IPStorm is a cross-platform botnet malware family used to compromise internet-connected devices and convert them into a proxy network for criminal use. First identified on Windows in 2019, it later expanded to Linux and macOS, and reporting has also associated the broader operation with Android devices. The malware was used to build a large for-profit proxy service that sold access to infected systems so customers could route traffic through victim devices and obscure their own activity.
Its core role is botnet-backed proxying, but reported capabilities also include reverse shell access and ad fraud functionality, particularly in the macOS port. On Linux, IPStorm has been observed establishing persistence through a systemd service. The macOS variant has been described as more limited and not implementing persistence. Reporting has linked its spread at least in part to SSH brute-forcing, and the operation compromised thousands of devices globally.
IPStorm is notable for its evolution from a Windows-focused threat into a broader multi-platform botnet aligned with the growing abuse of residential and endpoint proxy infrastructure. Law enforcement action publicly attributed the malware’s development and deployment from 2019 through 2022 to Sergei Makinin, a Russian and Moldovan national, and dismantled infrastructure associated with the botnet and its proxy service. The malware’s primary impact was enabling unauthorized use of victim systems as anonymizing proxies for downstream cybercrime rather than destructive effects on the infected hosts themselves.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet mentioned as an example of prior law-enforcement disruption in the proxy ecosystem.
Named as a botnet that has faced law enforcement scrutiny since 2021.
Referenced as a botnet that has faced law enforcement scrutiny/takedown activity since 2021.
Mentioned in passing as another Linux threat.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.