惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
量子位
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏
Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
J
Java Code Geeks
V
V2EX
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
博客园 - Franky
爱范儿
爱范儿
T
Tailwind CSS Blog
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
博客园_首页
B
Blog RSS Feed
博客园 - 司徒正美
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Help Net Security

Your work apps are quietly handing 19 data points to someone ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
A single platform powers SIM farm proxy networks across 1...
Mirko Zorz · 2026-04-21 · via Help Net Security

Racks of phones and 4G modems, connected to carrier networks and rented out as commercial mobile proxy services, are operating across at least 94 locations in 17 countries. An investigation by infrastructure intelligence firm Infrawatch traced a large portion of those deployments to a shared software platform called ProxySmart, built and operated out of Minsk, Belarus.

SIM farm proxy network

SIM farm (Source: Infrawatch)

Infrawatch identified 87 distinct instances of the ProxySmart control panel exposed on the internet, spread across at least 24 commercial proxy providers and 35 cellular carriers. In the United States alone, farms were found in 19 states, from California and Texas to Maine and Delaware. Researchers assess that an overwhelming majority of the farms it identified are U.S.-based.

“The legal grey area that SIM farms sit in has allowed that model to scale with limited disruption and we assess that it’s highly likely to be facilitating large-scale fraud operations,” said Lloyd Davies, CEO at Infrawatch.

What ProxySmart provides

ProxySmart sells its software to farm operators on a per-SIM pricing model. The platform covers device management, automated IP rotation, customer provisioning, plan enforcement, and anti-bot countermeasures. Operators self-host a control panel and are advised to route traffic through a reverse proxy on cloud infrastructure to obscure the farm’s physical origin.

Devices in the farms are either physical Android phones or USB 4G/5G modems. Phones enroll via an unsigned APK downloaded from the ProxySmart website, with SMS send and receive capability included. Modems are managed through ModemManager, an open-source USB dongle management tool. The Alcatel IK4, available through Amazon and eBay, is among the commonly used modem hardware. The ProxySmart service itself is written in Python and obfuscated using PyArmour.

IP address rotation is achieved by briefly placing mobile devices in airplane mode for three seconds, forcing a reconnection to the carrier and a new IP assignment. Supported tunneling protocols include OpenVPN, SOCKS5, VLESS, and HTTP. VLESS support is relevant in markets such as China, Iran, and Russia, where deep packet inspection is common.

OS fingerprint spoofing

ProxySmart includes an OS spoofing capability that lets operators configure individual proxy ports to present TCP/IP stack characteristics associated with macOS, iOS, Windows, or Android. Anti-fraud and anti-bot systems commonly use TCP/IP stack fingerprinting to infer a connecting device’s operating system.

The ProxySmart feature allows traffic originating from mobile carrier infrastructure to present as a desktop operating system, such as Microsoft Windows. AT&T in the U.S. and Three in the U.K. have implemented network-level countermeasures that block this spoofing.

Geographic spread and carrier coverage

The 94 farm locations Infrawatch identified span North America, Europe, and South America, with confirmed presence in the United States, Canada, United Kingdom, Germany, Spain, Portugal, Ukraine, Latvia, France, Romania, Brazil, Ireland, Netherlands, Australia, Italy, Poland, and Georgia. Farms are concentrated in major metropolitan areas with strong 4G/5G coverage. Some operators use external antennas positioned next to device racks to improve signal stability.

Carrier connectivity available through ProxySmart-powered farms includes AT&T, Verizon, T-Mobile, Vodafone, EE, O2, Three, Telstra, Optus, Rogers, Deutsche Telekom, Orange, SFR, Bouygues, KPN, Kyivstar, Lifecell, Vivo, Claro, and others.

Origins and operator links

ProxySmart is publicly linked through open-source intelligence to a man who advertises assistance with building 4G mobile proxy networks targeting platforms including Instagram, Facebook, and LinkedIn. His personal website promotes hands-on infrastructure setup services.

Coronium, one of the more established operators using ProxySmart, references ProxySmart’s remote script updating service on its installation website and uses an SSH key linked to the platform’s operator in that process.

Commercial providers and KYC

Infrawatch identified 24 commercial proxy services assessed to be running on ProxySmart-backed infrastructure. Some operate their own physical farms; others package third-party farm capacity into retail proxy plans. Some providers target narrow geographic markets and specific use cases including account creation, social media posting and engagement, and general platform automation.

Several services are marketed directly to Russian-speaking audiences as a way to obtain U.S.-located mobile connectivity and access to geo-restricted platforms. Most providers assessed did not appear to require meaningful KYC verification, according to Infrawatch.

A Russia-based service linked to U.S. SIM farms openly advertised censorship circumvention on Telegram, with promotional copy describing access to U.S.-based phones as a way to use top AI services and graphics card platforms.

Detection fingerprint

The ProxySmart control panel produces a consistent HTTP response with a SHA-256 hash of 739f22524fb0fbb64d9bd8bd9e54df73e17abbe8807ca6df350f69078e4bf164. Infrawatch notes this can be queried directly. A small number of larger operators have rebranded their panels to remove ProxySmart references. One instance was found running on a U.K. residential IP address.

UPDATE: April 21, 15:07 ET

Alex Zak, Technical Consultant & Director of Public Relations at ProxySmart, reached out to Help Net Security with the following comment:

“ProxySmart is a data-path proxy management layer, not a SIM farm. It has no voice primitives, no SMS origination, no interconnect functionality — the technical capabilities that define the infrastructure dismantled in the Europol and Secret Service cases the research references. Our deployments run on IoT-class cellular equipment authorised by the carriers themselves, in stock configurations, not the amplifier-heavy rack hardware used for SIM-box fraud. The infrastructure underpins legitimate work across advertising verification, brand protection, cybersecurity research, fraud-detection model training, and application QA, alongside the downstream providers visible on the public internet. Our full response to the research, covering the technical, methodological, and process points in detail, is here.”