Water Barghest is a financially motivated cybercriminal intrusion set focused on compromising internet-exposed IoT and edge devices and converting them into proxy infrastructure for resale. The actor is associated with a mature, highly automated operation that covers the full lifecycle from identifying vulnerable devices through public internet-scan data, exploiting known vulnerabilities and at least one reported zero-day, deploying malware, and rapidly onboarding compromised systems into a commercialized proxy ecosystem. Security reporting links the group to the Ngioweb malware family and to large-scale proxy botnet activity involving tens of thousands of compromised devices. The group’s operations have evolved over multiple years. Ngioweb activity has been observed since at least 2018, initially associated with proxy botnet functionality on Windows systems, later with Linux-based infections on web servers, and from 2020 onward with a sustained focus on IoT devices. Water Barghest has been observed targeting routers, NAS appliances, and other Linux-based embedded systems across multiple processor architectures. Reported victim device types include products from vendors such as Cisco, QNAP, Netgear, D-Link, and Ubiquiti. By 2024, the actor’s IoT botnet was assessed to have reached operational maturity, with infections observed on edge routing platforms and a substantial share of proxy exit capacity on at least one marketplace attributed to compromised devices running Ngioweb. Operationally, Water Barghest emphasizes automation, scale, and speed. The actor has been described as running VPS-based workers that continuously scan for exposed devices, validate exploitability, and deploy payloads. On successful compromise, Ngioweb is executed in memory on Linux-based IoT devices, registers with command-and-control infrastructure, and is then directed to connect to proxy access infrastructure where the device is tested and prepared for rental. The time from exploitation to marketplace availability has been observed to be on the order of minutes. The malware on IoT devices has been described as non-persistent, indicating an opportunistic, high-volume model optimized for rapid monetization rather than long-term stealth on any single node. Water Barghest demonstrates capabilities spanning reconnaissance, scanning, initial access, malware deployment, defense evasion through obfuscation, persistence tradeoffs favoring in-memory execution, and post-compromise monetization via proxy resale. The actor’s infrastructure was also linked to the October 2023 exploitation of a Cisco IOS XE zero-day that infected large numbers of routers, further underscoring its access to effective exploit capability against edge devices. Water Barghest is commonly discussed alongside Water Zmeu as part of the broader ecosystem of IoT proxy botnet operators, but it is tracked as a distinct intrusion set centered on criminal proxy monetization rather than state-directed espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Water Barghest operates a large botnet of over 20,000 compromised IoT devices, primarily used as proxies. The group leverages vulnerabilities discovered via internet scan databases to compromise devices, which are then used to facilitate malicious activities for themselves and other threat actors.
Automates the end-to-end compromise of vulnerable IoT devices, deploys Ngioweb malware to turn them into proxy nodes, and monetizes access by listing infected devices on a proxy marketplace.
Operates a mid-sized proxy/IoT botnet used for anonymization and monetization, with rapid exploitation of exposed IoT devices and resale of compromised devices on residential proxy marketplaces. Its infrastructure was also used to deploy a zero-day against Cisco IOS XE devices in October 2023.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.