Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 29 March, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Who else is using your servers? Massive underground market selling over 70,000 hacked servers exposed

by The Gurus
June 16, 2016
in Editor's News

EXPOSED

Share on FacebookShare on Twitter

Kaspersky Lab researchers have investigated a global forum where cybercriminals can buy and sell access to compromised servers for as little as $6 each. The xDedic marketplace, which appears to be run by a Russian-speaking group, currently lists 70,624 hacked Remote Desktop Protocol (RDP) servers for sale. Many of the servers host or provide access to popular consumer websites and services, and some even have software installed for direct mail, financial accounting and Point-of-Sale (PoS) processing. They can be used to target the owners’ infrastructures or as a launch-pad for wider attacks, while the owners, including government entities, corporations and universities, have little or no idea of what’s happening.
xDedic is a powerful example of a new kind of cybercriminal marketplace: well-organised and supported. The marketplace caters to everyone, from entry-level cybercriminals to APT groups, and provides fast, cheap and easy access to legitimate organisational infrastructure that keeps their crimes below the radar for as long as possible.
A European internet service provider (ISP) alerted Kaspersky Lab to the existence of xDedic and the companies worked together to investigate how the forum operates. The process is simple and thorough: hackers break into servers, often through brute-force attacks, and bring the credentials to xDedic. The hacked servers are then checked for their RDP configuration, memory, software, browsing history and more – all features that customers can search through before buying.  Following this, they are added to a growing online inventory that includes access to:

  • Servers belonging to government networks, corporations and universities
  • Servers tagged for having access to or hosting certain websites and services, including gaming, betting, dating, online shopping, online banking and payment, cell phone networks, ISPs and browsers
  • Servers with pre-installed software that could facilitate an attack, including direct mail, financial and PoS software
  • All supported by a range of hacking and system information tools.

From as little as $6 per server, members of the xDedic forum can access a server’s data in its entirety and also use it as a platform for further malicious attacks. This could potentially include targeted attacks, malware, DDoS, phishing, social-engineering and adware attacks, among others.
The servers’ legitimate owners, namely reputable organisations including government networks, corporations and universities, are often unaware that their IT infrastructure has been compromised. Further, once a campaign has been completed, the attackers can put access to the server back up for sale and the whole process can begin again.
The xDedic marketplace seems to have opened for business some time in 2014 and has grown significantly in popularity since the middle of 2015. In May 2016, it listed 70,624 servers from 173 countries for sale, posted in the names of 416 unique sellers.  The top ten countries affected are: Brazil, China, Russia, India, Spain, Italy, France, Australia, South Africa and Malaysia.
The group behind xDedic appears to be Russian-speaking and claims that it merely provides a trading platform and has no links or affiliations to the sellers.
“xDedic is further confirmation that cybercrime-as-a-service is expanding through the addition of commercial ecosystems and trading platforms. Its existence makes it easier than ever for everyone, from low-skilled malicious attackers to nation-state backed APTs, to engage in potentially devastating attacks in a way that is cheap, fast and effective. The ultimate victims are not just the consumers or organisations targeted in an attack, but also the unsuspecting owners of the servers. Additionally, the legitimate owners are likely to be completely unaware that their servers are being hijacked again and again for different attacks, all conducted right under their nose”, said Costin Raiu, Director, Global Research and Analysis Team, Kaspersky Lab.
Kaspersky Lab advises organisations to:

  • Install a robust security solution as part of a comprehensive, multi-layered approach to IT infrastructure security
  • Enforce the use of strong passwords as part of the server authentication process
  • Implement a continuous process of patch management
  • Undertake a regular security audit of the IT infrastructure
  • Consider investing in threat intelligence services which will keep the organisation informed of emerging threats and offer an insight into the criminal perspective to help them assess their level of risk.
FacebookTweetLinkedIn
ShareTweetShare
Previous Post

Security Experts Offer Password Hygiene Tips

Next Post

Data Breach Costs Rising, Now $4 million per Incident

Recent News

Blue Logo OUTPOST24

New Research Examines Traffers and the Business of Stolen Credentials

March 28, 2023

How to Succeed As a New Chief Information Security Officer (CISO)

March 28, 2023

The Importance of Data Security and Privacy for Individuals and Businesses in the Digital Age

March 28, 2023
penetration testing

Cymulate’s 2022 Cybersecurity Effectiveness Report reveals that organizations are leaving common attack paths exposed

March 28, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information