Wenn ein Exploit erfolgreich ist, laden die kompromittierten IoT-Geräte ein Skript herunter, das Ngioweb-Malware-Samples durchgeht, die für verschiedene Linux-Architekturen kompiliert wurden. Wenn eines der Samples problemlos läuft, wird die Malware Ngioweb im Speicher des IoT-Geräts des Opfers ausgeführt.
Ngioweb
Ngioweb is a long-running proxy botnet malware family that has operated since at least 2017–2018 and has evolved across Windows, Linux server, router, and IoT environments.
Profile source: Mallory opens in a new tabNgioweb
Family profile
Ngioweb is a long-running proxy botnet malware family that has operated since at least 2017–2018 and has evolved across Windows, Linux server, router, and IoT environments. Its core purpose is to convert compromised systems into proxy nodes that can be used for back-connect access, relay operations, and commercial residential proxy services. The malware has been associated with criminal monetization of infected devices through proxy marketplaces and has also appeared on infrastructure later abused by espionage actors.
Early activity linked Ngioweb to Windows infections distributed at scale by Ramnit in 2018, where Ramnit functioned as a loader for Ngioweb. In that phase, Ngioweb established persistence on Windows systems, used process hollowing for execution, and communicated through a staged command-and-control architecture protected with layered encryption and authenticity checks. Researchers estimated that this campaign infected well over one hundred thousand systems and primarily used them as malicious proxy servers.
By 2019, Linux variants were observed on compromised web servers, including WordPress-hosted systems, and later the malware shifted heavily toward Linux-based routers, NAS appliances, and other IoT devices. From 2020 onward, operators deployed Ngioweb across many Linux architectures after exploiting known vulnerabilities in exposed devices. On IoT targets, the malware commonly executes directly in memory and is often non-persistent, allowing compromised devices to be rapidly enrolled into proxy infrastructure while reducing forensic artifacts on disk. Infections on internet-facing routers such as EdgeRouter devices have also been documented.
Ngioweb supports multifunctional proxy behavior, including back-connect and relay modes over both IPv4 and IPv6 and across TCP and UDP. Infected devices register with command-and-control infrastructure, beacon system metadata, and may then be instructed to connect to proxy access points where they are tested and prepared for resale as rentable proxy nodes. Later variants retained the family’s original proxy-centric design while adding or maintaining domain generation functionality and anti-sinkholing measures such as DNS-based authenticity validation. Samples are also known for obfuscation and defense-evasion features.
The malware has been tied to the threat cluster commonly tracked as Water Barghest, which industrialized exploitation of vulnerable IoT devices and automated their conversion into proxy nodes for sale. That activity targeted a broad range of internet-exposed Linux-based embedded devices and routers. Ngioweb infections have been monetized through underground and criminal proxy services, with a large proportion of infected nodes appearing to be residential or small-office devices. The family therefore represents both a malware platform for proxy botnet operations and an enabling layer for anonymization, cybercrime, and potentially follow-on intrusion activity.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Scanning
Reported operators
Threat actors
2 named in public reportingSeven years after its first appearance, the proxy server botnet Ngioweb continues its impactful presence on the internet... One of the samples obtained during 2024 ... allowed LevelBlue Labs to determine that the Ngioweb trojan ... works very similarly to how Ngioweb worked in 2019.
Exploited software
Vulnerabilities linked to Ngioweb
8 CVEsMITRE ATT&CK