top of page
OutSystems-business-transformation-with-gen-ai-ad-300x600.jpg
OutSystems-business-transformation-with-gen-ai-ad-728x90.jpg
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Security researchers uncover underground proxy empire powered by 87,000 compromised devices

Marijan Hassan - Tech Journalist
2 hours ago
2 min read

Cybersecurity researchers have exposed an underground residential proxy operation dubbed "LeakySensey," which monetized unauthorized access to more than 87,000 compromised IP addresses globally. Operating out of Russia, the illicit proxy network turned hijacked consumer routers, firewalls, and legacy VPN appliances into commercial exit nodes sold to cybercriminals, spam operators, and state-sponsored threat groups.



The breach came to light when the service operator misconfigured their own backend database server, leaving internal operational logs, user databases, and customer records exposed on the open internet without authentication.


Mass Automated Brute-Forcing of Legacy Protocols

Investigations by security research firm Cybernews revealed that the threat actor built the proxy empire through automated brute-forcing campaigns targeting outdated network equipment and default credentials:


  • Legacy Protocol Targeting: Over 63,000 nodes were compromised by exploiting insecure Point-to-Point Tunneling Protocol (PPTP) endpoints, alongside more than 24,000 systems breached via Layer 2 Tunneling Protocol (L2TP) connections.

  • Credential Stuffing: A significant portion of the exposed devices relied on default admin/admin credentials or unpatched firmware on end-of-life edge appliances.

  • Active Proxy Capacity: At the time of discovery, 17,858 compromised IP addresses had active proxy credentials configured with a status of "ready" or "connected," enabling commercial clients to route traffic through legitimate residential and commercial subnets.


Commercial Reseller Ecosystem and Underground Operations

Database dumps retrieved from the exposed database indicate the operator served over 56,000 registered customers, with more than 11,000 linked to active Telegram accounts.


The operator distributed access through wholesale API feeds and white-label reseller brands, including "Pure Connect," "Rich Proxy," "SkySocks," and "Opm Proxy." These storefronts allowed third-party proxy vendors to market hijacked residential bandwidth to downstream buyers under the guise of ethically sourced proxy pools.


Moreover, the operational logs revealed that the service operator regularly contended with concurrent security incidents within their own infrastructure. To begin with, external attackers previously compromised the operator's internal Git repository, deploying unauthorized Monero cryptomining scripts and creating 37 unauthorized user accounts.


Competing threat actors also routinely applied credential stuffing to steal LeakySensey’s API keys and siphon proxy bandwidth without payment. Researchers also found evidence that the operator modified developer tools, including Anthropic's Claude Code, to bypass safety filters and automatically manage server routines via custom scripts.


Mitigating Exposure in Legacy Network Infrastructure

The discovery highlights systemic security debt in enterprise and consumer edge devices. Security analysts emphasize that simply changing administrative passwords on affected hardware is insufficient to dismantle persistent proxy bindings.


Network administrators and device owners are urged to retire end-of-life VPN equipment, disable obsolete remote management protocols such as PPTP and L2TP, and implement strict segmenting controls to prevent compromised hardware from serving as persistent pivot points for malicious network traffic.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page