Infrawatch
@infrawatch_app
Followers
616
Following
53
Media
1
Statuses
11
YARA-first adversary infrastructure discovery at internet scale. Uncover residential proxies, VPNs, malware C2s, and more with 500+ baked-in rules.
United Kingdom
Joined December 2023
Foreign-controlled proxy network "DSLRoot" has deployed hardware in 300+ U.S. homes across 20+ states-including military residences. Full investigation now live:
infrawatch.app
Detailed analysis of DSLRoot, a residential proxy network deploying hardware across U.S. homes, operated by a Belarusian national. Includes technical overview, network footprint, and operator...
3
35
126
Infrawatch researchers look into DSLRoot, a distributed residential proxy network across U.S. infrastructure, using hardware deployed in at least 20 states. https://t.co/dFC6FQV9Su
1
8
25
Also see Brian's post here: https://t.co/qljAPY59WJ. This was a great collaboration which led us down new paths to investigate! 🤖
krebsonsecurity.com
The cybersecurity community on Reddit responded in disbelief this month when a self-described Air National Guard member with top secret security clearance began questioning the arrangement they'd...
0
5
20
New research Tuesday: How is a Belarus company convincing US military personnel to install network devices in their homes? Our investigation into DSLRoot reveals Americans are unknowingly helping foreign actors build proxy infrastructure on US soil.
2
72
510
A sneak peek at our dashboard 👀 Hunt threats across VPN, malware, residential proxy and internet-scanning data in real-time. Get instant context across the entire internet. 🥇 Be among the first - BETA access still accepting applications: https://t.co/cfLtGS7Eca
0
2
10
Infrawatch researchers explore GhostSocks, a Golang-based SOCKS5 backconnect proxy malware, detailing its integration with LummaC2 and its command-and-control infrastructure. https://t.co/DoZUtb8d02
0
14
53
GhostSocks: A SOCKS5 backconnect malware enhancing LummaC2 infections. Our latest analysis covers its technical details, infrastructure, and how it improves credential fraud success. Learn more about about GhostSocks here 👉🏻 https://t.co/OPN58phCy8
infrawatch.app
This analysis explores GhostSocks, a Golang-based SOCKS5 proxy malware, detailing its integration with LummaC2 and its command-and-control infrastructure. We highlight its use of obfuscation and...
1
4
19
No more waiting on predefined scans from third-party tools. Customise probes, target specific IPv4/IPv6 ranges, ASNs, countries, or the entire 🌎 - and act immediately. Probe deeper into the internet. 👉🏻
infrawatch.app
The lack of flexibility in traditional scanning products leaves organizations reliant on publicly available datasets, often waiting for others to decide what gets scanned and when.
0
6
17