Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint Security

12:08 PM
Larry Loeb
Larry Loeb
Larry Loeb

Bulletproof Proxy Providers Try to Hide Botnet IP Address Needles in Haystacks

Cequence Security's CQ Prime research team thinks it has spotted a new trend it calls 'bulletproof proxies.'

Cequence Security's CQ Prime research team thinks it has spotted a new trend it calls "bulletproof proxies." It's related to bulletproof hosting where providers offer considerable leniency in what content may be uploaded and distributed through their infrastructure and as well as protection from law enforcement investigations, information requests, subpoenas and the like. Take the same idea and apply it to a proxy hoster.

Bulletproof proxy providers will include millions of globally distributed residential IP addresses in their namespace that are marketed under the false pretenses of being used for legitimate purposes and aggressively compete against one another for their share of adversarial buyers, according to Cequence.

It also says in the report that attacks emanating from bulletproof proxy networks targeting Cequence financial services and retail customer environments increased 518% and 800% respectively between Q1-Q2 2019. They also say that more than 70% of the attack traffic across bulletproof proxy networks targeted mobile endpoints.

The inaugural analysis of automated malicious bot campaigns that Cequence performed was conducted across three industry verticals, where bulletproof proxies were found to be used as a means of distributing attacks globally across millions of high-reputation, residential IP addresses (such as routers, refrigerators, IoT devices, garage door motors and others).

Will Glazier, head of CQ Prime research, said that "The initial focus of CQ Prime will be research on the growing number of malicious, automated bot attacks and the four key components of each unique attack: user credentials, infrastructure, tools and behaviors. These attacks, which are nearly impossible to detect with legacy security tools, abuse business application logic, enabling bad actors to achieve various fraud and theft objectives."

These sort of proxy providers will support IPs that appear as coming from residential providers such as Comcast, AT&T, Bell and Vodafone. This organization of IP infrastructure will mess up defenders from being able to throw out defending responses aimed at particular IP blocks, networks or even individual IPs themselves. The same IP could be used for both legitimate and attacking transactions.

But in early May, they observed a large influx of attack traffic coming from Cogent Communications and Isomedia. The attack pattern spread across multiple customers. Further investigation revealed the traffic was being generated by the Bulletproof Proxy Provider SmartProxy. All told, they saw a 548% increase in traffic from these seemingly legitimate ISPs in a little less than a three-month period.

But to what end? Well, they went on to find use cases of social media automation, sneaker bots, ticket bots (both of which buy up merchandise to sell on the secondary market) and black hat SEO Optimization (to cause click fraud or undeserved ranking in search engines) tended to dominate the marketing material of these bulletproof proxy services.

Some metrics that might be used to detect abnormal bot activity that is using proxies may include changes in behavior and traffic distributions that deviate substantially from the norm. That may be expressed as login failure ratios, irregular fast POST patterns in a user session of a scraper, or irregular rotation and obfuscation among fields.

Bots are trying to camouflage themselves to make it harder to eradicate them. Spreading IP addresses globally is just one of the tricks that botmasters are employing, but one worthy of attention in a security posture.

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Another COVID-19 Side Effect: Rising Nation-State Cyber Activity
Stephen Ward, VP, ThreatConnect,  7/1/2020
Lessons from COVID-19 Cyberattacks: Where Do We Go Next?
Derek Manky, Chief of Security Insights and Global Threat Alliances, FortiGuard Labs,  7/2/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-07-07
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
PUBLISHED: 2020-07-07
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
PUBLISHED: 2020-07-07
A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We recommend updating, or to res...
PUBLISHED: 2020-07-07
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
PUBLISHED: 2020-07-07
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user su...