Researchers identified Faceless as a long-running malware proxy service that rented access to tens of thousands of compromised systems, with a heavy reliance on exposed IoT devices to provide residential and device-based proxy infrastructure for cybercriminal activity. The service was also tied to adjacent fraud-enablement offerings, including email-bombing and Social Security number lookup services, indicating that it operated as more than a simple proxy marketplace.
The investigation connected Faceless to the Russian-speaking cybercriminal MrMurza, who was previously associated with the iSocks proxy service and activity across underground forums involving botnets, stolen payment cards, and drops. By correlating aliases, email addresses, Liberty Reserve account details, leaked forum messages, and password reuse, investigators assessed that the operation was likely linked to Denis Viktorovich Pankov in Russia, giving a probable real-world identity to a major criminal proxy platform.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
In March 2023, Faceless began marketing an SSN lookup service that claimed access to a very large Social Security number database. It bundled identity data with geographically corresponding proxy access for about $9.
In February 2023, Faceless relaunched an email-bombing service capable of flooding a victim's inbox with tens of thousands of junk messages. The move showed the service expanding beyond proxy rentals into broader fraud-enablement offerings.
In January 2023, Faceless advertised that it would pay for previously undocumented IoT vulnerabilities. It said it wanted IoT exploits affecting at least 5,000 systems identifiable through Shodan.
In September 2016, MrMurza told iSocks users that the service would be phased out in favor of Faceless. He offered existing iSocks users free Faceless registration before new-user registration fees of $50 to $100 took effect.
A 2016 Southern District of New York document tied Liberty Reserve account U1018928 to a Vadim Panov and the email address lesstroy@mgn.ru. This provided a key attribution link used in the Faceless investigation.
In a 2014 private message to the administrator of Verified, MrMurza said he had sold stolen Italian credit cards and drops services. He also said he had used the nickname AccessApproved on other forums and identified Liberty Reserve account U1018928 as his.
Faceless evolved from iSocks, a proxy service launched in 2014 that routed malicious traffic through compromised computers. Before launch, MrMurza had sought a partner on the Verified forum to help open a proxy service backed by a malware botnet.
U.S. authorities seized Liberty Reserve in 2013 and charged its founders with facilitating billions of dollars in money laundering tied to cybercrime. The seizure later became relevant to tracing account U1018928.
Flashpoint said MrMurza had been active in the Russian-speaking cybercrime underground since at least September 2012. The activity included botnet-related work and selling drops used for money laundering and cash-out schemes.
Intel 471 reported that the user AccessApproved joined the Russian crime forum Zloy in January 2012 from an IP address in Magnitogorsk, Russia. A 2012 private message also showed AccessApproved requesting payment to Liberty Reserve account U1018928.
KrebsOnSecurity published an attribution analysis linking the Faceless malware proxy service to the Russian-speaking cybercriminal MrMurza and tracing associated aliases, emails, and password reuse to a probable real-world identity connected to Denis Viktorovich Pankov in Russia. The report also described Faceless as a long-running service built on tens of thousands of compromised systems, especially exposed IoT devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
flashpoint-intel.com
Open sourceintel471.com
Open sourcekrebsonsecurity.com
Open sourceshodan.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.