Paying off the debt: I finally opened one of those hidden APK payloads, and it wasn't proxyware

Fourth post on where residential proxy exits come from. The SYN fingerprints said the pool wasn’t real users; MediaGet closed the Windows arm; this is the Android arm, and it’s a no. I opened the kind of hidden, packed payload I’ve twice failed to open before, and it’s a cheat framework with Chinese telemetry and no C2 of its own. The proxy correlation I chased alongside it holds up as a measurement and not as evidence — and my own March fingerprint data had already told me the Android channel was a minority tributary, which I only noticed afterwards.

July 28, 2026 · 19 min · Vitalii Zaiats

Eleven proxy networks and a country code: how a torrent client decides who rents your connection

Finishing a thread I left dangling: the torrent client from the booby-trapped-game post, named and taken apart. Its installer doesn’t contain a single payload URL — it asks a server, and the server answers based on what country you’re in. Eleven proxy vendors wired into the UI package, one slot per machine, and the geos that look clean turn out to be the ones with no consent screen. Two of the vendors it shipped me have since been dismantled by Google-led actions.

July 25, 2026 · 22 min · Vitalii Zaiats

From a proxy pool's torrents to a booby-trapped game

I chased a residential proxy pool’s own download habits down to one cracked driving game, and found a build that’s a confirmed ad-fraud carrier hiding an encrypted payload I still can’t prove is proxyware.

May 31, 2026 · 8 min · Vitalii Zaiats