A map of the world overlaid with sock puppets connected by red thread

One sock fits all: the use and abuse of the NSOCKS botnet

NSOCKS blends malware with a residential proxy service that routes traffic through infected devices. Lumen saw web and Telnet attacks from those devices. This points to direct botnet activity. Some NSOCKS traffic exposed proxy source headers. This can help anti-abuse teams spot and block it. In tests in August 2024, 47% of sites allowed access, 42% blocked it, and 11% issued anti-bot checks. Authorities disrupted NSOCKS in July 2024, but some infected devices still attack honeypots.

  • NSOCKS combines malware with a residential proxy service that routes buyer traffic through infected consumer devices.
  • Lumen observed NSOCKS-infected devices attacking honeypots with web exploits and Telnet commands that match botnet malware activity.
  • NSOCKS traffic exposed proxy source headers, which let anti-abuse teams and website operators identify and block proxy endpoints.
  • Website testing showed many domains blocked or challenged NSOCKS traffic, which suggests stronger anti-bot responses than earlier measurements.
  • Authorities disrupted NSOCKS, yet formerly infected devices still attack honeypots and may remain active bots.
Published on Nov 19, 2024 | 7 minute read