Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

CanOworms and rented proxy networks: what defenders need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: A 633-server anonymization network, CanOworms, that commodity malware operators and suspected state-linked actors use to hide attack origin behind disposable relays and defeat IP blocklists and reputation scoring has been mapped by SecurityScorecard's STRIKE team. Shared proxy infrastructure is now a durable operational layer for intrusion concealment, not just a nuisance feed issue.

NHIMG editorial — based on content published by SecurityScorecard: LLMjacking: How Attackers Hijack AI Using Compromised NHIs

By the numbers:

Questions worth separating out

Q: How should security teams respond when attack traffic comes from proxy-for-hire networks?

A: Treat proxy traffic as an evasion layer, not proof of benign activity or a single campaign.

Q: Why do proxy networks make intrusion attribution so difficult?

A: Because the visible IP usually belongs to the relay, not the actor.

Q: What do defenders get wrong about IP blocklists in modern intrusion campaigns?

A: They treat a blocked address as a durable control when it is often only a temporary containment step.

Practitioner guidance

  • Correlate relay fingerprints with authentication telemetry Use JARM, JA4X, certificate traits, and destination patterns alongside login and SSH telemetry so a proxy network is detected as a reusable infrastructure pattern rather than isolated IP noise.
  • Reduce reliance on source IP as a trust signal Treat IP reputation and geolocation as weak indicators for access decisions, especially where credential spraying or command-and-control may route through rented relays.
  • Harden privileged and service-account authentication paths Prioritise MFA, short-lived credentials, and strict session controls on remote access, API endpoints, and service accounts that attackers can abuse through anonymizing infrastructure.

What's in the full report

SecurityScorecard’s full report covers the operational detail this post intentionally leaves for the source:

  • The certificate, JARM, and JA4X fingerprints used to identify CanOworms members across changing IP space
  • The host clustering and registration clues that helped separate relay nodes from unrelated infrastructure
  • The June 2026 traffic patterns that suggest distributed credential spraying and proxy-based abuse
  • The indicator set defenders can use to build detections around relay behaviour rather than static addresses

👉 Read SecurityScorecard’s analysis of the CanOworms anonymization network →

CanOworms and rented proxy networks: what defenders need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Shared relay infrastructure is becoming an attribution layer, not just an evasion tactic. CanOworms shows how commodity and suspected state-linked actors can converge on the same rented transport layer without sharing ownership or tooling. That weakens the old assumption that one malicious IP or one blocked ASN meaningfully identifies an adversary. Practitioners should read these networks as infrastructure markets that sit above individual campaigns, not as isolated malicious hosts.

A question worth separating out:

Q: Who is accountable when proxy infrastructure is used to conceal malicious access?

A: Accountability sits with the organisation operating the exposed service, the provider of the affected credentials or secrets, and the teams responsible for monitoring abnormal authentication. Frameworks such as MITRE ATT&CK and NIST SP 800-53 help map source concealment, credential abuse, and logging gaps to concrete defensive ownership.

👉 Read our full editorial: CanOworms shows how rented proxy networks obscure attacker origin



   
ReplyQuote
Share: