meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, January 30th, 2026: Residential Proxy Networks; Clowdbot/Moltbot Themed Malware; eScan Malicious Updates

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 January 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Friday, January 30th, 2026: Residential Proxy Networks; Clowdbot/Moltbot Themed Malware; eScan Malicious Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, January 30th, 2026 edition of the Sands Inundate Storm Centers Stormcast.

0:12.9

My name is Johannes Ulrich, recording a day from Jacksonville, Florida.

0:17.9

And this episode is brought you by the Sands.edu grad certificate program in cloud security.

0:24.9

Google announced today that it did take down the world's largest residential proxy network.

0:32.8

At least that's what Google is claiming here.

0:35.6

And residential proxy networks have been in the news quite a few times of the last year.

0:42.5

Now, in the past, and I'm talking about sort of 10 years or so ago, when we talked about these

0:49.1

type of proxy networks, what we usually talked about was compromised IoT devices, like in particular

0:56.4

routers were often used. There was a big sort of proxy network that was set up by a large,

1:03.6

more advanced attacker with microtick devices. But in this case, in addition to these

1:09.9

compromised devices, we also now have

1:13.1

criminal organizations that are essentially offering money for volunteers who will install

1:19.1

their proxy.

1:21.0

It's not always clear to these volunteers that what they're doing is actually contributing

1:27.4

to attacks and to illegal activity.

1:32.6

In part, you could also talk about tour here, and just someone setting up a tour exit node is a little bit similar in this sense.

1:41.2

But of course, tour exit nodes are usually publicly known and people can block them.

1:46.7

What really differentiates these residential proxy networks is that they are taking advantage of

1:52.8

average residential IP addresses that are very difficult, if not impossible, to distinguish from

1:59.5

normal traffic. What Google took actually down

2:03.2

here was some domains that this group used in order to advertise and manage their proxy network.

2:12.3

The individual users that set up these proxies, they probably still have these proxies running and that's something

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.