Threats Tagged 'residential proxies'
View all threats tagged with 'residential proxies'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'residential proxies'
Click on any threat for detailed analysis and mitigation recommendations
A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix. Join the discussion | AlienVault OTX General | 09/10/2026, 13:26:22 UTC Added: 09/10/2026, 14:07:16 UTC |
Peer2Profit and Astroproxy are bandwidth-sharing applications that recruit users to share their internet connections for payment. This bandwidth is then monetized through a commercial proxy service at significantly higher rates. The applications install through official channels with user consent, making them difficult to detect with traditional security tools. Researchers identified over 117,000 unique IPs in 72 hours, with rapid growth in residential IPs. Reverse engineering revealed the communications protocol and backconnect infrastructure managing proxy sessions. Testing showed these proxy networks can access internal network resources via DNS entries resolving to internal IPs, potentially exposing corporate assets. The scale and internal access capabilities present significant risks to organizations where employees run these applications. Join the discussion | AlienVault OTX General | 08/20/2026, 17:09:15 UTC Added: 08/20/2026, 23:22:26 UTC |
0 Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting. Join the discussion | CVE Database V5 | 08/07/2026, 02:45:38 UTC Added: 05/13/2026, 18:36:36 UTC |
Investigation of DPRK-linked fake IT worker infrastructure began after cryptocurrency researcher ZachXBT identified domain luckyguys[.]site connected to illicit payments. Analysis of 30 days of network activity associated with IP 163.245.219[.]19 revealed concentrated VPN usage patterns, with Astrill VPN (37.5%), Mullvad (32.25%), and Proton VPN (6.25%) being prominent. American and Latvian residential IPs communicated with the infrastructure, showing frequent Astrill VPN usage and connectivity to Gmail, ChatGPT, and Workana freelance platform. A second IP, 216.158.225[.]144, was discovered through X509 certificate analysis. Traffic dropped sharply following public exposure, consistent with adversary behavior of abandoning attributed infrastructure. The activity suggests a distributed network of remote IT workers participating in sanctions evasion workflows, leveraging AI tools and freelance platforms to obtain employment under false identities. Join the discussion | AlienVault OTX General | 04/23/2026, 03:27:33 UTC Added: 04/23/2026, 09:06:03 UTC |
0 An investigation using Silent Push's Traffic Origin and residential proxy data revealed a suspicious Chinese VPN provider. The analysis focused on IP address 205.198.91.155, which showed unusual traffic from Russia, China, Myanmar, Iran, and Venezuela. This IP was linked to the domain lvcha.in, hosting a Chinese-language VPN. Further investigation uncovered nearly 50 related domains promoting the same VPN, suggesting attempts to bypass country-level firewalls. The VPN's infrastructure was found to use residential proxies and had connections to various high-risk countries. This case study demonstrates the importance of verifying physical and technical behaviors of connections to protect against fraud and state-sponsored actors using stolen identities and spoofed locations. Join the discussion | AlienVault OTX General | 02/10/2026, 09:09:44 UTC Added: 02/10/2026, 10:15:26 UTC |
Showing 1 to 5 of 5 results