Archive for Silent Push

New Research Finds Legitimate Bandwidth-Sharing App Can Expose Corporate Networks to Proxy Users 

Posted in Commentary with tags on August 20, 2026 by itnerd

Silent Push has released new research revealing how legitimate bandwidth-sharing apps can quietly turn employee devices into commercial proxy nodes, potentially exposing corporate IP addresses and internal network resources to anyone with access to the proxy service.

Silent Push researchers joined Peer2Profit, a bandwidth-sharing service that pays users to share their internet connection, and traced where that bandwidth actually goes. Within roughly 10 minutes of enrolling a test device, its residential IP appeared in Astroproxy’s commercial proxy network, confirming an active operational relationship between the two services. Peer2Profit recruits users and pays for their bandwidth, while Astroproxy resells that bandwidth commercially.

The findings expose a significant blind spot for enterprise security teams: Peer2Profit is not malware and can be knowingly installed through legitimate channels, meaning traditional antivirus and threat intelligence tools may not flag it. Once installed on a corporate device or network, however, the organization’s IP can become a proxy exit node, and Silent Push found the risk can extend beyond the public IP to internal network resources.

You can read the blog here:https://www.silentpush.com/blog/peer2profit-astroproxy/

Silent Push Enables Cybersecurity Companies to Build Proactive Security Products with First-Party Infrastructure Intelligence

Posted in Commentary with tags on August 4, 2026 by itnerd

Silent Push today announced expanded access to its proprietary first-party infrastructure intelligence platform, enabling cybersecurity companies to integrate the same data that powers Silent Push’s own threat detection and research capabilities directly into their products and workflows.

Unlike traditional threat intelligence that relies on indicators of compromise (IOCs) after an attack has occurred, Silent Push provides first-party infrastructure intelligence and Indicators of Future Attack® (IOFA) that identify adversary infrastructure while it is still being built, an average of 104 days before it is weaponized. This enables cybersecurity vendors to deliver earlier detection, richer context, and more proactive protection for their customers.

The offering is designed for both cybersecurity product and research teams and cyber threat intelligence (CTI) organizations seeking to enhance detection capabilities, accelerate research, and differentiate their offerings through exclusive infrastructure intelligence.

Key capabilities include:

  • First-party infrastructure intelligence unavailable through third-party data feeds or recycled threat intelligence.
  • Preemptive IOFA that identify malicious infrastructure months before attacks are launched.
  • API-first integration for enrichment, scoring, infrastructure context, bulk lookups, and automated security workflows.
  • MCP Server integration for AI-native and agentic security environments.
  • Historical DNS and WHOIS intelligence, behavioral fingerprinting, and Traffic Origin data to accelerate threat research and campaign analysis.
  • Custom intelligence feeds tailored to specific threat categories, geographies, or infrastructure patterns.

Supporting a Broad Range of Security Use Cases

Silent Push APIs enable security vendors and technology partners to build next-generation detection and investigation capabilities into their products, enrich existing threat intelligence platforms with continuously updated infrastructure data, and power published threat research with deterministic, first-party intelligence. The platform also accelerates AI-assisted security operations and threat hunting while helping organizations identify lookalike domains, malicious infrastructure, and adversary activity before attacks occur, enabling a more proactive approach to cyber defense.

Silent Push offers flexible deployment options including direct Data API access, MCP Server integration for AI workflows, full platform access for research teams, and customized intelligence feeds.  The company already provides proprietary intelligence to cybersecurity organizations that use Silent Push data to enrich their products and power customer-facing threat intelligence offerings.

For more information about Silent Push’s cybersecurity company offering, visit http://www.silentpush.com or contact sales@silentpush.com.

AI wrote exploit scripts against 12,500 domains and found live targets

Posted in Commentary with tags on July 30, 2026 by itnerd

Security firm Silent Push used Claude Opus 5 to write exploitation scripts against 12,500 domains, then filtered the results down to several hundred genuinely exploitable dangling DNS records. It’s a known bug class, a DNS record still pointing at a cloud resource that’s since been deleted, letting an attacker reclaim it, but Silent Push demonstrated it against real, named organizations.

You can read more here: Welcome to Danglegeddon – Silent Push

John Watters, Chairman & CEO, iCOUNTER had this to say:

“Silent Push used Claude Opus 5 to write exploitation scripts against 12,500 domains and came back with several hundred workable targets. These are real organizations, not lab conditions: a dangling Azure blob storage record tied to U.S. government infrastructure that could bypass .gov trust filters, an unassigned Société Générale Azure resource, exposed developer credentials and API keys at Ford, and a stale record at Eli Lilly. Silent Push projects losses in the hundreds of billions across pharmaceutical companies alone if this class of vulnerability gets weaponized at scale.

Security teams need to treat domain inventory as something that gets maintained continuously, not set up once and forgotten. That means tracking every DNS record they’ve created, including the orphaned ones pointing at cloud resources that were deleted months or years ago and never cleaned up. Most organizations have no idea how many of those records exist in their own environment, and Silent Push just showed exactly what an attacker can do with the ones they find.

What used to take a nation-state’s intelligence apparatus, mapping thousands of domains, cross-referencing DNS history, and building exploitation infrastructure by hand, now runs as an automated pipeline. An AI model did the reconnaissance, filtered the noise, and handed back a ranked target list touching banking, government, manufacturing, and pharma in a single pass. The skill and headcount required to run a globally coordinated infrastructure attack just dropped by an order of magnitude.”

If you haven’t been attacked by AI, you’re going to be. Of that there is no doubt. The question is will you be ready to defend against an AI attack.

Triad Nexus Operations Infrastructure Reborn as Threat Actor Distances Activity from FUNNULL CDN

Posted in Commentary with tags on April 14, 2026 by itnerd

Silent Push has released new research revealing that following US Treasury sanctions in 2025, Triad Nexus has matured its operational security, employing geographic fencing to blind US investigators while simultaneously laundering its infrastructure through account muling and a rotating network of “clean” front companies. 

Triad Nexus is responsible for $200M+ in reported losses, driven largely by sophisticated “pig-butchering” and virtual currency scams. Individual victim losses average $150K, highlighting the high conversion nature of its operations. Despite federal sanctions in 2025, the group has reinstated its global fraud engine, shifting its focus toward emerging markets while maintaining a persistent threat to Western enterprise assets. 

Triad Nexus continues to pose a direct risk to corporate brand integrity and customer trust. The group manages an industrialized catalog of impersonation assets targeting: 

Banking and Fintech: Payment portals for more than 25 global institutions (including Wells Fargo and Bank of America) used for large-scale credential harvesting and “pig-butchering” scams. 

Luxury Retail: High-fidelity clones of brands such as Tiffany and Cartier to intercept high-value consumer transactions. 

Global Logistics: Exploitation of services, including the Vietnam Post, to facilitate regional personally identifiable information (PII) theft. 

You can read the research here: https://www.silentpush.com/blog/triad-nexus-funnull-2026

New SystemBC Botnet Malware Research Finds Novel Variant & 10K Unique Infected IPs Part of Family

Posted in Commentary with tags on February 4, 2026 by itnerd

Silent Push has revealed its analysts have identified more than 10,000 unique infected IP addresses as part of the SystemBC botnet malware family, which is used in ransomware attacks and as a SOCKS5 proxy network. 

Silent Push’s analysis shows SystemBC infections are globally distributed at scale, with the highest concentration of infected IP addresses observed in the US, followed by Germany, France, Singapore, and India.

Silent Push identified SystemBC infections within sensitive infrastructure, including compromised IP addresses hosting government websites in Burkina Faso and Vietnam. 

The research uncovers a previously undocumented SystemBC variant written in Perl, indicating continued development activity and ongoing evolution of the malware family.

You can read the analysis here: https://www.silentpush.com/blog/systembc

New Magecart Network Disrupts Online Shoppers: Campaign Targets AmEx, Mastercard, Capital One Subsidiary

Posted in Commentary with tags on January 13, 2026 by itnerd

Silent Push has uncovered an extensive network of domains associated with a long-term, ongoing web-skimmer campaign, known under the umbrella name: “Magecart.” 

This campaign utilizes scripts targeting at least six major payment network providers: American Express, Diners Club, Discover (a subsidiary of Capital One), JCB Co., Ltd., Mastercard, and UnionPay. 

The most likely victims of this web-skimming campaign are online shoppers and enterprise organizations that are clients of the various payment providers. 

Current findings suggest this campaign has been active for several years, dating back to the beginning of 2022. 

You can read the details here: https://www.silentpush.com/blog/magecart

Adaptix Ties to Russian Criminal Underworld, Threat Actors Harness Open-Source Tool for Malicious Payload

Posted in Commentary with tags on October 30, 2025 by itnerd

Silent Push has published new research in which its threat analysts uncover threat actors using Adaptix, a free and open source tool commonly used by penetration testers, to deliver malicious payloads. Silent Push has observed heavy ties linking Adaptix to Russia and the Russian criminal underworld. 

Abuse of Adaptix was first discovered during Silent Push’s research on the new malware CountLoader, which they reported previously. Soon after signatures were added to Silent Push detection methods, several public reports highlighted the surge in threat actors using Adaptix in global ransomware campaigns. 

Silent Push has identified a potential threat actor with significant ties to Russia who goes by the handle “RalfHacker,” appears to be a developer behind Adaptix, and manages a Russian language sales Telegram channel for the tool. 

The research can be found here: https://www.silentpush.com/blog/adaptix-c2.

Fake Browser Update Campaign Driving Attacks Worldwide

Posted in Commentary with tags on August 6, 2025 by itnerd

TodaySilent Push released an in-depth analysis of SocGholish (operated by TA569)—functioning as a sophisticated Malware-as-a-Service operation, selling access to compromised systems to various financially motivated cybercriminal clients. The malware acts as an Initial Access Broker (IAB), enabling other notorious groups and even the Russian GRU’s Unit 29155 to conduct follow-on attacks, including ransomware deployments.

The research dives into how SocGholish uses fake browser updates to lure victims in and leads them to drive-by malware downloads. The group also leverages Traffic Distribution Systems (including Parrot and Keitaro TDS) to filter and redirect victims to malicious content.

Additionally, the group’s use of domain shadowing and rotates its domains frequently to evade detection, making proactive threat intelligence crucial for defense and keeps them one step ahead of the game. 

You can read more here: https://www.silentpush.com/blog/socgholish

Silent Push Expands Cyber Defense Capabilities with VPN, Proxy, and Sinkhole Tagging on all Public IP Addresses 

Posted in Commentary with tags on August 5, 2025 by itnerd

Silent Push today announced the release of IP Context – a powerful new detection method that identifies all uses of IP addresses in one place, including use as a VPN, proxy, or sinkhole or benign scanner across the company’s global dataset.

IP Context allows defenders to minimize fraud and abuse through more effective identification of adversary infrastructure by gaining immediate context on the function and risk level of any given IP address. Tagged IPs are presented alongside everything else we know about an indicator – including its relationship with the rest of the Internet – in a single view, including DNS history, hosting relationships, campaign associations,  and proprietary categories not available anywhere else.VPNs and proxies are tagged and filtered per commercial service provider. Proxies are further categorized as ‘residential’, ‘open’, ‘http’, ‘socks4/5’, or if authentication is required.

With currently over 50 million IPs categorized daily as a VPN, proxy, or sinkhole, Silent Push brings full-spectrum tagging and enrichment to any IP it scans – whether it’s in an existing threat feed or discovered during an investigation.

Enterprise use cases for IP Context include:

  • Credential Stuffing & Account Takeover Detection: Flag login attempts from residential proxy IPs commonly used in automated attacks, helping SOC teams act before escalation.
  • Infrastructure Discovery: Reveal contextual information about unknown IP addresses, allowing differentiation between normal users, residential proxies, and VPNs.
  • Threat Actor Clustering: Identify shared proxy or VPN services across campaigns, enabling faster attribution and proactive blocking of related assets.
  • Incident Response & Malware Triage: Instantly recognize sinkhole-tagged IPs to avoid false alarms and focus efforts on containment and root cause analysis.
  • Advertising Fraud and Abuse Discovery: IP Context provides new opportunities to track ad fraud operators and coordinated inauthentic traffic schemes.

IP Context is available as an add-on for Enterprise customers. Tags are accessible through Silent Push’s Total View screen, or as a daily bulk data download, allowing teams to integrate tag intelligence into existing workflows and filter based on their unique operational needs.

New Chinese Fake Marketplace e-Commerce Phishing Campaign Using Thousands of Websites to Spoof Retail Brands

Posted in Commentary with tags on July 2, 2025 by itnerd

Silent Push has uncovered a new Chinese fake marketplace e-commerce phishing scam campaign using thousands of websites to spoof retail brands.

Silent Push followed a tip from Mexican journalist Ignacio Gómez Villaseñor about a threat actor targeting “Hot Sale 2025,” an annual sales event similar to “Black Friday” in the U.S.

The Silent Push team pivoted from that Mexico-centric campaign into thousands of websites that broadly targeted a more global audience with abundant waves of fake marketplace scams.

Silent Push has observed this threat actor group building multiple phishing websites with pages spoofing well-known retailers, including Apple, Harbor Freight Tools, Michael Kors, REI, Wayfair, and Wrangler Jeans.

The threat actor has also been caught abusing online payment services such as MasterCard, PayPal, and Visa, as well as payment security techniques for Google Pay, in order across this campaign’s network of scam websites.

You can read the research here.