Summary
The core message of this session is that user-installed residential proxies are marketed as harmless passive-income apps, but they create a measurable security and policy problem for networks because customer traffic is routed through participants’ residential or institutional connections. The first speaker narrows the scope to proxies users intentionally install, contrasting them with infection-based proxy malware. Examples include Honeygain, Bright Data’s Earn app, PacketStream, and Pawns.app, all presented as colorful services that invite users to earn money by sharing bandwidth. PacketStream’s pricing illustrates the business model: a “packeteer” receives $0.10 per gigabyte of tunneled traffic, while customers pay $1 per gigabyte to buy proxy traffic.
The talk then breaks down the proxy chain. A customer buys traffic from a proxy provider, traffic passes through back-end or broker infrastructure, and ultimately exits through a residential node toward a target site. Using Pawns.app as an example, the speaker explains how the node authenticates, attempts to escape NAT, and uses an SSH tunnel to connect into backhaul infrastructure that functions like command-and-control. A key point is that the ecosystem is opaque: some companies clearly sell and buy traffic, while others present only one side of the bandwidth marketplace, leaving provider, broker, and backhaul relationships difficult to distinguish.
The most concrete evidence comes from traffic observed through a testbed. The speaker shows proxy traffic scraping ChatGPT, arguing that $1 per gigabyte of text through a residential proxy can be cheaper than paying for AI tokens. Other intercepted examples include attempts to log in to live.com or Outlook accounts with credentials, and Android Debug Bridge traffic resolving a domain to 127.0.0.1 and trying root/root access, similar to behavior associated with the Kimwolf Botnet. From there, the speaker describes reverse engineering 17 residential proxy providers to discover how they retrieve backhaul or C2 IPs, ranging from hard-coded DNS names to authenticated APIs and Bright Data’s unauthenticated but rate-limited WebSocket.
The second part, presented by Martijn from SURFcert, explains how this intelligence is used operationally on SURF’s network. SURF collects NetFlow rather than deep packet inspection, combining source and destination address, ports, protocol, packet counts, and byte counts with feeds of known residential proxy backhaul IPs. Martijn frames residential proxies as problematic because they can put attackers inside the network and violate rules against commercial and anonymous use. The provided transcript ends while he is showing how residential proxy flows and bytes vary over time, including summer-holiday peaks and weekday/weekend patterns consistent with students or employees bringing devices onto the network.
Key Topics
5 key topics from Etienne Khan and Martijn Heitkönig at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Audit user-installed bandwidth-sharing apps on institutional networks.
- Correlate NetFlow with residential proxy backhaul IP feeds.
- Treat proxy back-end IPs on shared hosting cautiously.
- Reverse engineer provider clients to map C2 infrastructure.
- Monitor weekday traffic patterns for proxy-enabled devices.
“Also, we don't allow commercial traffic on a network, and we don't allow anonymous usage of the network.”
Up Next

Next in agenda
Power, Trust, Responsibility in Fragmented Digital World
Miguel De Bruycker
Also on threat intelligence
A Pragmatic Path to Continuous Purple Teaming
Cas van Cooten


Also on threat intelligence
