STRIKE

Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire

Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire

Blocklists, geolocation, and ASN reputation all share one assumption: that an IP tells you who’s behind it. CanOworms is built to break that assumption. STRIKE identified 633 confirmed member servers operating as a shared Squid/SOCKS/OpenVPN/IPsec relay fleet — not a command-and-control panel, but the disposable front in front of one. Dozens of tenants, from Remcos and Quasar operators to suspected APT41 and APT43/APT37 infrastructure, have used these same relays. The operator is unattributed by design. Many tenants, one set of relays.

What you’ll learn:

  • How the mesh was found. A shared self-signed TLS certificate (O=kickass), corroborated by JARM and JA4X fingerprints, exposed 633 confirmed nodes out of 748 candidate IPs across a dozen dense /24 blocks, six-plus hosting providers, and more than a dozen countries.
  • How it’s run. Five Czech Republic control-plane hosts manage the fleet in a centralized “star” topology, with one node alone touching roughly 256 others and a fleet-wide ~35-second heartbeat back to a single collector — a pressure point defenders can watch.
  • Who’s renting it, and who isn’t. A reseller called “PrivacyFirst” (MAXKO d.o.o., AS214366) surfaces in the paper trail, but only a fraction of its address space actually carries the mesh certificate — a case study in why reseller identity isn’t operator identity isn’t tenant identity.
  • Where the attack traffic lands. Suspected credential-spray traffic exits the fleet toward MikroTik routers, TR-069 CPE, and Hikvision cameras — concentrated in South Africa, India, the U.S., Brazil, and Bangladesh. Commodity-crime geography, not espionage-target geography.
  • Why IP-based defense fails here, and what to fingerprint instead. The report lays out why durable detection means tracking how the infrastructure was built (certificate thumbprints, JARM, JA4X, service-stack signature) rather than chasing IPs that get burned and replaced faster than blocklists can keep up.
  • Full IOCs and MITRE ATT&CK mapping. Appendix A publishes the complete fingerprint set — ready to drop into detection tooling — mapped to ATT&CK Resource Development and C2 techniques (T1583.003, T1090.002, T1571).

Download “Catch Me If You Can” for the complete CanOworms research, including the fingerprint methodology, control-plane analysis, and the full IOC appendix.

Register to get it now: