Cybernews researchers uncovered a large underground proxy network comprising thousands of hijacked devices worldwide, all controlled by a single Russian hacker. This brute-force campaign has already gained access to 87,000 vulnerable IPs, and the hacker is reselling them to residential proxy providers and individual users via Telegram bots and various websites.
Key information:
- The threat actor leases its proxy network to multiple residential proxy platforms and over 20,000 end users, earning over $200,000 in two years.
- The hacker “patched” official Claude Code so that it disables all security and accepts any large language model.
- The discovered server leaked everything: malicious tools, AI software, client lists, IP addresses with credentials, and logs of others hacking it.
- The campaign has been running for about two years, targeting devices with outdated VPN protocols like PPTP and L2TP.
- The leaked database had over 56,000 illicit users, with over 11,000 having linked Telegram accounts. Some of the users registered using their real names.
“The brute-forcing campaign monetizes compromised hosts by deploying proxy software and renting access. The hacker’s malicious actions are beyond doubt. Yet it also highlights another issue – owners neglect security by leaving old or unprotected devices running, and malicious actors abuse their environments for cybercrime,” said Aras Nazarovas, information security researcher at Cybernews.
For more information, here’s the full report:
https://cybernews.com/security/russian-vpn-hacker-brute-forcing-routers-building-proxy-empire
Related
This entry was posted on September 17, 2026 at 7:44 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Russian hacker built a $200,000 proxy empire by brute-forcing neglected routers using Claude Code
Cybernews researchers uncovered a large underground proxy network comprising thousands of hijacked devices worldwide, all controlled by a single Russian hacker. This brute-force campaign has already gained access to 87,000 vulnerable IPs, and the hacker is reselling them to residential proxy providers and individual users via Telegram bots and various websites.
Key information:
“The brute-forcing campaign monetizes compromised hosts by deploying proxy software and renting access. The hacker’s malicious actions are beyond doubt. Yet it also highlights another issue – owners neglect security by leaving old or unprotected devices running, and malicious actors abuse their environments for cybercrime,” said Aras Nazarovas, information security researcher at Cybernews.
For more information, here’s the full report:
https://cybernews.com/security/russian-vpn-hacker-brute-forcing-routers-building-proxy-empire
Share this:
Like this:
Related
This entry was posted on September 17, 2026 at 7:44 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.