Desk live·
ForensicPost
Nation-state/Infrastructure/File 26-0320

Residential Proxy Networks Sell State-Grade Traffic Origination to Any Buyer

Residential proxy networks give any buyer the ability to originate traffic from an ordinary home connection in almost any country. It is a capability states used to have to build.

Constructed geometry · not a chart of case data
TargetNetwork origin controls
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

This desk filed the enforcement action against a 17-million-device proxy network at 26-0528. The strategic point deserves separating from the takedown.

The ability to originate network traffic from an ordinary residential connection in a chosen country, at will, used to require infrastructure that only a well-resourced service could assemble. It is now a subscription.

What The Capability Actually Defeats

Geographic risk scoring assumes a foreign address is a signal. Impossible-travel detection assumes physical implausibility. Reputation blocking assumes bad traffic comes from identifiable ranges. Residential origination defeats all three simultaneously, and this desk has documented the technique in the APT40 pattern noted at 26-0311.

It also breaks attribution in the other direction. Traffic that appears to originate from a domestic connection in a particular country tells an investigator very little, because the connection was rented.

The Market Serves Both Ends

Residential proxy services are not exclusively criminal. They are sold for advertising verification, price monitoring and content availability testing, which is why they operate commercially with billing systems and support.

That dual-use character is what makes them durable. A purely criminal service is a target; a service with legitimate customers, corporate branding and a terms-of-service page is a harder legal problem, and the supply chain for exit nodes runs through consumers who clicked accept.

The Defensive Consequence

Controls that treat network origin as evidence of identity are now unreliable at the exact moment identity-led intrusion has become the dominant pattern in this database.

What remains are controls that do not depend on where traffic comes from: phishing-resistant authentication, device attestation, and behavioural signals about what an account does rather than where it appears to be.

How we reported this

This is an analysis file built on published research and reporting, listed below. Corrections: corrections@forensicpost.com.

Sources
  1. One year later: the residential proxy botnet problem got bigger, not smallerNokia
  2. Aisuru botnet shifts from DDoS to residential proxiesKrebs on Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary