FCC Abolishes Gigabit Speed Goal, Suggesting It Is Unfair To Slower Technologies
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Botnets powered by residential proxy networks are proliferating, enabling cybercriminals of all types to evade detection by blending in with seemingly legitimate traffic, Lumen Technologyβs Black Lotus Labs said in a report Friday.
The global scale of botnets observed by Lumen is currently approaching 60 million victim IP addresses, Chris Formosa, senior lead information security engineer at Black Lotus Labs, told CyberScoop. Roughly 1 in 4 of those compromised IPs are based in the United States, and the true number of infected devices is much greater because there are networks beyond Lumenβs visibility and multiple devices are often unknowingly running a malicious proxy network on the same IP.Β
Super-sized botnets are also gaining momentum, according to Lumen, with an average of 10 distinct botnets controlling their own populations of about 1 million active victims daily.
βThe only reason these botnets keep getting more and more victims is because there is clearly a market. Aside from criminal activity, who wants access to millions of IPs regularly?β Formosa said.Β
That demand for botnets fuels opportunities for growth, reselling, collaboration, and quick rebounds following massive disruptions.
IPIDEA, one of the largest residential proxy networks in operation when its infrastructure was disrupted by coordinated strikes in January, recovered at nearly half-strength within hours and earlier this surpassed its pre-disruption botnet size with a current botnet population of about 10 million IPs, researchers said.
βTheir rebuild was eye-opening as they began to rebound from that interdiction,β Ryan English, information security engineer at Black Lotus Labs, told CyberScoop. βEven for how quickly some botnets can rebound, theirs was surprising. Weβve seen them all rebuild, but we havenβt seen anybody do it that fast.β
Meanwhile, botnets are continuously growing, as cybercriminals seek out the cover they provide, more cheap and poorly defended devices hit the market and vendors stop providing security updates for older but still usable products.Β
βYour available pool for those proxy hunters grows every year, and it will continue to grow every year,β English said, adding that more than 1 billion devices are currently vulnerable and available to be unknowingly sucked up into botnets.
The challenge for defenders is lopsided, and while disruptions and seizures occur relatively often, botnet operators have formed a global supply chain with pathways that are difficult to break.Β
βWe have observed multiple residential proxy services collaborating to form what amounts to the largest cooperative network ever seen on the internet,β researchers wrote in the report.
Black Lotus Labs currently tracks more than 30 distinct malicious proxy botnet clusters, and most of those regularly boast more than 100,000 daily victims.
βOur understanding of the various botnets in this space, along with experience in multiple disruptions, leads us to a very important conclusion: taking down a single malicious proxy provider or their botnet in isolation is likely to result in a short-lived solution,β researchers wrote.Β
βIn recent years, the malicious proxy environment has essentially created the largest collective botnet currently active on the internet, capable of moving millions of IPs within hours to wherever they are needed,β they added. βUntil the malicious proxy landscape is properly addressed and regulated on both the private industry and law enforcement sides, this issue will grow and, along with the DDoS botnet landscape, will most likely become a greater problem in the long term.β
The post Despite multiple takedowns, botnets continue to grow appeared first on CyberScoop.












![]()
Ethan Robish // Why Segment Your Network? Hereβs a quick recap from Part 1. A typical home network is flat. This means that all devices are connected to the same [β¦]
The post Home Network Design β Part 2 appeared first on Black Hills Information Security, Inc..
![]()
Kent Ickler // Link-Local Multicast Name Resolution (LLMNR) This one is a biggie, and youβve probably heard Jordan, John, me, and all the others say it many many times. LLMNR [β¦]
The post How To Disable LLMNR & Why You Want To appeared first on Black Hills Information Security, Inc..
![]()
Ethan Robish // In this series of posts, Iβll discuss how I segmented my home network using VLANs and how I moved away from using a risky consumer-grade router at [β¦]
The post Home Network Design β Part 1 appeared first on Black Hills Information Security, Inc..
Beau Bullock // If you have been even remotely in touch with technology in the past thirty years you have probably heard of this thing called a βfirewallβ. If not, [β¦]
The post Poking Holes in the Firewall: Egress Testing With AllPorts.Exposed appeared first on Black Hills Information Security, Inc..
Β Katherine MacMillan // Something interesting happened last week. A programmer by the name of Matthew Garrett gained access to the lighting and window controls to nearly every room of a [β¦]
The post How to Secure Your Home Network appeared first on Black Hills Information Security, Inc..