Researchers reported that Water Barghest has industrialized the compromise of internet-exposed IoT and router devices, using public scan data such as Shodan, long-lived datacenter infrastructure, known vulnerabilities, and at least one zero-day to deploy the Ngioweb malware and convert victims into rentable proxy nodes. Trend Micro said the group can move from initial exploitation to listing a device on a proxy marketplace in about 10 minutes, while LevelBlue linked the botnet’s monetization to the Nsocks service, which advertised nearly 30,000 global IPs at low daily prices. Observed targets have included Cisco IOS XE devices, EdgeRouter systems, Zyxel routers, Linear eMerge devices, and even Neato vacuum cleaners, with many infected hosts belonging to residential ISP users.
The activity extends a botnet lineage that researchers traced from a Win32.Ngioweb proxy botnet seen in 2018, to Linux infections on WordPress servers in 2019, and then to broad IoT targeting from 2020 onward. Earlier analysis by Netlab 360 found Linux.Ngioweb used a two-tier C2 design, DGA fallback domains, anti-analysis features, and encrypted Stage-2 communications, while newer reporting said the operators have kept the malware largely stable but expanded their exploit arsenal, altered C2 request paths, and added TXT-record authenticity checks to hinder sinkholing. Researchers assessed that a substantial share of one proxy marketplace’s exit nodes were compromised devices running Ngioweb, underscoring how mature criminal operators are turning vulnerable IoT systems into persistent anonymization infrastructure for sale or reuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
In 2024, researchers assessed that a significant portion of the exit nodes offered by a specific proxy marketplace were devices infected with Ngioweb.
By 2024, LevelBlue found that Nsocks was advertising almost 30,000 proxy IPs globally, with infected systems sold cheaply as residential proxies.
By 2024, Trend Micro assessed that Water Barghest had largely automated the workflow from exploiting exposed IoT devices to listing them for rent as proxy nodes within about 10 minutes.
By 2024, researchers found processes on multiple EdgeRouter devices that they identified as a new version of Ngioweb behaving similarly to earlier variants.
In spring 2024, LevelBlue observed Ngioweb scanning for vulnerable devices and delivering Ngioweb payloads, including activity targeting Linear eMerge systems.
In October 2023, Water Barghest infrastructure was used to deploy a zero-day against Cisco IOS XE devices, infecting tens of thousands of routers.
LevelBlue reported that Nsocks was created in July 2022 after other illicit residential proxy services such as 911, vip72, and LuxSocks were taken down.
LevelBlue reported that Nsocks advertised 14,000 systems in 2022, showing the scale of the proxy marketplace used to monetize infected devices.
In 2020, Netlab reported that the actor was exploiting nine different n-day vulnerabilities affecting IoT devices including QNAP, Netgear, and D-Link products.
By 2020, Ngioweb operations had shifted from primarily compromised web servers to IoT devices, with samples compiled for multiple processor architectures.
Netlab said its detection system first highlighted a Linux.Ngioweb sample on May 27, 2019, identifying a Linux variant of Win32.Ngioweb.
During the 2019 investigation, researchers registered a DGA-generated domain used by Linux.Ngioweb and observed 2,692 bot IPs connecting to it, confirming broad compromise of mostly WordPress servers.
In 2019, Netlab documented Linux.Ngioweb as a Linux proxy botnet with added DGA functionality and observed infections primarily on WordPress web servers.
In 2018, the command-and-control domain that gave Ngioweb its name was registered, and Check Point Research reported Ngioweb being distributed by the Ramnit trojan as a Windows proxy botnet.
Trend Micro reported that some Ngioweb samples date back to 2017, marking the earliest known artifacts of the malware family.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcetrendmicro.com
Open sourcelevelblue.com
Open sourcetrendmicro.com
Open sourceblog.netlab.360.com
Open sourceblog.netlab.360.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.