Resources

STRIKE

Resource Library

Clear filters

Catch Me If You Can: Inside the Anonymization-for-Hire Network

August 10, 2026

Catch Me If You Can: Inside the Anonymization-for-Hire Network
In this briefing, Wade Lance VP, Product Marketing & Sales Enablement walks through STRIKE’s newest report Catch Me If You Can. Wade takes viewers inside the full commercial stack behind CanOworms — tenants, relay fleet, resellers, and landlord ASNs — and explains why treating a threat-feed-flagged C2 as a single actor’s infrastructure can lead defenders to the wrong conclusion entirely. This isn’t a read-through of the report. It’s Wade’s field-tested take on what the findings mean for how security teams should actually hunt this kind of infrastructure. Download the briefing now.
STRIKE Alert
STRIKE News
STRIKE Team
Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire

August 5, 2026

Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire
Blocklists, geolocation, and ASN reputation all share one assumption: that an IP tells you who’s behind it. CanOworms is built to break that assumption. STRIKE identified 633 confirmed member servers operating as a shared Squid/SOCKS/OpenVPN/IPsec relay fleet — not a command-and-control panel, but the disposable front in front of one. Dozens of tenants, from Remcos and Quasar operators to suspected APT41 and APT43/APT37 infrastructure, have used these same relays. The operator is unattributed by design. Many tenants, one set of relays. What you’ll learn: How the mesh was found. A shared self-signed TLS certificate (O=kickass), corroborated by JARM and JA4X fingerprints, exposed 633 confirmed nodes out of 748 candidate IPs across a dozen dense /24 blocks, six-plus hosting providers, and more than a dozen countries. How it’s run. Five Czech Republic control-plane hosts manage the fleet in a centralized “star” topology, with one node alone touching roughly 256 others and a fleet-wide ~35-second heartbeat back to a single collector — a pressure point defenders can watch. Who’s renting it, and who isn’t. A reseller called “PrivacyFirst” (MAXKO d.o.o., AS214366) surfaces in the paper trail, but only a fraction of its address space actually carries the mesh certificate — a case study in why reseller identity isn’t operator identity isn’t tenant identity. Where the attack traffic lands. Suspected credential-spray traffic exits the fleet toward MikroTik routers, TR-069 CPE, and Hikvision cameras — concentrated in South Africa, India, the U.S., Brazil, and Bangladesh. Commodity-crime geography, not espionage-target geography. Why IP-based defense fails here, and what to fingerprint instead. The report lays out why durable detection means tracking how the infrastructure was built (certificate thumbprints, JARM, JA4X, service-stack signature) rather than chasing IPs that get burned and replaced faster than blocklists can keep up. Full IOCs and MITRE ATT&CK mapping. Appendix A publishes the complete fingerprint set — ready to drop into detection tooling — mapped to ATT&CK Resource Development and C2 techniques (T1583.003, T1090.002, T1571). Download “Catch Me If You Can” for the complete CanOworms research, including the fingerprint methodology, control-plane analysis, and the full IOC appendix.
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity

August 5, 2026

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
STRIKE Team
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers

July 9, 2026

LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
SecurityScorecard’s New Driftnet Engine Reveals America’s Small-Town Surveillance Blind Spot

May 14, 2026

SecurityScorecard’s New Driftnet Engine Reveals America’s Small-Town Surveillance Blind Spot
SecurityScorecard researchers used Driftnet’s internet-scale discovery capabilities to analyze the network footprint of a small U.S. municipal utility provider that also operates as the town’s internet service provider (ISP). The investigation identified widespread exposure across internet-facing systems, including vulnerable surveillance equipment, exposed Industrial Control Systems (ICS), weak encryption configurations, and End-of-Life (EoL) Windows devices. The utility provider operates its own Autonomous System (AS), meaning internet connectivity and critical infrastructure services exist within the same broader operational environment. This convergence creates a concentrated point of failure where disruption to one service can affect others across the community. Over a six-month period, Driftnet identified 1,498 services across 692 IP addresses. Of those, 446 IPs (64%) exhibited at least one technical issue that increased exposure risk. SecurityScorecard’s Driftnet engine identifies 150% more internet-facing services than previous scanning methodologies, uncovering exposures traditional approaches miss. Findings included: 30 instances of Dahua and Hikvision surveillance equipment inside the entire footprint of the utilities AS. Banned internet protocol (IP) cameras could enable Man-in-the-Middle (MitM) attacks, Distributed Denial of Service (DDoS) attacks, malware-based campaigns, and more. Exposed ICS, SCADA, and OT-related services directly reachable from the internet. At least three /24 clusters hosting ICS or IOT services and consumer devices on the same broadcast domain. Weak or misconfigured encryption across 382 IP addresses, in addition to cleartext FTP and HTTP and unrecognized Certificate Authorities. EoL Windows hosts reachable via Server Message Block (SMB) and NetBIOS. A relic from the past, rarely ever makes an appearance outside of OT environments. 25 Known Exploited Vulnerabilities (KEVs) identified across internet-facing services. Convergence of a utility and ISP creates a single point of failure. Power delivery and internet reside on the same AS. Incidents on one impacts the other. The research also identified multiple network segments where consumer-grade devices, surveillance systems, and ICS-related technologies operated within the same local network environment. This lack of segmentation increases the likelihood that compromise of a lower-security system could enable lateral movement toward operational infrastructure. To understand the full scope of the findings, download the full report today to see how Driftnet delivers the visibility organizations need to move from reactive security to continuous, threat-informed defense.
STRIKE Alert
STRIKE News
STRIKE Team
Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence

February 9, 2026

Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence
While the world debates Moltbook’s role in the AI ecosystem, it is just the tip of the iceberg of Titanic risk. SecurityScorecard’s STRIKE team uncovered what lurks beneath: Thousands of exposed OpenClaw (Moltbot) control panels vulnerable to takeover through misconfigured access and known exploits.
STRIKE Team
What Are Moltbot and Moltbook and What Happens When Agentic AI Assistants Scale Without Security

February 3, 2026

What Are Moltbot and Moltbook and What Happens When Agentic AI Assistants Scale Without Security
Moltbot AI assistants and their social media platform Moltbook have sparked AGI fears in recent days, but the real risk is access. Learn what Moltbook and Moltbot are (now OpenClaw and formerly known as Clawdbot), why it’s not artificial general intelligence (AGI), and how to reduce security exposure.
The Quiet Siege II

January 23, 2026

The Quiet Siege II
Explore a fictional depiction of a DDoS attack in The Quiet Siege Part II: Life, Interrupted. The scenario described does not represent a real attack, organization, or incident.
The Quiet Siege I

January 23, 2026

The Quiet Siege I
Explore a fictional depiction of a DDoS attack. The scenario described does not represent a real attack, organization, or incident.
Latin America as a Proving Ground: Cybercriminal Innovation and Escalation

January 23, 2026

Latin America as a Proving Ground: Cybercriminal Innovation and Escalation
The Conti ransomware group, active since late 2019, quickly became one of the most aggressive forces in the world of cybercrime. Known for “big game hunting” and its double-extortion model: stealing data before encrypting systems, Conti targeted major institutions in healthcare, education, and infrastructure.
Operation WrtHug Exposed: The Router Hack You Need to Know

December 10, 2025

Operation WrtHug Exposed: The Router Hack You Need to Know
SecurityScorecard STRIKE threat intelligence researchers uncovered a suspected China-backed campaign by chasing an extremely unusual 100‑year certificate that kept appearing on routers. Here is how the research team hunted the signal, what they found, and the practical steps security teams can take to protect themselves.
Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router

November 19, 2025

Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router
SecurityScorecard’s STRIKE team uncovers how attackers turned thousands of ASUS routers into a worldwide spy network.
STRIKE Team
When SaaS Trust Becomes a Threat: Insights from the Salesloft Drift Compromise

September 10, 2025

When SaaS Trust Becomes a Threat: Insights from the Salesloft Drift Compromise
The STRIKE team has been analyzing the Salesloft Drift breach that spread into Salesforce environments. Discover what the breach tells us about supply chain security, how attackers abused OAuth tokens, what data is exposed, and defensive actions to take next.
STRIKE Team
From the Depths of the Shadows: IRGC and Hacker Collectives Of The 12-Day War

August 5, 2025

From the Depths of the Shadows: IRGC and Hacker Collectives Of The 12-Day War
From reconnaissance to propaganda to payloads, this is how Iran’s digital foot soldiers mobilized across borders and platforms during the war with Israel in June 2025.
STRIKE Team
9 Year Old Vulnerability Still Affecting Thousands (CVE-2016-10033)

July 7, 2025

9 Year Old Vulnerability Still Affecting Thousands (CVE-2016-10033)
On July 07, 2025, CVE-2016-10033 was added to CISA’s list of Known Exploited Vulnerabilities (CISA-KEV).
STRIKE Alert
Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign

June 23, 2025

Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign
SecurityScorecard’s STRIKE team uncovered a new China-Nexus ORB Network targeting the United States and Southeast Asia. Read the report to gain an in-depth look at the LapDogs ORB network, its custom malware, and its role in cyberespionage.
STRIKE Team
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability (CVE-2025-32433) Added to CISA KEV

June 10, 2025

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability (CVE-2025-32433) Added to CISA KEV
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability (CVE-2025-32433)
STRIKE Alert
SecurityScorecard Advisory: Synacor Zimbra Collaboration Suite XSS Vulnerability (CVE-2024-27443) Added to CISA KEV

May 20, 2025

SecurityScorecard Advisory: Synacor Zimbra Collaboration Suite XSS Vulnerability (CVE-2024-27443) Added to CISA KEV
SecurityScorecard Advisory: Synacor Zimbra Collaboration Suite XSS Vulnerability (CVE-2024-27443)
STRIKE Alert
SecurityScorecard Advisory: Apache HTTP Server Improper Escaping of Output Vulnerability (CVE-2024-38475) Added to CISA KEV

May 6, 2025

SecurityScorecard Advisory: Apache HTTP Server Improper Escaping of Output Vulnerability (CVE-2024-38475) Added to CISA KEV
SecurityScorecard Advisory: Apache HTTP Server Improper Escaping of Output Vulnerability (CVE-2024-38475) \r\n
STRIKE Alert
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590) Added to CISA KEV

April 7, 2025

SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590) Added to CISA KEV
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590)
STRIKE Alert