Description

The U.S. Department of Justice recently celebrated a major triumph in the fight against cybercrime by disclosing the successful dismantling of the IPStorm botnet proxy service network and infrastructure by the Federal Bureau of Investigation (FBI). IPStorm had been enabling cybercriminals worldwide to route malicious traffic anonymously through a wide array of compromised devices across various platforms like Windows, Linux, Mac, and Android. Sergei Makinin, a Russian-Moldovan national, faced three counts of computer fraud in connection with this operation. He could potentially face a maximum prison sentence of 10 years. The U.S. DoJ emphasized the serious consequences experienced by IPStorm victims, who not only unknowingly aided cybercrime but also suffered from the hijacking of their network bandwidth and the constant threat of receiving harmful payloads. Operating through websites 'proxx.io' and 'proxx.net,' Makinin's illicit proxying service boasted over 23,000 anonymous proxies worldwide. According to court documents, from June 2019 to December 2022, Makinin developed and deployed malicious software to convert infected devices into proxies, generating profits. He confessed to earning at least $550,000 from the sale of these proxy services and agreed to forfeit cryptocurrency wallets containing the proceeds. IPStorm targeted Windows systems, Linux architectures, and Android IoT devices, showcasing a modular design with Golang packages for versatility across these systems. The botnet exploited the InterPlanetary File System (IPFS) peer-to-peer network to conceal its activities and resist infrastructure takedowns. IPStorm featured various capabilities such as brute-force SSH, antivirus evasion, and persistence. This successful operation was a result of collaboration among global law enforcement agencies, including the Spanish National Police Cyber Attack Group, Dominican National Police-International Organized Crime Division, and Ministry of the Interior and Police-Immigration Directorate. The takedown of the IPStorm botnet represents a significant milestone in the global fight against cyber threats.