Who else is using your servers?

July 2016 Information Security

Kaspersky Lab researchers have investigated a global forum where cybercriminals can buy and sell access to compromised servers for as little as $6 each. The xDedic marketplace, which appears to be run by a Russian-speaking group, currently lists 70 624 hacked Remote Desktop Protocol (RDP) servers for sale.

Many of the servers host or provide access to popular consumer websites and services and some have software installed for direct mail, financial accounting and point-of-sale (PoS) processing. They can be used to target the owners’ infrastructures or as a launch-pad for wider attacks, while the owners, including government entities, corporations and universities, have little or no idea of what’s happening.

xDedic is a powerful example of a new kind of cybercriminal marketplace: well-organised and supported and offering everyone from entry-level cybercriminals to APT groups fast, cheap and easy access to legitimate organisational infrastructure that keeps their crimes below the radar for as long as possible.

A European Internet service provider (ISP) alerted Kaspersky Lab to the existence of xDedic and the companies worked together to investigate how the forum operates. The process is simple and thorough: hackers break into servers, often through brute-force attacks, and bring the credentials to xDedic. The hacked servers are then checked for their RDP configuration, memory, software, browsing history and more – all features that customers can search through before buying. After that, they are added to a growing online inventory that includes access to:

• Servers belonging to government networks, corporations and universities.

• Servers tagged for having access to or hosting certain websites and services, including gaming, betting, dating, online shopping, online banking and payment, cellphone networks, ISPs and browsers.

• Servers with pre-installed software that could facilitate an attack, including direct mail, financial and PoS software.

• All supported by a range of hacking and system information tools.

From as little as $6 per server, members of the xDedic forum can access all of a server’s data and also use it as a platform for further malicious attacks. This could potentially include targeted attacks, malware, DDoS, phishing, social-engineering and adware attacks, among others.

The servers’ legitimate owners, reputable organisations including: government networks, corporations and universities, are often unaware that their IT infrastructure has been compromised. Further, once a campaign has been completed, the attackers can put access to the server back up for sale and the whole process can begin again.

The xDedic marketplace seems to have opened for business some time in 2014, and has grown significantly in popularity since the middle of 2015. In May 2016, it listed 70 624 servers from 173 countries for sale, posted in the names of 416 different sellers. The top 10 countries affected are: South Africa, Brazil, China, Russia, India, Spain, Italy, France, Australia and Malaysia.

The group behind xDedic claims that it merely provides a trading platform and has no links or affiliations to the sellers.

“xDedic is further confirmation that cybercrime-as-a-service is expanding through the addition of commercial ecosystems and trading platforms. Its existence makes it easier than ever for everyone, from low-skilled malicious attackers to nation-state backed APTs to engage in potentially devastating attacks in a way that is cheap, fast and effective. The ultimate victims are not just the consumers or organisations targeted in an attack, but also the unsuspecting owners of the servers: they are likely to be completely unaware that their servers are being hijacked again and again for different attacks, all conducted right under their nose,” said Costin Raiu, director, global research and analysis team, Kaspersky Lab.

Kaspersky Lab advises organisations to:

• Install a robust security solution as part of a comprehensive, multi-layered approach to IT infrastructure security.

• Enforce the use of strong passwords as part of the server authentication process.

• Implement a continuous process of patch management.

• Undertake a regular security audit of the IT infrastructure.

• Consider investing in threat intelligence services which will keep the organisation informed of emerging threats and offer an insight into the criminal perspective to help them assess their level of risk.

Read more about xDedic at Securelist.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
What does Agentic AI mean for cybersecurity?
Information Security AI & Data Analytics
AI agents will change how we work by scheduling meetings on our behalf and even managing supply chain items. However, without adequate protection, they become soft targets for criminals.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Crypto in SA: between progress and precaution
Information Security
“As cryptocurrency gains momentum and legitimacy, it’s becoming increasingly important for people to pay attention to financial security”, says Richard Frost, head of technology and innovation at Armata Cyber Security.

Read more...
Cyber recovery requires a different approach to disaster recovery
Information Security
Disaster recovery is about getting operations back on track after unexpected disruptions; cyber recovery, however, is about calculated actions by bad actors aiming to disrupt your business, steal sensitive data, or hold your system hostage.

Read more...
MDR users claim 97,5% less
Sophos Information Security
The average cyber insurance claim following a significant cyberattack is just $75 000 for MDR users, compared with $3 million for endpoint-only users, according to a new independent study.

Read more...
The impact of GenAI on cybersecurity
Sophos News & Events Information Security
Sophos survey finds that 89% of IT leaders worry GenAI flaws could negatively impact their organisation’s cybersecurity strategies, with 87% of respondents stating they were concerned about a resulting lack of cybersecurity accountability.

Read more...
Efficient, future-proof estate security and management
Technews Publishing ElementC Solutions Duxbury Networking Fang Fences & Guards Secutel Technologies OneSpace Technologies DeepAlert SMART Security Solutions Editor's Choice Information Security Security Services & Risk Management Residential Estate (Industry) AI & Data Analytics IoT & Automation
In February this year, SMART Security Solutions travelled to Cape Town to experience the unbelievable experience of a city where potholes are fixed, and traffic lights work; and to host the Cape Town SMART Estate Security Conference 2025.

Read more...
Kaspersky KATA 7.0 for targeted attack protection
Information Security Products & Solutions
] Kaspersky has announced a major update to its Kaspersky Anti Targeted Attack (KATA) including enhanced network detection and response (NDR) capabilities with deeper network visibility, internal threats detection and other critical security features.

Read more...
The role of advanced technologies in ransomware recovery
Information Security
As businesses increasingly adopt cloud technologies, the complexities of maintaining resilience and ensuring rapid recovery from such incidents become even more pronounced. The integration of advanced technologies is essential to navigate these challenges effectively.

Read more...