Fxmsp is a criminal threat actor known for building a trusted proxy reseller network and developing a credential-stealing botnet.
Analyst brief
Fxmsp is a threat actor active in the criminal underground during 2017-2018, known for building a trusted proxy reseller network. They target corporate networks via externally available RDP servers and exposed Active Directory. The actor claims to have shifted focus to developing a credential-stealing botnet for exfiltrating sensitive user credentials from high-profile targets. Defenders should prioritize securing exposed RDP services, enforce multi-factor authentication, and monitor for anomalous authentication patterns in Active Directory to detect credential access TTPs.
Fxmsp
unknown
Throughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground. Some of the known Fxmsp TTPs included accessing network environments via externally available remote desktop protocol (RDP) servers and exposed active directory.
Most recently, the actor claimed to have developed a credential-stealing botnet capable of infecting high-profile targets in order to exfiltrate sensitive usernames and passwords. Fxmsp has claimed that developing this botnet and improving its capabilities for stealing information from secured systems is their main goal.
The actor most recently claimed to have developed a credential-stealing botnet designed to exfiltrate sensitive usernames and passwords from high-profile targets.
How did Fxmsp gain access to corporate networks?+
Fxmsp accessed network environments via externally available RDP servers and exposed Active Directory.