CanOworms: Shared Relays, Many Tenants, One Pre-Attack Problem

This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

Most teams still treat a malicious IP as belonging to one actor.
That assumption collapses when the IP is rented. SecurityScorecard’s STRIKE Threat Intelligence Team just published research on CanOworms: roughly 633 proxy and VPN servers operating as a commercial anonymization service for hire. Commodity malware crews and suspected state-linked operators show up on the same disposable relays. Blocking one address interrupts a session. It does not remove the business behind it.
Malanta is proud to have contributed to this joint research alongside FalconFeeds and SecurityScorecard.
What SecurityScorecard found
CanOworms is not one group’s private command-and-control mesh. STRIKE characterizes it as shared, multi-tenant infrastructure: Squid, SOCKS, OpenVPN, and related services forwarding other people’s traffic across more than six hosting providers in at least a dozen countries.
The investigation started with a single self-signed TLS certificate using throwaway values (O=kickass). Combined with corroborating JARM and JA4X fingerprints, STRIKE confirmed 633 member servers in a 180-day window. The lineage of related bulletproof / no-logs hosting stretches back to at least 2017.
Public threat intelligence has associated fleet members with Remcos, Quasar, NanoCore, NetWire, AsyncRAT, and Loki. STRIKE also observed attack-shaped traffic exiting the network, including activity consistent with distributed SSH credential spraying against edge devices. The durable hunting signal is not a static IP list. It is the fleet’s build fingerprints, published in the full report for defender use.
In MITRE terms, this is Resource Development and supporting tradecraft in practice (TA0042 and related proxy techniques): acquire infrastructure, rent anonymity, rotate fronts faster than reputation systems can keep up.
What Malanta contributed
SecurityScorecard built the fleet map, netflow analysis, and fingerprint methodology. Our role was different: help answer who rents the relays, and what that pattern implies.
Malanta’s contributions, as credited in the STRIKE report:
- Tenant attribution on certificate-defined mesh hosts. We attributed suspected APT43 infrastructure on a Datasource AG host (
91.192.100[.]62), and suspected APT37 plus APT43 infrastructure on a Fink Telecom host (79.134.225[.]22). SecurityScorecard presents these as partner assessments (external / assessed by other vendor), not as independently confirmed ownership of the network. - An open infrastructure anomaly. We flagged mesh node
79.134.225[.]21presenting a borrowed German mail certificate (CN=ciesnik[.]de) that renews in lockstep with the legitimate owner’s Let’s Encrypt cycle - the only real third-party certificate STRIKE observed on a CanOworms node among otherwise kickass / nVpn fleet certs. - The multi-tenant thesis. Mutually unrelated advanced actors appearing on the same certificate-defined pool supports the core finding: many tenants, one set of relays. Convergence is evidence of a rental service, not proof that any one APT owns CanOworms.
That distinction matters. Treating a relay IP as APT X infrastructure can send defenders after the wrong layer while the real backend simply fronts through the next node.
Why this matters for Pre-Attack Prevention
Shared anonymization services compress the attacker’s setup cost and stretch the defender’s response cycle. Reputation, geolocation, and ASN denylists are exactly what this architecture is built to defeat. The useful work happens earlier: recognizing adversary infrastructure identity, clustering related assets, and treating rented fronts as part of a living membrane, not a single campaign box.
That is the pre-attack window. IoPAs (Indicators of Pre-Attack) matter when the signal is identity and linkage, not only a post-compromise IOC on a disposable exit IP.
Acknowledgements
Thanks for the collaboration with SecurityScorecard’s STRIKE Threat Intelligence Team and FalconFeeds. Shared investigations like this make adversary infrastructure harder to hide behind rented anonymity.
The Bottom Line
CanOworms shows the market for anonymity-for-hire is mature, multi-tenant, and designed to outlast any one customer. SecurityScorecard’s STRIKE team mapped the fleet and published durable fingerprints. Malanta contributed tenant attribution and infrastructure anomaly research that help explain who shows up on those relays - and why single-actor ownership claims do not fit.
Read the full technical report and the SecurityScorecard blog for the complete findings, methodology, and indicator appendix:






