Friday, April 25, 2025
HomeCyber AttackHackers Transform the Raspberry Pi into an Online Anonymity Tool

Hackers Transform the Raspberry Pi into an Online Anonymity Tool

Published on

SIEM as a Service

Follow Us on Google News

A new tool, GEOBOX, was advertised on the Dark Web that utilizes Raspberry Pi devices for fraud and anonymization, allowing users to spoof GPS locations, emulate network settings, mimic Wi-Fi access points, and bypass anti-fraud filters. 

Criminals were using multiple GEOBOX devices as proxies to enhance anonymity during an online banking theft investigation.

Attackers are believed to utilize more custom-made or modified devices in the future, creating challenges for law enforcement. 

- Advertisement - Google News

The tool is advertised on underground forums and Telegram for a fee of $700 for a lifetime or $80 monthly in cryptocurrency. 

Raspberry Pi i
Advertisement on Telegram

GEOBOX utilizes the Raspberry Pi to create an anonymous and fraudulent device, where a user manual with clear instructions is provided to simplify setup. 

The manual includes SD card selection for optimal performance, guides users to download Raspberry Pi OS from the official website, and explains how to obtain the GEOBOX software image. 

Obtaining Geobox Software Image

After installing the OS, the user guide details how to use the GEOBOX software, activate the device, connect to the Internet, and configure GEOBOX functions. 

Raspberry Pi i
Working of Geobox Software

Feature of Geobox

A software suite designed for network configuration on the Raspberry Pi offers various functionalities, including managing multiple VPN connections with protocols like OpenVPN, L2TP, and Wireguard. 

Fatureset of the Geobox

Users can create and switch between VPN profiles for customized network routing, which supports creating cascaded VPN tunnels for enhanced anonymity and allows the configuration of proxy servers to manipulate DNS, GPS, and Wi-Fi MAC address information. 

It provides a GPS emulator for devices lacking a GPS receiver and enables users to manage Wi-Fi network settings and DNS servers. For advanced users, GEOBOX offers a Mimic Tab to monitor data manipulation and a Log Tab for system diagnostics.

Document

Integrate ANY.RUN in Your Company for Effective Malware Analysis

Are you from SOC, Threat Research, or DFIR departments? If so, you can join an online community of 400,000 independent security researchers:

  • Real-time Detection
  • Interactive Malware Analysis
  • Easy to Learn by New Security Team members
  • Get detailed reports with maximum data
  • Set Up Virtual Machine in Linux & all Windows OS Versions
  • Interact with Malware Safely

If you want to test all these features now with completely free access to the sandbox:

Technical Insights

Geobox is a device that can be installed on a Raspberry Pi to anonymize online activity and manipulate geolocation and it achieves this by using WebRTC IP, GPS spoofing, and MAC address masking. 

Raspberry Pi i
Mimic Tab

The device is easy to use and provides a variety of functionalities through a web interface, including proxy server configuration, VPN connectivity, and altering Wi-Fi network parameters. 

It also poses a significant challenge to cybersecurity as it can be used to commit a variety of cybercrimes, such as cyber-attacks, dark web market operations, and financial fraud.

Resecurity discovered cybercriminals using GEOBOX with multiple LTE modems and proxy servers to anonymize connections, which makes tracing them difficult, especially for remote access. 

Criminals use short sessions to eliminate evidence, further impeding investigations, while easy access to GEOBOX raises concerns about its potential widespread use. The evolving threat landscape highlights the need for advanced security solutions and global cooperation to combat increasingly sophisticated cybercrime. 

Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

7 Best Third-Party Risk Management Software in 2025

Whether you operate a small business or run a large enterprise, you rely on...

Chrome UAF Process Vulnerabilities Actively Exploited

Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser...

Microsoft Defender XDR False Positive Leaked Massive 1,700+ Sensitive Documents to Publish

An alarming data leak involving Microsoft Defender XDR has exposed more than 1,700 sensitive...

‘SessionShark’ – A New Toolkit Bypasses Microsoft Office 365 MFA Security

Security researchers have uncovered a new and sophisticated threat to Microsoft Office 365 users:...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

7 Best Third-Party Risk Management Software in 2025

Whether you operate a small business or run a large enterprise, you rely on...

Hackers Exploit MS-SQL Servers to Deploy Ammyy Admin for Remote Access

A sophisticated cyberattack campaign has surfaced, targeting poorly managed Microsoft SQL (MS-SQL) servers to...

New Report Reveals How AI is Rapidly Enhancing Phishing Attack Precision

The Zscaler ThreatLabz 2025 Phishing Report unveils the alarming sophistication of modern phishing attacks,...