ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10914
OS Command Injection in D-Link DNS-320/320LW/325/340L NAS Firmware

CVE-2024-10914 is a critical OS command injection flaw (CWE-74/CWE-78/CWE-707) in the cgi_user_add function of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add on D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L network-attached storage devices. A remote, unauthenticated attacker can trigger it by manipulating the 'name' argument sent to that CGI endpoint, injecting operating system commands that the device executes. Successful exploitation yields arbitrary command execution on the NAS, giving the attacker control of the device — a profile attractive for follow-on actions such as botnet recruitment, consistent with recent IoT botnet activity. Affected devices are the DNS-320, DNS-320LW, DNS-325, and DNS-340L, which news reports describe as end-of-life D-Link NAS models, with all firmware up to 20241028 listed as vulnerable. A public proof-of-concept is available, the EPSS score is 96.2% (top percentile, indicating very high likelihood of exploitation within 30 days), and news headlines indicate hackers are actively targeting the flaw, though it is not yet in CISA KEV.

Do: Owners of DNS-320, DNS-320LW, DNS-325, and DNS-340L devices should check D-Link's support pages for updated firmware or end-of-life guidance and apply any fix the vendor publishes. Because the flaw is reachable via /cgi-bin/account_mgr.cgi?cmd=cgi_user_add, block or restrict remote (WAN) access to the device's web management interface — and consider blocking that specific endpoint — until patched; these EOL devices may never receive an update, in which case retiring or isolating them behind a restricted network is the safest option.

9.296% PoC
  • D-Link DNS-320 firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-320LW firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-325 firmware up to and including 20241028 (all listed firmware)
  • +1 more
large≈ tens of thousands of internet-exposed NAS devices (10k–100k range; exact counts unknown)
CVE-2024-41713
Unauthenticated Path Traversal in Mitel MiCollab NuPoint Unified Messaging

CVE-2024-41713 is a path traversal vulnerability (CWE-22) in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201), caused by insufficient input validation. An unauthenticated remote attacker can send crafted requests that traverse the file system without needing credentials or user interaction. A successful exploit grants unauthorized access allowing the attacker to view, corrupt, or delete users' data and system configurations, and reporting indicates exposure to unauthorized file and administrative access. Any organization running an affected MiCollab version, particularly with the NPM component reachable from untrusted networks, is at risk. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, and EPSS places it in the top percentile with a 98.1% probability of exploitation within 30 days.

Do: Upgrade MiCollab to a release later than 9.8 SP1 FP2 (9.8.1.201) per Mitel's advisory; if patching is not immediately possible, apply the vendor's mitigations or restrict/discontinue use of the NPM component, especially where it is internet-facing, as required by the CISA KEV entry. Given known ransomware use and reported admin-access abuse, hunt for signs of exploitation on exposed MiCollab servers (unexpected file changes, configuration tampering, and follow-on lateral movement).

9.198% KEV ransomware
  • Mitel MiCollab (NuPoint Unified Messaging component) through 9.8 SP1 FP2 (9.8.1.201)
largeon the order of tens of thousands of enterprise deployments, with thousands of MiCollab instances likely internet-exposed
CVE-2024-55591
Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy

CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it.

Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching.

9.898% KEV ransomware
  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12
large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands
CVE-2025-0108
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2025-0108 is a missing-authentication flaw (CWE-306) in the PAN-OS management web interface of Palo Alto Networks firewalls that lets an unauthenticated attacker with network access to that interface bypass login and invoke certain PHP scripts, reportedly via path-confusion tricks in the web server stack. Invoking the scripts does not yield remote code execution, but it can compromise the confidentiality and integrity of PAN-OS, such as by reading or modifying management-plane information. Any PAN-OS firewall whose management web interface is reachable by an attacker — for example, exposed to the internet or reachable from a compromised internal network — is affected, while Cloud NGFW and Prisma Access are not. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-18, a public proof-of-concept is available, EPSS puts the 30-day exploitation probability at 98.5%, and headlines report attackers chaining this bug with other PAN-OS flaws to breach firewalls.

Do: Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory (security.paloaltonetworks.com/CVE-2025-0108), since the vendor has patched the flaw. Until patched, restrict management web interface access to trusted internal IP addresses or management-only network zones as recommended in the vendor's hardening guidance. Check management-interface logs for unauthenticated requests to PHP scripts and for signs of chaining with other recently exploited PAN-OS vulnerabilities.

8.898% KEV PoC ×3
  • Palo Alto Networks PAN-OS
large≈ tens of thousands of internet-exposed PAN-OS management interfaces (subset of a much larger firewall install base)
CVE-2025-24472
Authentication Bypass in Fortinet FortiOS and FortiProxy Grants Super-Admin Access

CVE-2025-24472 is an authentication bypass (CWE-288) in the Fortinet Security Fabric of FortiOS and FortiProxy. A remote, unauthenticated attacker who already knows the serial numbers of both the upstream and downstream devices can send crafted CSF proxy requests to gain super-admin privileges on the downstream device; the attack only works where the Security Fabric is enabled, and the need for serial-number knowledge raises attack complexity. An attacker gains full super-admin control of the downstream Fortinet device, which can serve as a foothold for network-wide compromise. Organizations running affected FortiOS 7.0.x or FortiProxy 7.0.x/7.2.x builds with Security Fabric enabled are in scope. The flaw was added to CISA's KEV catalog on 2025-03-18 with known ransomware use, and multiple ransomware groups (including Gunra, SuperBlack, Mora_001 and Qilin operators) have been reported exploiting Fortinet firewall flaws in recent campaigns.

Do: Upgrade FortiOS 7.0.x and FortiProxy 7.0.x/7.2.x deployments to the fixed releases listed in the Fortinet PSIRT advisory for CVE-2025-24472, and identify any devices where the Security Fabric is enabled and serial numbers of peer devices may be discoverable. As interim mitigation, restrict or disable Security Fabric (CSF) connectivity toward untrusted peers and limit access to the CSF proxy handling path. Because the flaw is KEV-listed with known ransomware use, federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use, and all defenders should review device logs for unexpected super-admin sessions and anomalous CSF proxy traffic.

8.17% KEV ransomware
  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19
  • Fortinet FortiProxy 7.2.0 through 7.2.12
masshundreds of thousands of deployed Fortinet appliances plausibly affected; the practical subset is those with Security Fabric enabled
Full article709 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 21, 2025Vulnerability / Threat Intelligence

Cybersecurity researchers have disclosed a surge in "mass scanning, credential brute-forcing, and exploitation attempts" originating from IP addresses associated with a Russian bulletproof hosting service provider named Proton66.

The activity, detected since January 8, 2025, targeted organizations worldwide, according to a two-part analysis published by Trustwave SpiderLabs last week.

"Net blocks 45.135.232.0/24 and 45.140.17.0/24 were particularly active in terms of mass scanning and brute-force attempts," security researchers Pawel Knapczyk and Dawid Nesterowicz said. "Several of the offending IP addresses were not previously seen to be involved in malicious activity or were inactive for over two years."

The Russian autonomous system Proton66 is assessed to be linked to another autonomous system named PROSPERO. Last year, French security firm Intrinsec detailed their connections to bulletproof services marketed on Russian cybercrime forums under the names Securehost and BEARHOST.

Several malware families, including GootLoader and SpyNote, have hosted their command-and-control (C2) servers and phishing pages on Proton66. Earlier this February, security journalist Brian Krebs revealed that PROSPERO has begun routing its operations through networks run by Russian antivirus vendor Kaspersky Lab in Moscow.

However, Kaspersky denied it has worked with PROSPERO, stating that the "routing through networks operated by Kaspersky doesn't by default mean provision of the company’s services, as Kaspersky’s automatic system (AS) path might appear as a technical prefix in the network of telecom providers the company works with and provides its DDoS services."

Trustwave's latest analysis has revealed that the malicious requests originating from one of Proton66 net blocks (193.143.1[.]65) in February 2025 attempted to exploit some of the most recent critical vulnerabilities -

  • CVE-2025-0108 - An authentication bypass vulnerability in the Palo Alto Networks PAN-OS software
  • CVE-2024-41713 - An insufficient input validation vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab
  • CVE-2024-10914 - A command injection vulnerability D-Link NAS
  • CVE-2024-55591 & CVE-2025-24472 - Authentication bypass vulnerabilities in Fortinet FortiOS

It's worth noting that the exploitation of the two Fortinet FortiOS flaws has been attributed to an initial access broker dubbed Mora_001, which has been observed delivering a new ransomware strain called SuperBlack.

The cybersecurity firm said it also observed several malware campaigns linked to Proton66 that are designed to distribute malware families like XWorm, StrelaStealer, and a ransomware named WeaXor.

Another notable activity concerns the use of compromised WordPress websites related to the Proton66-linked IP address "91.212.166[.]21" to redirect Android device users to phishing pages that mimic Google Play app listings and trick users into downloading malicious APK files.

The redirections are facilitated by means of malicious JavaScript hosted on the Proton66 IP address. Analysis of the fake Play Store domain names indicate that the campaign is designed to target French, Spanish, and Greek speaking users.

"The redirector scripts are obfuscated and perform several checks against the victim, such as excluding crawlers and VPN or proxy users," the researchers explained. "User IP is obtained through a query to ipify.org, then the presence of a VPN on the proxy is verified through a subsequent query to ipinfo.io. Ultimately, the redirection occurs only if an Android browser is found."

Also hosted in one of the Proton66 IP addresses is a ZIP archive that leads to the deployment of the XWorm malware, specifically singling out Korean-speaking chat room users using social engineering schemes.

The first stage of the attack is a Windows Shortcut (LNK) that executes a PowerShell command, which then runs a Visual Basic Script that, in turn, downloads a Base64-encoded .NET DLL from the same IP address. The DLL proceeds to download and load the XWorm binary.

Proton66-linked infrastructure has also been used to facilitate a phishing email campaign targeting German speaking users with StrelaStealer, an information stealer that communicates with an IP address (193.143.1[.]205) for C2.

Last but not least, WeaXor ransomware artifacts – a revised version of Mallox – have been found contacting a C2 server in the Proton66 network ("193.143.1[.]139").

Organizations are advised to block all the Classless Inter-Domain Routing (CIDR) ranges associated with Proton66 and Chang Way Technologies, a likely related Hong Kong-based provider, to neutralize potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/04/hackers-abuse-russian-bulletproof-host.html