Researchers: cybercriminals are increasingly turning from “bulletproof” hosts to “residential proxies” that disguise malicious traffic as normal online activity
In an effort to evade detection, cybercriminals are increasingly turning to “residential proxy” … Forums: Slashdot Forums: Msmash / Slashdot : Cybercriminals Are Hiding Malicious Web Traffic in Plain Sight
Context & Ripple Effects
Abuse-friendly infrastructure was already under scrutiny: Spamhaus linked the bulletproof host Prospero to routing through Kaspersky Lab's networks, while compromised name-brand routers had been observed serving both criminal and state-linked operators as cover for their attacks.
This report identifies a tactical migration within that infrastructure problem: rather than relying primarily on identifiable abuse-friendly hosts, attackers can blend command, scanning, or attack traffic into connections that appear to originate from ordinary residential users.
First-order effects
- Defenders face lower-confidence source signals as malicious traffic arrives through residential proxy endpoints instead of more readily blocklisted bulletproof-host networks.
- Residential proxy operators and the owners of devices supplying those routes become immediate points of exposure, because their infrastructure can make hostile activity look like routine consumer traffic.
Second-order effects
- Security teams and online services will have to rely less on IP reputation alone and put more weight on behavioral signals, authentication, and traffic patterns when deciding what to block or challenge.
- The shift raises the value of identifying proxy supply chains and compromised routers, consistent with prior reporting on shared criminal and state-linked use of consumer routers.
Third-order effects
- If residential routes remain a durable substitute for bulletproof hosting, abuse enforcement is likely to move from takedowns of overtly hostile hosts toward disruption of distributed proxy networks and the devices feeding them.
- The pattern further erodes the boundary between consumer connectivity and attack infrastructure, making coordinated action by platforms, security vendors, device makers, and law enforcement more important; a later disruption of a residential proxy network illustrates that direction.
The trend: Cybercrime infrastructure is shifting from conspicuous, abuse-tolerant hosting toward distributed residential networks that are harder to distinguish from normal internet use.