Cybercriminals Are Hiding Malicious Web Traffic in Plain Sight

Cybercriminals Increasingly Use Residential Proxies to Mask Malicious Web Traffic
Photo: WIRED

Cybercriminals Increasingly Use Residential Proxies to Mask Malicious Web Traffic

Cybercriminals have shifted their tactics to evade detection by increasingly using residential proxy services that disguise malicious web traffic as normal online activity. Traditionally, cybercriminals relied on ‘bulletproof’ hosting services, which allowed anonymous web infrastructure with little oversight. However, law enforcement crackdowns on these hosts have led criminals and providers to adopt proxy-based methods. These proxies, including residential proxies running on consumer devices like old smartphones or laptops, rotate IP addresses and mix traffic, making it nearly impossible to distinguish malicious activity from legitimate internet use. This approach complicates threat detection because malicious traffic appears to originate from trusted home or office IP addresses. The decentralized nature of these proxy networks also limits service providers’ visibility and control, hindering law enforcement efforts. Experts warn that while proxies support internet freedom and privacy, they also pose significant challenges for cybersecurity. The rise of residential proxies as a gray-market service marks a notable shift from earlier, more centralized cybercrime infrastructure. Despite efforts to target malicious proxy providers, the widespread legitimate use of proxies means that taking down one service does not resolve the broader issue of proxy-enabled cybercrime.

Leave a Reply

Your email address will not be published. Required fields are marked *