Research
Research & Intelligence
Deep dives into internet infrastructure, threat actor tradecraft, and data analysis from the Synthient team.
Who Are The Victims of Residential Proxies?
Our latest research reveals how modern residential proxy networks use "AI marketing" to hide a darker reality of global device exploitation. By tracking major proxy botnets, this comprehensive deep dive exposes how...


Who Are The Victims of Residential Proxies?
Our latest research reveals how modern residential proxy networks use "AI marketing" to hide a darker reality of global device exploitation. By tracking major proxy botnets, this comprehensive deep dive exposes how...

ProxyBox: Socks5Systemz Lives On
Synthient’s Research Team continuously tracks Black Hat proxy services due to the significant risks they pose to clients in the financial sector. Recently, a service known as “ProxyBox” stood out after online...

A Broken System Fueling Botnets
Synthient continues to track the Kimwolf DDoS and proxy botnet with this report, delivering significant findings on the inner workings, infection chain, and reliance on the residential proxy ecosystem. Kimwolf has been...

IPCola: A Tangled Mess
A look into the internals behind a large-scale proxy operation, from the sourcing of IPs to the platform itself. How proxy providers utilize everything from TV boxes to free software for building out a pool of unique...

The Stealer Log Ecosystem: Processing Millions of Credentials a Day
In early November of last year Synthient would take on a research project to map out the cybercrime ecosystem. In that effort we would go on to ingest several billion credentials from combolists, stealer logs and...

GhostSocks: From Initial Access to Residential Proxy
This blog post explores the Malware as a Service (MAAS) ecosystem and its adoption of GhostSocks the proxy based malware.