Slaying Hidden Threats in Residential (and Mobile!) IP Proxies

Christo Roberts (Cloudflare)

BSides NYC 2025 (0x05) · Day 1 · Tech - Blue

Overview

In a revealing talk at BSides NYC, Christo Roberts from Cloudflare delved into the clandestine world of residential and mobile IP proxies, exposing how these sophisticated tools are leveraged by a spectrum of actors, from legitimate businesses to black-hat operators, to circumvent traditional bot detection mechanisms. Titled "Slaying Hidden Threats in Residential (and Mobile!) IP Proxies," Roberts' presentation highlighted the escalating cat-and-mouse game between those seeking to hide their online identity and the security industry striving to unmask them. The talk provided a comprehensive look at the underlying technologies, the diverse applications, and the critical defensive strategies required to combat these increasingly prevalent threats.

Watch on YouTube

Visual summary for Slaying Hidden Threats in Residential (and Mobile!) IP Proxies by Christo Roberts
Visual summary for Slaying Hidden Threats in Residential (and Mobile!) IP Proxies by Christo Roberts

Key moments

  1. 2:30 Genesis of the talk and conference themes
  2. 4:30 Introduction to residential and mobile proxies
  3. 5:30 Key takeaway: IP anonymity and authenticity
  4. 6:10 Where's Waldo analogy for hiding in plain sight
  5. 7:00 Who uses residential and mobile proxies?

Slaying Hidden Threats in Residential (and Mobile!) IP Proxies

Speakers: Christo Roberts, Cloudflare

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=ERtf7jOXkYg

Overview

In a revealing talk at BSides NYC, Christo Roberts from Cloudflare delved into the clandestine world of residential and mobile IP proxies, exposing how these sophisticated tools are leveraged by a spectrum of actors, from legitimate businesses to black-hat operators, to circumvent traditional bot detection mechanisms. Titled "Slaying Hidden Threats in Residential (and Mobile!) IP Proxies," Roberts' presentation highlighted the escalating cat-and-mouse game between those seeking to hide their online identity and the security industry striving to unmask them. The talk provided a comprehensive look at the underlying technologies, the diverse applications, and the critical defensive strategies required to combat these increasingly prevalent threats.

Roberts underscored the pervasive impact of these proxy networks, emphasizing that their influence extends far beyond niche cybercrime. From manipulating social media algorithms and driving artificial engagement on platforms like OnlyFans, to enabling high-speed sneaker bots that scalp limited-edition products, and even facilitating AI scrapers like Perplexity in evading detection, the reach of these proxy networks is extensive. This talk is particularly relevant for anyone navigating the digital landscape, as the integrity of online interactions, e-commerce, and content distribution is constantly challenged by the covert operations enabled by these IP proxies.

The core problem Roberts addressed is the quest for IP address anonymity that appears authentic, allowing malicious (or even grey-hat) activities to blend seamlessly with legitimate user traffic. Unlike conventional VPNs, which often flag users as suspicious due to their datacenter IP addresses, residential and mobile proxies leverage real user IPs, making them significantly harder to detect. This talk is a crucial exploration of how this anonymity is achieved, the economic incentives driving its growth, and the advanced techniques security professionals must employ to differentiate genuine users from sophisticated automated threats.

Background

▶ Watch: Genesis of the talk and conference themes (2:30)

The digital realm operates on the fundamental principle of the IP address – a unique identifier akin to a physical street address or phone number, essential for two-way communication on the internet. While many users employ Virtual Private Networks (VPNs) to mask their true IP and enhance privacy, these services often route traffic through datacenter IPs. From a website's perspective, a sudden surge of traffic from a datacenter IP, especially when exhibiting unusual behavior, is a strong indicator of automated activity or malicious intent, leading to easy detection and blocking. This limitation of traditional VPNs created a void for actors seeking anonymity without triggering immediate suspicion.

The problem, as Roberts explained, is that while headers like user agents can be easily spoofed, the originating IP address cannot. This inherent immutability of the IP address forced those seeking advanced anonymity to innovate, leading to the rise of residential and mobile IP proxies. These proxies do not spoof an IP; instead, they route traffic through legitimate, real-world IP addresses belonging to residential internet service providers (ISPs) or mobile carriers. This gives the traffic an air of authenticity that datacenter IPs simply cannot replicate.

