Todos os artigos

Este artigo ainda não foi traduzido, aqui está a versão em inglês.

Two free servers, one proxy operator: what August 2026 taught us

In August 2026, twice in the same week, the same person used Alama's free offers to turn a game server into a relay for other people's traffic. Nothing belonging to our customers was read or taken. We are writing this down because hosting is a trust business, and trust is built on telling what happened, not on pretending nothing ever does.

What they were after

The goal was not to steal data. It was to borrow our network. The uploaded code installed a proxy and opened an outbound tunnel to a public tunnelling service, so strangers could send their traffic through a server hosted in France. Because the tunnel starts from the inside, no port needs to be open: blocking incoming traffic changes nothing.

The risk that matters for a host is what such a relay can reach. A proxy with no rules can knock on the other machines of the network it lives in. That is the part we treated as urgent.

The first attempt: a bot that was not a bot

The first account ordered the free Discord bot offer. The support ticket was believable, asking how to change the start command. The server's name and a web page served on its port told the story of a harmless feed bot. The code told another one: no feed, no Discord, and instead the download of a proxy and a tunnel client.

The second attempt: a real Minecraft server with one file changed

A few days later, a new account took the free Minecraft offer and uploaded its own server file. It was a genuine open-source lobby server, complete and working, with a single class out of ninety-five replaced. The replacement started the proxy first, then the real server, then cleared the console after thirty seconds. "My Minecraft server works" was true, and proved nothing.

This time the payload did run before we stopped it.

What we did

  • We stopped and removed both servers and closed the accounts.
  • We reported the tunnel and the download host to the provider that served them, and the domain to its registrar. The download host was cut at the source.
  • We took the second sample apart, down to the one modified class, and shared it with people who study this kind of code: the file is public on MalwareBazaar, the abuse.ch repository of malware samples, with our full write-up attached as a comment, and a sandbox run of it is public on CAPE. We also sent the analysis to vx-underground, a collection that studies malware. The technical details are in the section below.

Technical details

For people who want to look at the second sample themselves. What follows comes from reading the file, not from running it.

The file. It was uploaded as server.jar, 3,643,157 bytes, built on 19 August 2026, the day the account was created.

  • SHA-256: 7c0b59171dfdaab72f18ef5325a508f2813f0477958167e53fb78cd716386937
  • MD5: f38fd9a636106f82e751a89d48cfbcf0
  • It is a copy of the open-source NanoLimbo project, a minimal Minecraft lobby server.

The one modified class. ua/nanit/limbo/NanoLimbo.class is the entry point. In the original project its main() is 31 lines and only starts the lobby server. In this build the class is 9,284 bytes and carries added methods that download and run a program, load its settings, stop it, and clear the console. The other 94 project classes and the bundled libraries are untouched.

What it does, in order.

  1. It refuses to run on a Java older than version 10, with a message that talks about the "startup menu", the vocabulary of game server panels. It was written for a host like ours.
  2. It downloads a native executable from a server the operator controls, saves it in the temporary directory under the name sbx, makes it executable and runs it. It is a multi-protocol proxy built on sing-box, exposed to the Internet through an outbound Cloudflare tunnel.
  3. The settings are hard-coded in the jar, can be overridden by environment variables, and a .env file next to the jar wins over both. The operator can therefore change the node without uploading anything again. The proxy's own files go into the world folder of the Minecraft server.
  4. It prints that the logs will be deleted, waits, and clears the console, which is exactly where the proxy had just printed its connection links.
  5. Only then does it start the real Minecraft server.

What the scanners said. Not much, which is the point. The MalwareBazaar entry has no malware family and is tagged binary, dropper, elf, jar and proxy. Three engines call the file "suspicious" without naming anything, and two others, including the CAPE sandbox, find nothing. The sandbox run ended early because its machine had Java 8: the jar's version check stopped it before the payload could start.

Checking your own server. Do not run anything to find out. Compare instead:

  • The SHA-256 of any .jar you did not build, with sha256sum file.jar, against the one above.
  • The class list of a Minecraft jar, with unzip -l file.jar: a NanoLimbo.class of several kilobytes, when the original is a 31-line file, is a reason to ask questions.
  • A file called sbx in the temporary directory, or unexpected binaries inside the world folder.
  • A server that opens a long-lived outbound connection to a tunnelling service it has no reason to use.

No single sign proves anything: a tunnelling client has legitimate uses. Look for several together, and write to us if in doubt.

What it taught us

  • Uploaded files cannot be judged by their name or by what they visibly do. A complete, working program with one altered file passes every surface check.
  • The useful control is on the way out. A free server has little reason to reach the whole Internet; limiting where it can connect is what stops a relay, not firewall rules on the way in.
  • Keep a copy before deleting. We removed the second server before copying its files, and lost the answer to a question we still have.

If you run a server with us and something in this story worries you, write to us at contact@alama.host.