This desk filed the enforcement action against a 17-million-device proxy network at 26-0528. The strategic point deserves separating from the takedown.
The ability to originate network traffic from an ordinary residential connection in a chosen country, at will, used to require infrastructure that only a well-resourced service could assemble. It is now a subscription.
What The Capability Actually Defeats
Geographic risk scoring assumes a foreign address is a signal. Impossible-travel detection assumes physical implausibility. Reputation blocking assumes bad traffic comes from identifiable ranges. Residential origination defeats all three simultaneously, and this desk has documented the technique in the APT40 pattern noted at 26-0311.
It also breaks attribution in the other direction. Traffic that appears to originate from a domestic connection in a particular country tells an investigator very little, because the connection was rented.
The Market Serves Both Ends
Residential proxy services are not exclusively criminal. They are sold for advertising verification, price monitoring and content availability testing, which is why they operate commercially with billing systems and support.
That dual-use character is what makes them durable. A purely criminal service is a target; a service with legitimate customers, corporate branding and a terms-of-service page is a harder legal problem, and the supply chain for exit nodes runs through consumers who clicked accept.
The Defensive Consequence
Controls that treat network origin as evidence of identity are now unreliable at the exact moment identity-led intrusion has become the dominant pattern in this database.
What remains are controls that do not depend on where traffic comes from: phishing-resistant authentication, device attestation, and behavioural signals about what an account does rather than where it appears to be.
This is an analysis file built on published research and reporting, listed below. Corrections: corrections@forensicpost.com.