Blog

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.

Somewhere on the internet, roughly 633 servers are doing a brisk business in hiding people. SecurityScorecard’s STRIKE Threat Intelligence Team mapped this rental network, dubbed CanOworms, along with its suspected end users: garden-variety malware crews sitting alongside suspected nation-state operators, all routing their malicious campaigns through the same disposable servers.

A proxy-for-hire network sells distance and anonymity. Rent access, and your traffic exits through someone else’s server and someone else’s IP address, so tracing an intrusion back leads to a rented relay, not the attacker. That lets them hide the true origin of malware, fraud, and intrusion attempts behind disposable IP addresses that get replaced faster than defenders can place them on a blocklist.

That kind of covert operation defeats the tools defenders lean on most: IP blocklists, reputation scoring, and geography.

STRIKE’s partners have tied suspected China-nexus and North Korea-nexus actors to the network, each at low confidence and each as one renter among many, not as owners. SecurityScorecard built this research alongside partners FalconFeeds and Malanta, pairing their intelligence with STRIKE’s own analysis. 

Read the full technical CanOworms report here.

Infrastructure designed to mask attackers

CanOworms is not a single hacking group or one actor’s private command-and-control network. It functions more like a service or infrastructure whose product is passing other people’s traffic, not the toolkit of a bespoke malware controller.

Its servers run a consistent mix of proxy and VPN services that relay traffic for customers. Public threat intelligence has associated servers in the network with malware including Remcos, Quasar, NanoCore, NetWire, AsyncRAT and Loki.

It is spread deliberately thin over more than six unrelated hosting providers in at least a dozen countries.

This setup allows attackers to hide behind rented servers rather than expose their own infrastructure. Malicious traffic appears to originate from the relay, not the person behind it. When one server is blocked or taken down, the attacker can move to another.

One certificate revealed more than 600 servers

The investigation began with a single server connected to an unrelated intrusion report. On its own, the host appeared unremarkable. But it presented a self-signed TLS certificate containing placeholder values and an unusual organization name — ”kickass.” Those details looked less like the identity of a legitimate service and more like throwaway values an operator entered once while creating the network.

STRIKE searched for other systems presenting the same certificate and found hundreds of hosts grouped within densely populated address blocks.

The certificate alone was not enough to confirm membership. Other unrelated servers could reuse the same text, either deliberately or by coincidence. STRIKE therefore combined it with two independently derived fingerprints powered by SecurityScorecard’s Driftnet, JARM and JA4X. These fingerprints characterize a server’s TLS behavior and certificate structure.

Using that three-signal test, STRIKE confirmed 633 CanOworms servers observed during a 180-day window. Another subset carried the same certificate wording but failed the corroborating tests and were excluded from the fleet count.

STRIKE also observed a communication pattern in which dozens of nodes send regular heartbeats to a consistent IP that could signal that nodes are online, using management protocols.

The investigation had moved from one suspicious server to a purpose-built commercial network.

Disposable fronts hide the real infrastructure

The architecture challenges a common assumption about malicious IP addresses. Threat feeds have previously classified individual servers in the fleet as malware command-and-control infrastructure. STRIKE assesses that many of those addresses are instead disposable relay points sitting in front of the real backend.

The servers send traffic to a wide range of destinations, which is more consistent with a proxy serving multiple customers than a command server supporting one malware family.

For defenders, blocking one of these addresses may interrupt activity, but it cannot remove the infrastructure behind the attack because the customer can always shift to another relay.

CanOworms is designed to launder and cover these kinds of changes. Its servers are distributed across unrelated hosting providers and countries. The network also uses leased address space that can be dropped once it accumulates too many abuse complaints or blocklist entries.

STRIKE traced related infrastructure and commercial identities back to at least 2017, indicating a long-running anonymization business rather than a temporary network created for one campaign.

Live attack traffic

STRIKE observed several traffic patterns leaving CanOworms servers.

During June 2026, dozens of fleet nodes contacted concentrated groups of external systems over SSH. In one case, 48 CanOworms servers contacted 50 hosts in one address block over several days.

The activity resembles distributed credential spraying. Many of the systems contacted by the network appeared to be consumer and small-business edge devices, including routers, remote-management equipment and security cameras.

The evidence does not show whether the CanOworms operator initiated the activity or whether customers routed their own tools through the service. It does show that live, attack-shaped traffic is exiting through the network.

Tracking the network beyond IP addresses

Locating the people running CanOworms proved to be elusive. STRIKE traced one promising lead deep into the control plane, only to find it dissolved into an innocent third party sharing space with the real operator. That finding turned out to be some of the clearest evidence of how the network is designed: every control-plane host is buried inside small, benign-looking, borrowed infrastructure, engineered so that anyone tracing ownership lands on a bystander instead. 

Multiple unrelated nation-state and criminal groups turning up on the same certificate-defined server pool doesn’t mean one of them secretly owns it. It’s closer to the reverse: proof that the pool works exactly as a shared, for-hire infrastructure business should.

What defenders can do about it 

CanOworms is designed to make common infrastructure controls less reliable.

IP reputation has limited value when addresses are regularly replaced. Geolocation and hosting-provider reputation are less useful when servers are spread across multiple countries and unrelated providers. A command-and-control indicator may identify only the relay, not the attacker’s actual infrastructure.

STRIKE is publishing the TLS certificate and the JARM and JA4X signatures associated with CanOworms. These fingerprints can help defenders identify network members even when their IP addresses change.

The indicators will not last forever. They are more like a living membrane of proxy servers, rather than a static set of IPs, with nodes rotating in and out of service. The operator can change certificates or rebuild the server configuration. But they give defenders a stronger starting point than a static list of IP addresses.

CanOworms shows how the market for services aimed at APTs and cybercriminals is diversifying and continuing to grow. A server connected to several unrelated malware families or threat actors may not belong to any one of them. It may simply be the rented infrastructure used by all of them.

As state-sponsored and financially motivated threat actors increasingly converge on shared, commercially operated infrastructure to obscure their origins, CanOworms is best understood not as a botnet or a command-and-control network but as an anonymization service for hire, laundered through other people’s infrastructure at every layer.

The network sits alongside a broader pattern SecurityScorecard research has previously documented, including the LapDogs ORB and Operation WrtHug, in which China-nexus actors increasingly rent rather than build the infrastructure that hides them. This convergence of state and criminal tenants on identical relay space is precisely what makes the infrastructure durable: it is priced, marketed, and re-let, not staged for a single campaign, and it will outlast any one operator’s use of it.

Read the full CanOworms report for the complete evidence trail: who’s renting the network, how it moves address space to dodge takedowns, and what its architecture reveals about where commercial cybercrime infrastructure is headed next.

We drew internet-scan, threat-feed, and registration data from SecurityScorecard’s own Driftnet, as well as from VirusTotal, abuse.ch, and RIPE.

To learn how Driftnet-powered intelligence can help you identify and reduce exposure across your ecosystem, visit securityscorecard.com or request a demo.

SecurityScorecard built this research in collaboration with FalconFeeds and Malanta, combining their intelligence with our own analysis. Some findings reflect their direct observations, reported to us and included as working hypotheses. We hold ourselves to a clear standard: we only present data as confirmed when we’ve verified it independently. That distinction protects the integrity of this research and respects the work our partners contributed.

About SecurityScorecard STRIKE Team

SecurityScorecard’s STRIKE team is an elite squad of cybersecurity experts who have spent decades as intelligence analysts, threat hunters, and military cyber operators. The team processes more than 12 billion daily security signals, transforming data into actionable insights for security operations centers. 

STRIKE’s intelligence is created by the team itself, not purchased from others, allowing them to deliver real-time information that lets teams “strike first” against threats. By analyzing global telemetry, SSL/TLS logs, and dark web activity, STRIKE creates unique, proprietary, accurate, and timely threat intelligence that helps organizations defend against active and emerging threats. 

For media inquiries, contact us here.