The evolution of this industry is rooted in several key technical concepts. Network Address Translation (NAT), commonly found in home routers, allows multiple devices on a local network to share a single public IP address. This means that a single residential IP can represent many internal devices, creating a pool of potential "authentic" IPs. More critically, Carrier Grade NAT (CGNAT) is widely used by mobile network operators to conserve IPv4 addresses. CGNAT dynamically assigns and reassigns public IP addresses to mobile devices as they move between cell towers, leading to frequently changing IPs. This dynamic nature makes mobile IPs exceptionally valuable for evasion, as a fresh IP can be acquired with minimal effort, making it difficult for detection systems to track persistent malicious activity.

The demand for such sophisticated anonymity has spurred the development of specialized tools, including anti-detect browsers which help manage multiple digital identities and evade browser fingerprinting, and a continuous arms race with anti-bot vendors like Cloudflare. This talk explores the intricacies of this ecosystem, where the pursuit of authentic-looking IP anonymity fuels a multi-million dollar industry, blurring the lines between legitimate data gathering and outright cyber exploitation.

Key Findings

▶ Watch: Introduction to residential and mobile proxies (4:30)

Christo Roberts' talk illuminated several critical findings regarding the landscape of residential and mobile IP proxies, underscoring their sophistication and pervasive impact.

Firstly, the most significant discovery is the unparalleled authenticity offered by residential and mobile IP addresses compared to traditional VPN or datacenter IPs. These proxies route traffic through genuine user connections, making it incredibly difficult for target websites to distinguish between a legitimate human user and a sophisticated botnet. Mobile IPs, in particular, are highlighted as the most valuable due to their dynamic nature, frequently changing as devices move between cell towers, which further enhances their evasion capabilities.

Secondly, the talk exposed the wide spectrum of use cases for these proxies, spanning the entire ethical continuum from white-hat to black-hat activities:

  • Black Hat/Gray Hat: This includes sneaker bots that leverage multiple IPs to rapidly purchase limited-edition products for resale, as exemplified by the story of a Discord group coordinating high-value Louis Vuitton Supreme crossovers. It also covers social media manipulation, where individuals or groups use numerous accounts, often from the same physical machine but different proxy IPs, to artificially inflate engagement, as illustrated by the OnlyFans account boosting scenario.
  • AI Scraping: Roberts specifically called out companies like Perplexity AI for reportedly using these mobile IP approaches to circumvent bot detection and scrape data from websites without proper attribution or payment, highlighting a growing concern in the AI industry.
  • White Hat: Legitimate uses include ad verification, where companies need to check if advertisements are being served correctly in specific geographical locations, and market research requiring geo-specific data collection.

A crucial finding is the often-grey legal status of these activities. Roberts explicitly stated that many "gray hat" uses of these proxies are not illegal. For instance, renting out one's unused bandwidth and IP address, even if used for activities like sneaker botting, typically does not lead to legal repercussions for the IP owner. This legal ambiguity contributes to the robustness and growth of the proxy market, as participants operate in a space where they are unlikely to face prosecution.

Furthermore, Roberts detailed the economic drivers behind this industry. Mobile IPs are significantly more expensive to rent than residential or datacenter IPs, reflecting their higher value and effectiveness in bypassing detection. The market offers various options, including rotating IPs for frequent changes or static IPs for persistent access, catering to different operational needs and budgets.

Finally, the talk emphasized the "cat-and-mouse" nature of this security challenge. The proxy providers and anti-detect browser developers are constantly evolving their techniques to stay ahead of detection, forcing security vendors to continuously innovate. This dynamic ensures that no single "silver bullet" solution exists, making ongoing vigilance and adaptable defense strategies paramount.

Technical Deep Dive

▶ Watch: Key takeaway: IP anonymity and authenticity (5:30)

The technical underpinnings of residential and mobile IP proxies are sophisticated, designed to leverage legitimate network infrastructure for deceptive purposes. Roberts meticulously explained how these systems operate, from individual users unknowingly contributing to proxy networks to large-scale, purpose-built proxy farms.

The fundamental mechanism involves a user's traffic being routed through a proxy server, which then forwards the request through a legitimate residential or mobile IP address. This process effectively masks the attacker's true origin, making their traffic appear as if it originates from a regular internet user.

Residential Proxies are often sourced from ordinary home internet connections. Roberts described how individuals can unwittingly or willingly rent out their unused home bandwidth and IP addresses to "middlemen." These middlemen then aggregate these IPs and sell access to others. The speaker cited a real-world example of an architectural firm whose network was compromised, and the attacker exploited their unused IP address space to generate passive income by renting it out, all without the firm's knowledge. This highlights a significant vulnerability: abundant unused bandwidth and a static IP address at home can be monetized, creating a lucrative, albeit sometimes illicit, market.

