17 million devices for rent: tracing a residential-proxy botnet from one cracked game

I got bored on a forum doing arithmetic on ‘millions of residential IPs’, ended up reverse-engineering a botnet’s C2 from one infected phone, and reported it. The whole messy thread — and where it led.

June 26, 2026 · 14 min · Vitalii Zaiats

Paying off the debt: I finally opened one of those hidden APK payloads, and it wasn't proxyware

Fourth post on where residential proxy exits come from. The SYN fingerprints said the pool wasn’t real users; MediaGet closed the Windows arm; this is the Android arm, and it’s a no. I opened the kind of hidden, packed payload I’ve twice failed to open before, and it’s a cheat framework with Chinese telemetry and no C2 of its own. The proxy correlation I chased alongside it holds up as a measurement and not as evidence — and my own March fingerprint data had already told me the Android channel was a minority tributary, which I only noticed afterwards.

July 28, 2026 · 19 min · Vitalii Zaiats

From a proxy pool's torrents to a booby-trapped game

I chased a residential proxy pool’s own download habits down to one cracked driving game, and found a build that’s a confirmed ad-fraud carrier hiding an encrypted payload I still can’t prove is proxyware.

May 31, 2026 · 8 min · Vitalii Zaiats