A sophisticated cybercriminal operation called REM Proxy is exploiting thousands of compromised servers to create one of the largest malicious proxy networks in operation today, according to new research from Lumen Technologies’ Black Lotus Labs.
## The Scale of the Operation
The REM Proxy network operates on an impressive scale, leveraging approximately 80% of the SystemBC botnet infrastructure. This criminal service markets access to:
– 20,000 compromised Mikrotik routers
– Thousands of freely available open proxies
– Over 1,500 daily victim machines, primarily compromised virtual private servers (VPS)
The network has become a preferred tool for various cybercriminal groups, including those behind TransferLoader malware and the notorious Morpheus ransomware operation.
## How SystemBC Powers the Network
At the heart of REM Proxy lies SystemBC, a C-based malware first identified in 2019. This sophisticated tool transforms infected computers into SOCKS5 proxies, creating a pathway for cybercriminals to route their malicious traffic through legitimate-looking IP addresses.
The malware targets both Windows and Linux systems, with recent variants specifically designed to infiltrate corporate networks, cloud servers, and IoT devices. The operation maintains over 80 command-and-control servers to manage its vast network of compromised machines.
## A Vulnerable Infrastructure
Perhaps most concerning is the security state of the victimized servers. Research reveals that these compromised systems are riddled with security vulnerabilities:
– Each victim averages 20 unpatched security flaws
– Most have at least one critical vulnerability
– One server in Atlanta was found vulnerable to over 160 unpatched security issues
– Nearly 40% of infections persist for more than 31 days
## Criminal Marketplace
The SystemBC network serves multiple criminal enterprises beyond REM Proxy, including:
– Two Russia-based proxy services
– VN5Socks, a Vietnamese proxy operation
– Various Russian web scraping services
– WordPress credential harvesting operations
The network’s operators use their own infrastructure to conduct brute-force attacks against WordPress websites, harvesting login credentials to sell on underground criminal forums.
## Operational Strategy
Unlike traditional residential proxy networks, SystemBC focuses on compromising commercial VPS systems. This approach offers several advantages to cybercriminals:
– Higher bandwidth capacity for sustained malicious activities
– Longer operational periods before detection
– More reliable infrastructure for large-scale operations
The malware operates with minimal stealth, prioritizing rapid expansion over avoiding detection. A key infrastructure component, IP address 104.250.164[.]214, serves as both a hosting platform and attack source for recruiting new victims.
## The Bigger Picture
SystemBC represents a evolution in cybercriminal infrastructure. Originally designed to support ransomware operations, it has transformed into a comprehensive platform for assembling and selling custom botnets. This model enables widespread reconnaissance, spam distribution, and targeted attacks while allowing criminals to reserve premium proxy resources for high-value operations.
The persistent nature of this threat, operating successfully across multiple years, demonstrates the challenge facing cybersecurity professionals in combating sophisticated, resilient criminal networks that exploit fundamental security weaknesses in internet infrastructure.
