• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
hackers abuse russian bulletproof host proton66 for global attacks and

Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery

You are here: Home / General Cyber Security News / Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery
April 21, 2025

Cybersecurity researchers have disclosed a surge in “mass scanning, credential brute-forcing, and exploitation attempts” originating from IP addresses associated with a Russian bulletproof hosting service provider named Proton66.

The activity, detected since January 8, 2025, targeted organizations worldwide, according to a two-part analysis published by Trustwave SpiderLabs last week.

“Net blocks 45.135.232.0/24 and 45.140.17.0/24 were particularly active in terms of mass scanning and brute-force attempts,” security researchers Pawel Knapczyk and Dawid Nesterowicz said. “Several of the offending IP addresses were not previously seen to be involved in malicious activity or were inactive for over two years.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The Russian autonomous system Proton66 is assessed to be linked to another autonomous system named PROSPERO. Last year, French security firm Intrinsec detailed their connections to bulletproof services marketed on Russian cybercrime forums under the names Securehost and BEARHOST.

Cybersecurity

Several malware families, including GootLoader and SpyNote, have hosted their command-and-control (C2) servers and phishing pages on Proton66. Earlier this February, security journalist Brian Krebs revealed that Prospero has begun routing its operations through networks run by Russian antivirus vendor Kaspersky Lab in Moscow.

However, Kaspersky denied it has worked with Prospero and that the “routing through networks operated by Kaspersky doesn’t by default mean provision of the company’s services, as Kaspersky’s automatic system (AS) path might appear as a technical prefix in the network of telecom providers the company works with and provides its DDoS services.”

Trustwave’s latest analysis has revealed that the malicious requests originating from one of Proton66 net blocks (193.143.1[.]65) in February 2025 attempted to exploit some of the most recent critical vulnerabilities –

  • CVE-2025-0108 – An authentication bypass vulnerability in the Palo Alto Networks PAN-OS software
  • CVE-2024-41713 – An insufficient input validation vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab
  • CVE-2024-10914 – A command injection vulnerability D-Link NAS
  • CVE-2024-55591 & CVE-2025-24472 – Authentication bypass vulnerabilities in Fortinet FortiOS

It’s worth noting that the exploitation of the two Fortinet FortiOS flaws has been attributed to an initial access broker dubbed Mora_001, which has been observed delivering a new ransomware strain called SuperBlack.

The cybersecurity firm said it also observed several malware campaigns linked to Proton66 that are designed to distribute malware families like XWorm, StrelaStealer, and a ransomware named WeaXor.

Another notable activity concerns the use of compromised WordPress websites related to the Proton66-linked IP address “91.212.166[.]21” to redirect Android device users to phishing pages that mimic Google Play app listings and trick users into downloading malicious APK files.

The redirections are facilitated by means of malicious JavaScript hosted on the Proton66 IP address. Analysis of the fake Play Store domain names indicate that the campaign is designed to target French, Spanish, and Greek speaking users.

Cybersecurity

“The redirector scripts are obfuscated and perform several checks against the victim, such as excluding crawlers and VPN or proxy users,” the researchers explained. “User IP is obtained through a query to ipify.org, then the presence of a VPN on the proxy is verified through a subsequent query to ipinfo.io. Ultimately, the redirection occurs only if an Android browser is found.”

Also hosted in one of the Proton66 IP addresses is a ZIP archive that leads to the deployment of the XWorm malware, specifically singling out Korean-speaking chat room users using social engineering schemes.

The first stage of the attack is a Windows Shortcut (LNK) that executes a PowerShell command, which then runs a Visual Basic Script that, in turn, downloads a Base64-encoded .NET DLL from the same IP address. The DLL proceeds to download and load the XWorm binary.

Proton66-linked infrastructure has also been used to facilitate a phishing email campaign targeting German speaking users with StrelaStealer, an information stealer that communicates with an IP address (193.143.1[.]205) for C2.

Last but not least, WeaXor ransomware artifacts – a revised version of Mallox – have been found contacting a C2 server in the Proton66 network (“193.143.1[.]139”).

Organizations are advised to block all the Classless Inter-Domain Routing (CIDR) ranges associated with Proton66 and Chang Way Technologies, a likely related Hong Kong-based provider, to neutralize potential threats.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «apt29 deploys grapeloader malware targeting european diplomats through wine tasting lures APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through Wine-Tasting Lures
Next Post: ⚡ THN Weekly Recap: iOS Zero-Days, 4Chan Breach, NTLM Exploits, WhatsApp Spyware & More ⚡ thn weekly recap: ios zero days, 4chan breach, ntlm exploits,»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.