bg
News
20:52, 12 June 2026
views
7

Russian Researchers Uncover a 14,000-Node Botnet That Has Operated Since 2011

Researchers at Solar 4RAYS have identified ProxyCB, a large-scale cyberattack platform that has been operating largely unnoticed since 2011. The botnet's infrastructure now spans about 14,000 Russian IP addresses.

Photo: www.arsis.ru

The botnet came to light in 2025 during an investigation into a cybersecurity incident affecting a major client. Analysts noticed that requests followed the same patterns while originating from constantly changing sources, and the bots increasingly mimicked the behavior of real users. Further analysis showed that ProxyCB is a full-fledged ecosystem with its own control panel, dedicated data transmission channels, and server-side core. Over the years, access to the platform has reportedly been sold on dark web marketplaces for password-cracking campaigns, data theft, artificial traffic generation, and spam distribution. Researchers also found links to TeamSpy, a hacking group known for covert attacks carried out through the legitimate remote-access software TeamViewer.

"ProxyCB is a true dinosaur of the internet era. Its operators appear to have spent years refining malware droppers and testing different distribution methods, giving them a deep understanding of how Russia's internet segment operates. That likely helped the project avoid large-scale disruptions for nearly 15 years, with its command-and-control servers changing only three times during that period while the number of infected nodes continued to grow," said Alexey Khabarov, an analyst at Solar 4RAYS.

The researchers recommend that organizations closely monitor incoming traffic characteristics and deploy modern bot-mitigation technologies to detect and block similar threats.

like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next