Security19.06.2016

Hacked South African servers sold in massive underground market

Hacker

Kaspersky Lab researchers have investigated a global forum where cybercriminals can buy and sell access to compromised servers for as little as $6 (R91) each.

The xDedic marketplace, which appears to be run by a Russian-speaking group, currently lists 70,624 hacked Remote Desktop Protocol (RDP) servers for sale.

Many of the servers host or provide access to popular consumer websites and services and some have software installed for direct mail, financial accounting, and point-of-sale (PoS) processing.

They can be used to target the owners’ infrastructure, or as a launch-pad for wider attacks, while the owners – including government entities, corporations, and universities – have little or no idea of what’s happening.

xDedic is an example of a new kind of cybercriminal marketplace: well-organized and supported – offering everyone fast, cheap, and easy access to legitimate organizational infrastructure that keeps their crimes below the radar for as long as possible.

A European Internet service provider alerted Kaspersky Lab to the existence of xDedic and the companies worked together to investigate how the forum operates.

The process is:

  1. Hackers break into servers, often through brute-force attacks, and bring the credentials to xDedic.
  2. The hacked servers are then checked for their RDP configuration, memory, software, browsing history and more – all features that customers can search through before buying.

After that, they are added to a growing online inventory that includes access to:

  • Servers belonging to government networks, corporations, and universities.
  • Servers tagged for having access to or hosting certain websites and services, including gaming, betting, dating, online shopping, online banking and payment, cellphone networks, ISPs, and browsers.
  • Servers with pre-installed software that could facilitate an attack, including direct mail, financial, and PoS software.
  • All supported by a range of hacking and system information tools.

From as little as $6 per server, members of the xDedic forum can access all of a server’s data and also use it as a platform for further malicious attacks.

This could potentially include targeted attacks, malware, DDoS, phishing, social-engineering, and adware attacks.

The servers’ legitimate owners are often unaware that their IT infrastructure has been compromised.

Further, once a campaign has been completed, the attackers can put access to the server back up for sale and the whole process can begin again.

The xDedic marketplace seems to have opened for business some time in 2014, and has grown significantly in popularity since the middle of 2015.

In May 2016, it listed 70,624 servers from 173 countries for sale, posted in the names of 416 different sellers.

The top 10 countries affected are: Brazil, China, Russia, India, Spain, Italy, France, Australia, South Africa, and Malaysia.

The group behind xDedic appears to be Russian-speaking, and claims it merely provides a trading platform and has no links or affiliations to the sellers.

Hacked servers

More on security

Immediately update or delete Adobe Flash Player

Google’s Project Shield: protecting news sites against DDoS attacks

Massive increase in DDoS attacks

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter