SYMBOLCOMMON_NAMEaka. SYNONYMS

Water Barghest  (Back to overview)


Water Barghest is a cybercriminal group that has compromised over 20,000 IoT devices by October 2024, monetizing them through a residential proxy marketplace. They automate the entire process from identifying vulnerable devices using n-day and zero-day exploits to deploying Ngioweb malware and selling the compromised assets. Their operations include leveraging Ubiquiti EdgeRouter devices for espionage and utilizing automated scripts to exploit vulnerabilities within minutes of discovery. Water Barghest has maintained a low profile for years, but their activities gained attention due to the deployment of a zero-day vulnerability against Cisco IOS XE devices in October 2023.


Associated Families
elf.ngioweb

References
2024-11-19LumenBlack Lotus Labs
One Sock Fits All: The Use And Abuse Of The NSOCKS Botnet
Ngioweb Ngioweb
2024-11-18Trend MicroFeike Hacquebord, Fernando Mercês
Inside Water Barghest’s Rapid Exploit-to-Market Strategy for IoT Devices
Ngioweb Water Barghest
2024-11-18Trend MicroFeike Hacquebord, Fernando Mercês
Inside Water Barghests Rapid Exploit-to-Market Strategy for IoT Devices
Ngioweb
2024-11-18Trend MicroFeike Hacquebord, Fernando Mercês
Inside Water Barghest’s Rapid Exploit-to-Market Strategy for IoT Devices
Ngioweb
2024-11-01LevelBlueFernando Martinez
Ngioweb Remains Active 7 Years Later
Ngioweb
2024-05-01Trend MicroFeike Hacquebord, Fernando Mercês
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
Ngioweb SSHDoor
2020-11-13NetlabAlex Turing, Hui Wang
Quick update on the Linux.Ngioweb botnet, now it is going after IoT devices
Ngioweb
2020-11-05IntezerTwitter (IntezerLabs)
Tweet on Ngioweb botnet
Ngioweb
2019-06-21Network Security Research Lab @ Qihoo 360Alex Turing, yegenshen
An Analysis of Linux.Ngioweb Botnet
Ngioweb

Credits: MISP Project