How Is Water Barghest Group Exploiting IoT Devices for Proxy Networks?

In an alarming discovery, security firm Trend Micro has uncovered a significant cybercrime campaign attributed to the Water Barghest group, which is believed to be linked to Russian state-sponsored hackers. Since 2020, the group’s activities have involved the rapid infection of 20,000 IoT devices, which are swiftly listed as proxy networks within ten minutes of their initial compromise. This campaign employs highly efficient, automated tools to escalate its scale, making the infected devices available for rent on proxy marketplaces almost immediately after infection.

Rapid Proliferation of the Campaign

Automated Tools and Proxy Networks

Trend Micro attributes the rapid proliferation of this campaign to its use of efficient, automated tools. These tools enable the Water Barghest group to quickly transform compromised IoT devices into proxy networks marketed to cybercriminals and nation-state hackers. The objectives of these proxy networks are multifaceted and range from website scraping, accessing compromised assets, to launching cyberattacks. The primary goal of these activities is to help anonymize them using geo-located IP addresses, thus making it challenging for authorities to trace the actions back to the perpetrators.

The discovery of this cybercrime campaign coincides with the FBI’s takedown of the botnet infrastructure used by Pawn Storm in January, also known as APT28 and Forest Blizzard, linked to the Russian GRU. Following this takedown, Trend Micro proceeded to uncover the Ngioweb botnet operated by Water Barghest. This Ngioweb botnet employs a new version of malware active since 2020, targeting various IoT devices, including EdgeRouter, Cisco, DrayTek, Fritz!Box, and Linksys. The ability to compromise such a broad range of devices is primarily due to exploiting both n-day and zero-day vulnerabilities.

Initial Infection Process

The infection process of IoT devices begins with the exploitation of both n-day and zero-day vulnerabilities. Water Barghest meticulously identifies vulnerable devices by leveraging public databases like Shodan, which catalog exposed devices and their IP addresses. Once identified, the group deploys malware directly into the memory of these devices. Although this infection is quite potent, it is not persistent, meaning that a simple reboot of the device can remove it from the system.

Upon compromising the devices, they connect to command-and-control servers to perform speed and name server tests. Following these tests, the devices are rapidly listed for sale on the proxy marketplace. Despite previous law enforcement actions targeting similar services, such as VPNFilter and the Cyclops Blink botnet, many IoT devices remain susceptible to such attacks. The high demand for anonymizing services from advanced persistent threat (APT) groups and other sophisticated threat actors ensures the continued prevalence of campaigns like those conducted by Water Barghest.

Mitigation Strategies for IoT Devices

Security Measures and Continuous Monitoring

Trend Micro emphasizes that the systematic exploitation of IoT device vulnerabilities by the Water Barghest group presents a serious threat, affecting hundreds of thousands of devices. To mitigate these risks, the security firm advises against exposing IoT devices to unnecessary internet connections. In addition, it is crucial to implement robust security measures and continuously monitor the devices to detect and prevent malicious activities.

One of the key strategies to safeguard IoT devices is the frequent updating and patching of firmware to address known vulnerabilities. Organizations and individuals should also disable any services and features on their IoT devices that are not being actively used. This helps to limit the attack surface available to cybercriminals. Deploying network segmentation can also be effective, isolating IoT devices from critical infrastructure to contain any potential breaches.

Importance of User Awareness

In a worrying development, cybersecurity firm Trend Micro has identified a major cybercrime campaign connected to the Water Barghest group, which is suspected of having ties to Russian state-sponsored hackers. Since 2020, this group has been involved in the rapid infection of around 20,000 Internet of Things (IoT) devices. These compromised devices are taken over and added to proxy networks within just ten minutes of the initial breach. The campaign uses highly efficient, automated tools to scale up its operations quickly, making these infected devices available for rent on proxy marketplaces almost immediately after they are compromised. This swift and efficient process allows the Water Barghest group to expand their reach and capabilities significantly. The campaign’s automation and speed mark a troubling evolution in cybercrime, with serious implications for digital security. The affected IoT devices serve as gateways for further malicious activities, emphasizing the need for increased vigilance and enhanced cybersecurity measures to counteract these sophisticated threats.

Explore more

Why Are Cross-Border Payments Still So Expensive in 2026?

Diverse data privacy laws and regulatory requirements across borders mean that mandatory compliance checks are often duplicated at every single stage of a payment’s journey. This fragmentation remains the primary reason why, despite the sophisticated digital tools available in 2026, the cost of moving value internationally has not plummeted as many expected. While domestic payment systems in major economies have

Android 15 Tops Market as Fragmentation Poses Security Risks

The 2026 data reveals that nearly 14 percent of the Android user base still relies on Android 13, highlighting the slow pace of migration to newer, safer platforms. While the latest iteration of the operating system has reached a dominant position in the market, the stubborn persistence of legacy software creates a complex security landscape. This fragmentation is not merely

How Are Instant Payments Reshaping Latin American Finance?

A significant maturity divide exists in Latin American finance, where world-leading adoption in Brazil contrasts sharply with structural barriers in countries like Mexico. As of 2026, the rapid expansion of real-time payment networks has moved beyond simple peer-to-peer transfers to become the definitive backbone of the regional economy. Between 2017 and 2024, the volume of these transactions increased by an

Domestic Activity Dominates Global Stablecoin Payments

Within the Asia-Pacific region, nearly eighty percent of stablecoin transaction volume remains within local borders or neighboring countries, highlighting a strong preference for regional liquidity. Recent data from 2026 shows that the grand vision of stablecoins as purely international remittance tools is being overshadowed by their utility in local markets. Global identifiable on-chain transfers show that billions in volume occur

Safaricom Launches M-PESA Tap-to-Pay Contactless Payments

Standing in a crowded supermarket queue during the evening rush often highlights the minor frustrations of digital payments when every second counts for weary commuters. The rapid evolution of mobile financial services has reached a significant milestone with the commercial debut of a new contactless interface designed to accelerate these moments of daily commerce. The new system allows for a