← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
TrendMicro highlights the dangers of internet-facing routers and elaborates on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024. Cybercriminals and nation-state actors share an interest in compromised routers used as an anonymization layer, with cybercriminals renting out compromised routers and nation-state threat actors like Pawn Storm and Sandworm using dedicated proxy botnets. The analysis focuses on a criminal botnet of Ubiquiti EdgeRouters, disrupted by the FBI in January 2024, which Pawn Storm accessed in April 2022 for persistent espionage campaigns.
MITRE ATT&CK & Malware Families
Indicators of Compromise (9 / 73 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 142e4198e11d405899619d49cc6dc79c | — | 2024-08-07 | |
| FileHash-MD5 | 369d5d0a5c800724a6d77f100fef0e2c | — | 2024-08-07 | |
| FileHash-MD5 | 6f56666e4a9d31089b6310ebbdffa6f4 | — | 2024-08-07 | |
| FileHash-MD5 | 973eee9fae6e3a353286206da7a89904 | — | 2024-08-07 | |
| FileHash-MD5 | ae3054b3d932f7605cfd13ed31668efb | — | 2024-08-07 | |
| FileHash-MD5 | cb075ac6e8084aa29cffc2000cbe2576 | — | 2024-08-07 | |
| FileHash-MD5 | d5f6794c3b41f1d7f12715ba3315fd7b | — | 2024-08-07 | |
| FileHash-MD5 | e994df2dec28cc74fa9471f02e23b6af | — | 2024-08-07 | |
| FileHash-MD5 | f4c0c90d97f3d774d26268bc8900c887 | — | 2024-08-07 |