17 million devices for rent: tracing a residential-proxy botnet from one cracked game

I got bored on a forum doing arithmetic on ‘millions of residential IPs’, ended up reverse-engineering a botnet’s C2 from one infected phone, and reported it. The whole messy thread — and where it led.

June 26, 2026 · 14 min · Vitalii Zaiats

Paying off the debt: I finally opened one of those hidden APK payloads, and it wasn't proxyware

Fourth post on where residential proxy exits come from. The SYN fingerprints said the pool wasn’t real users; MediaGet closed the Windows arm; this is the Android arm, and it’s a no. I opened the kind of hidden, packed payload I’ve twice failed to open before, and it’s a cheat framework with Chinese telemetry and no C2 of its own. The proxy correlation I chased alongside it holds up as a measurement and not as evidence — and my own March fingerprint data had already told me the Android channel was a minority tributary, which I only noticed afterwards.

July 28, 2026 · 19 min · Vitalii Zaiats

Eleven proxy networks and a country code: how a torrent client decides who rents your connection

Finishing a thread I left dangling: the torrent client from the booby-trapped-game post, named and taken apart. Its installer doesn’t contain a single payload URL — it asks a server, and the server answers based on what country you’re in. Eleven proxy vendors wired into the UI package, one slot per machine, and the geos that look clean turn out to be the ones with no consent screen. Two of the vendors it shipped me have since been dismantled by Google-led actions.

July 25, 2026 · 22 min · Vitalii Zaiats

A browser can fake its WebRTC address — it can't fake the packet

Every WebRTC leak check reads a value the browser reports, and an anti-detect browser reports whatever keeps you happy. So I stopped reading its answer and started checking mine: run the STUN server yourself, and whether a packet actually arrived becomes the one thing the browser can’t forge. Here’s the idea, a widget to test your own browser, and an honest tour of everywhere it fails.

July 22, 2026 · 8 min · Vitalii Zaiats

A TLS fingerprint won't tell you it's a bot — what it reaches for will

Most tools ask whether a TLS fingerprint resembles Chrome. I wanted a different question — how does it behave? So I sat inside a residential proxy network, named a million handshakes, and found the bulk of the ‘bot’ traffic isn’t faking Chrome. It’s driving it.

July 19, 2026 · 9 min · Vitalii Zaiats

From a proxy pool's torrents to a booby-trapped game

I chased a residential proxy pool’s own download habits down to one cracked driving game, and found a build that’s a confirmed ad-fraud carrier hiding an encrypted payload I still can’t prove is proxyware.

May 31, 2026 · 8 min · Vitalii Zaiats

Coordinated disclosure: CCTV cameras selling their owners' bandwidth

How I passively fingerprinted hacked Dutch CCTV cameras being resold as residential proxy exit nodes — and reported them to NCSC-NL without ever touching a single box.

April 15, 2026 · 5 min · Vitalii Zaiats

The iOS proxy ghost: why you can't find an iPhone in a residential pool

Turns out the iPhone on every proxy provider’s landing page is the one device that basically can’t be in the pool — and that absence is exactly what makes a real iOS fingerprint a trustworthy “human here” signal.

April 3, 2026 · 4 min · Vitalii Zaiats

TCP-fingerprinting 300K residential proxy IPs: 98% are Linux

Probed 319,706 residential-proxy exits by their TCP SYN fingerprints — 98% Linux, two kernel defaults covering 70%+, MSS leaking the real link, and a handful of big ISPs — showing the “real user devices” are mostly a rack of Linux boxes.

March 26, 2026 · 4 min · Vitalii Zaiats