At a glance.
- Autonomous system Proton66 tied to bulletproof hosting services.
- New Rust-based botnet targets vulnerable TOTOLINK and DrayTek routers.
- Texas city disrupted by cyberattack.
Autonomous system Proton66 tied to bulletproof hosting services.
Researchers at Trustwave SpiderLabs have found that the Russian autonomous system Proton66 (AS198953) is tied to bulletproof hosting services used to launch malware campaigns. Some of the activity was linked to SuperBlack ransomware operators. Other campaigns involved "compromised WordPress websites redirecting Android devices to fake Google Play stores, an XWorm campaign targeting Korean-speaking chat room users, and the WeaXor Ransomware."
The researchers note, "Starting from January 8, 2025, SpiderLabs observed an increase in mass scanning, credential brute forcing, and exploitation attempts originating from Proton66 ASN targeting organizations worldwide. Although malicious activity was seen in the past, the spike and sudden decline observed later in February 2025 were notable, and offending IP addresses were investigated....Statistics collected between January and March indicated that technology and financial organizations were, in general, the most common target for these activities."