LurkProxy: A Dual-Mode Reverse Proxy Utility
LurkProxy is a specialized utility used in the campaign to proxy network traffic. It operates in either SOCKS5 or transparent proxy mode,…
LurkProxy is a specialized utility used in the campaign to proxy network traffic. It operates in either SOCKS5 or transparent proxy mode,…
Fuyao apps are malicious applications pre-installed on Android TV boxes that spoof device identities to mimic popular phone brands, perform ad fraud,…
Nextcloud is a file sync and share platform that can be used as a proxy for Windmill endpoints, with exploitation observed targeting…
Stowaway is a proxy and remote access tool with SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based…
McMx RAT is a basic Go-based proxy and remote access tool that is a lightweight version of GoSerpent. It includes capabilities such…
A browser-based proxy tool that was used as the base for the malicious npm packages, allowing students to bypass web filters. It…
Badbox 2.0 is a botnet of hijacked Android TV devices used for ad fraud and proxy services. Google took its operators to…
Alarum Technologies, a publicly traded Israeli company (NASDAQ: ALAR), owns NetNut. It rejects the botnet label, claiming its software is for consented…
Synthient, a security firm, conducted controlled tests showing traffic sent into NetNut's commercial gateway exited through a device enrolled in Popa, providing…
Spur, a threat intelligence firm, was part of the research team that linked the Popa botnet to NetNut.