of cybercrime are encouraged to contact and report cyber incidents through the Internet Crimes Complaint Center (IC3). The site provides impacted parties with the tools to file a complaint as well as information to help determine who should file, what should be filed, and what happens once a complaint is filed.
Image credit: Global network by royyimzy25414
Recommend
-
8
Background On June 21, 2019, we published a blog about a Proxy Botnet, Linux.Ngioweb. On August 4, 2020, we captured a batch of ELF files with z...
-
11
Cybercriminals used compromised IoT devices in order to launch massive DDoS attacks all around the world The Mirai botnet is an IoT malware that allowed cybercriminals to compromise over 300,000 dev...
-
10
Most of the following article was completed around early 2020, at that time the vendor was trying different ways to recover the massive amount of infected devices, we shared our findings with the vendor, as well as to CNCERT, and decided to n...
-
5
Botnet definitionA botnet is a collection of internet-connected devices that an attacker has compromised to carry out DDoS attacks and other tasks as a swarm. The idea is that each computer becomes a mindless robot in a larger networ...
-
4
Rsocks, a popular proxy service, was just seized by the DOJCarly PageSat, June 18, 2022, 12:37 AM·2 min read
-
4
美国司法部成功打掉了 RSocks 僵尸网络-51CTO.COM
-
26
Meet the Administrators of the RSOCKS Proxy Botnet Authorities in the United States, Germany, the Netherlands and the U.K. last...
-
5
Accused Russian RSOCKS Botmaster Arrested, Requests Extradition to U.S. – Krebs on Security A 36-year-old Russian man recently identified by KrebsOnSecurity as the likely proprietor of the m...
-
11
Press Release Russian Botnet Disrupted in International Cyber Operation Thursday, June 16, 2022 ...
-
13
News New Mirai botnet variant V3G4 targets Linux servers, IoT devices The new V3G...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK