OTHER

FBI and Dutch Police Break Up Botnet of Hacked Routers

A joint international law enforcement effort has resulted in the shutdown of two services suspected of providing a botnet comprised of compromised internet-connected devices, such as routers, to cybercriminals. U.S. prosecutors have indicted four individuals accused of infiltrating these devices and overseeing the botnet.

On Wednesday, the websites for Anyproxy and 5Socks displayed notices indicating their seizure by the FBI as part of an operation called “Operation Moonlander.” The announcement specified the involvement of the FBI, the Dutch National Police (Politie), the U.S. Attorney’s Office for the Northern District of Oklahoma, and the U.S. Department of Justice.

Subsequently, on Friday, U.S. prosecutors announced the dismantling of the botnet and indicted three Russian nationals: Alexey Viktorovich Chertkov, Kirill Vladimirovich Morozov, and Aleksandr Aleksandrovich Shishkin, along with Dmitriy Rubtsov, a citizen of Kazakhstan. They are accused of profiting from the management of Anyproxy and 5Socks, falsely representing them as legitimate proxy services based on compromised routers.

Chertkov, Morozov, Rubtsov, and Shishkin, all residing outside the U.S., targeted older versions of wireless internet routers with known vulnerabilities, compromising “thousands” of these devices, according to the recently unsealed indictment.

After gaining control over these routers, the four individuals sold access to the botnet through Anyproxy and 5Socks, which have been operating since 2004, according to their websites and the prosecuting authorities.

While residential proxy networks are not inherently illegal, these services are typically used to provide customers with IP addresses for accessing geo-restricted content or bypassing government censorship. However, Anyproxy and 5Socks allegedly built their proxy network—partly consisting of residential IP addresses—by infecting thousands of vulnerable internet-connected devices, thereby forming a botnet for cybercriminal activity, as stated by the Department of Justice.

“Thus, the internet traffic of botnet subscribers appeared to originate from the IP addresses assigned to the compromised devices, rather than from the actual IP addresses of the devices the subscribers used for their online activities,” the indictment stated.

Techcrunch event

Berkeley, CA
|
June 5

BOOK NOW

“Conspirators promoting through 5Socks openly marketed the Anyproxy botnet as a residential proxy service on social media and in cybercriminal forums,” the indictment emphasized. “Such residential proxy services are especially appealing to criminal hackers as they offer anonymity while committing cybercrimes; residential IP addresses are typically considered by internet security services to represent more legitimate traffic compared to commercial ones.”

According to the DOJ’s press release, the four individuals are believed to have generated over $46 million from selling access to the botnet.

An FBI representative declined to comment when approached by TechCrunch, and neither the DOJ nor the Dutch National Police responded to inquiries for comments.

Ryan English, a researcher at Black Lotus Labs, informed TechCrunch before the domain seizures that both services were involved in multiple abuses such as password spraying, executing distributed denial-of-service (DDoS) attacks, and ad fraud.

On Friday, Black Lotus Labs, a team within cybersecurity firm Lumen, released a report detailing their assistance to authorities in tracking the proxy networks. According to Black Lotus, the botnet was “purposed to provide anonymity for malicious actors online.”

English expressed confidence that Anyproxy and 5Socks represent “the same pool of proxies run by the same operators, merely under a different name,” adding that “the majority of the botnet was comprised of various outdated router makes and models.”

Based on the report and Lumen’s global network visibility, the botnet had an “average of around 1,000 weekly active proxies across over 80 countries.”

Spur, a company monitoring proxy services on the internet, also played a role in the operation. Spur’s co-founder Riley Kilmer informed TechCrunch that, although 5Socks was one of the smaller criminal networks they monitored, it had “gained traction for financial fraud.”

This story has been updated to reflect the FBI’s lack of comment.