Research
Research & Intelligence
Research on proxy networks, botnets, credential stuffing, threat actor tradecraft, and internet infrastructure from the Synthient team.
Synthient Version 4
Synthient version 4 brings one of the largest updates to the platform so far. This release aims to improve developer experience, stability, and overall data...

Index
Research archive for proxy networks, feeds, Firehose, and Helios.

Popa: From Sourcing to Distribution
Popa is an Android proxyware SDK that turns consumer devices (phones, tablets, streaming boxes) into residential proxy nodes. It ships inside third-party...

Who Are The Victims of Residential Proxies?
Our latest research reveals how modern residential proxy networks use "AI marketing" to hide a darker reality of global device exploitation. By tracking...

ProxyBox: Socks5Systemz Lives On
Synthient’s Research Team continuously tracks Black Hat proxy services due to the significant risks they pose to clients in the financial sector. Recently, a...

A Broken System Fueling Botnets
Synthient continues to track the Kimwolf DDoS and proxy botnet with this report, delivering significant findings on the inner workings, infection chain, and...

IPCola: A Tangled Mess
A look into the internals behind a large-scale proxy operation, from the sourcing of IPs to the platform itself. How proxy providers utilize everything from...

The Stealer Log Ecosystem: Processing Millions of Credentials a Day
In early November of last year Synthient would take on a research project to map out the cybercrime ecosystem. In that effort we would go on to ingest...