The FBI warned that cybercriminals are abusing residential proxy networks to mask their identities and relay malicious traffic through consumer and small-business internet connections. Devices may join these networks through SDK partnerships and bandwidth-sharing applications, deceptive “free” VPN terms, malware and backdoors, or compromised IoT devices. The proxy infrastructure can obscure command-and-control traffic and support phishing, account takeover, brute-force attacks, data exfiltration, fraud, spam, and illicit-market operations.
A report titled “SuperProxy: How Residential Proxy Networks Have Become Malware Delivery Platforms” also identifies residential proxy services as infrastructure for malware delivery. Organizations should restrict unvetted software and bandwidth-sharing tools, promptly patch systems, segment and monitor networks, enforce device and firewall controls, and report suspected compromise to the FBI’s IC3.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
A blueteamsec post referenced the report “SuperProxy: How Residential Proxy Networks Have Become Malware Delivery Platforms,” describing residential proxy networks as infrastructure used to deliver malware. The available material did not identify a malware family, threat actor, victims, or technical indicators.
The FBI published Public Service Announcement I-031226-PSA, warning that criminals abuse residential proxy networks to conceal malicious traffic through consumer and small-business devices and connections. The notice outlined enrollment methods, criminal uses, and recommended protective measures and IC3 reporting.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.