Mobile Proxies represent an even more advanced form of evasion. Their authenticity stems from the way mobile carriers manage IP addresses. Due to the scarcity of IPv4 addresses and the sheer volume of mobile devices, carriers employ Carrier Grade NAT (CGNAT). This means that a mobile device's public IP address can change frequently as it connects to different cell towers. This constant rotation makes mobile IPs incredibly effective for evading detection, as a bot can cycle through a new, legitimate IP address for each request, making it challenging for anti-bot systems to establish a pattern of suspicious activity tied to a single identifier. Roberts noted that mobile IPs are the most expensive to rent, reflecting their superior evasion capabilities.

The talk also detailed the physical infrastructure supporting these operations, particularly mobile IP proxy farms. Roberts referred to a recent Wired article that reported on a large-scale farm found in New York City, featuring "a hundred thousand" SIM cards connected to high-bandwidth internet. While the Wired article speculated about potential DDoS attacks on the UN, Roberts dismissed this, asserting it was primarily a sophisticated sneaker bot farm – a business designed to sell authentic IP addresses. He also showed an image of a school bus converted into a mobile proxy farm, driving around to ensure the IPs appear even more authentic and frequently changing. These farms demonstrate the industrial scale at which these operations can be conducted, utilizing kits available for purchase, allowing even individuals to set up their own passive income streams by assembling these devices.

To further enhance their evasion, attackers frequently employ anti-detect browsers. These specialized browsers, such as Multilogin, Incogniton, or GoLogin, are designed to manage multiple browser profiles, each with a unique digital fingerprint (user agent, canvas fingerprint, WebGL, fonts, etc.). They integrate seamlessly with proxy networks, allowing an operator to control dozens or hundreds of seemingly distinct "users" from a single machine. Roberts mentioned their cost, typically around $50 per month or more, indicating a significant investment for serious operators. These browsers continuously evolve to bypass the latest fingerprinting and detection techniques, underscoring the dynamic nature of the cat-and-mouse game.

In summary, the technical deep dive reveals a sophisticated ecosystem where legitimate network infrastructure is repurposed for anonymity. From leveraging unused home bandwidth to establishing large-scale mobile proxy farms and employing specialized anti-detect browsers, the goal is always to present automated or illegitimate traffic as indistinguishable from genuine human interaction.

Demo / Proof of Concept

▶ Watch: Where's Waldo analogy for hiding in plain sight (6:10)

While Christo Roberts' presentation did not feature a live, interactive demonstration of tricking detection tools using mobile IPs, he conceptually outlined several proof-of-concept approaches and existing tools that illustrate both the attacker's and defender's perspectives. Roberts candidly admitted that he "didn't get enough time to actually try doing these things" with mobile IPs, but that it was a planned next step in his research.

From the attacker's perspective, the demonstration of capability rested on the discussion of anti-detect browsers and the architecture of proxy farms. Roberts presented slides showcasing examples of anti-detect browsers like Multilogin and Incogniton, detailing their monthly costs and highlighting their core function: to manage multiple browser profiles with unique fingerprints that can be routed through different proxy IPs. This effectively serves as a conceptual proof that attackers have readily available, commercial tools to execute sophisticated evasion tactics. Similarly, the visual examples of mobile IP proxy farms—from a warehouse full of SIM cards to a school bus equipped with cellular devices—served as a powerful illustration of the physical infrastructure enabling large-scale, authentic-looking botnets.

From the defensive perspective, Roberts presented several techniques and tools:

  1. DIY Detection Techniques: He showcased methods that a website administrator could implement independently. One example involved checking for discrepancies between an IP address's geographical origin and the browser's stated language headers. If an IP is from Germany but the browser's Accept-Language header only lists English, it could indicate suspicious activity. Another "cool trick" mentioned was leveraging WebRTC (Web Real-Time Communication). A server could challenge the browser for its WebRTC IP address and then compare it against the requesting IP address. If these two IPs do not match, it strongly suggests the use of a proxy or VPN, providing a potential indicator of compromise.
  2. Third-Party Proxy Detection Services: Roberts introduced services like ProxyDetect.live, which offer a paid solution for evaluating the authenticity of an incoming IP address. He showed a screenshot of such a service, indicating how it might score an IP (e.g., a high VPN score if testing from a VPN). These tools provide a more robust and automated approach than DIY methods, leveraging extensive databases and heuristics to identify suspicious IPs.
  3. Cloudflare Turnstile: As a core defensive offering, Roberts provided a detailed explanation of Cloudflare's Turnstile. This free-to-use, CAPTCHA-replacement mechanism performs a series of non-intrusive browser tests in the background to verify if a user is human, without requiring frustrating image puzzles. He demonstrated its simplicity, showing it as a checkbox or a brief loading animation. Turnstile's integration, even for non-Cloudflare customers, involves embedding a JavaScript snippet that initiates an iframe to Cloudflare's platform, returning a token upon successful verification. This token is then used to allow sensitive actions like logins or checkouts, acting as a powerful deterrent against automated bots.

While a live exploit demonstration was absent, the talk effectively used examples, conceptual flows, and existing tool showcases to illustrate the complex interplay between attackers and defenders in the realm of IP proxies.

Defensive Implications

▶ Watch: Who uses residential and mobile proxies? (7:00)

The proliferation and sophistication of residential and mobile IP proxies present significant challenges for online defenders. Christo Roberts outlined various strategies, ranging from do-it-yourself (DIY) methods to leveraging professional bot management solutions, emphasizing that the "cat-and-mouse" game necessitates continuous adaptation.

DIY Detection Techniques:

For organizations with limited resources, some basic detection methods can be implemented:

  • IP-to-Language Header Mismatch: One heuristic involves cross-referencing the geographical location derived from an incoming IP address with the language preferences specified in the HTTP Accept-Language header. A mismatch—for example, an IP from Germany requesting content only in English—could be a weak indicator of proxy use.
  • WebRTC IP Leakage: Modern browsers support WebRTC, which can, under certain circumstances, reveal a client's true local and public IP addresses, even when using a proxy or VPN. A server can challenge the browser to establish a WebRTC connection and then compare the IP address reported by WebRTC with the IP address of the initial HTTP request. A discrepancy suggests the client is attempting to mask its true origin.

However, Roberts cautioned that these DIY methods are often rudimentary and easily circumvented by sophisticated attackers employing anti-detect browsers or advanced proxy services designed to mask such inconsistencies. They offer a baseline defense but are unlikely to deter determined adversaries.

Leveraging Commercial Proxy Detection and Bot Management Tools:

A more robust approach involves subscribing to specialized services. Roberts highlighted ProxyDetect.live as an example of a tool that provides a rating for an IP address's authenticity, indicating if it's likely a VPN, proxy, or a clean residential IP. These services aggregate vast amounts of data to make more accurate assessments.

For comprehensive protection, Roberts strongly recommended professional bot management vendors. He referenced the 2024 Q3 Forrester Wave report on Bot Management, identifying key players like Cloudflare, DataDome, and Human Security. These platforms offer multi-layered defense mechanisms:

  • Heuristics and Machine Learning: Cloudflare's approach, as detailed by Roberts, involves analyzing a wide array of signals. This includes the IP address, its geographical location, associated Autonomous System Number (ASN), ISP ranges, HTTP headers, request paths, and behavioral patterns. Machine learning models are continuously trained on this data to identify anomalous traffic that deviates from typical human behavior.
  • Behavioral Analysis: Beyond static indicators, these systems monitor user interactions—mouse movements, keystrokes, navigation patterns—to distinguish between human and automated activity. Bots, even sophisticated ones, often exhibit predictable or non-human patterns of interaction.
  • Cloudflare Turnstile: This is Cloudflare's flagship solution for mitigating automated traffic without resorting to the frustrating experience of traditional CAPTCHAs. Turnstile is a free-to-use, JavaScript-based challenge that runs a series of non-intrusive tests in the background within the user's browser. These tests might include evaluating browser properties, device characteristics, and user behavior over time. Upon successful verification, Turnstile issues a token that can be used to authorize actions like logging in or checking out. Crucially, Turnstile can be integrated into any website, even if it's not hosted by Cloudflare, by simply embedding a JavaScript snippet. This allows any web service to benefit from Cloudflare's advanced bot detection capabilities, providing a robust defense against automated attacks, including those originating from residential and mobile proxies.

Roberts underscored that the decision to invest in these professional solutions hinges on the value of the data and user traffic being protected. Given that the use of these proxies is often not illegal and the industry is constantly evolving, a "progress over perfection" mindset is essential. Defenders must continuously adapt their strategies, understanding that no single solution will offer permanent immunity. Investing in leading bot management providers becomes a strategic necessity for organizations looking to safeguard their online assets against these persistent and elusive threats.

Key Takeaways

  • Authenticity is King: Residential and mobile IP proxies offer unparalleled authenticity compared to traditional VPNs, making them the preferred choice for sophisticated evasion tactics across various online activities.
  • Mobile IPs Lead the Charge: Due to their dynamic nature and frequent changes facilitated by Carrier Grade NAT (CGNAT), mobile IPs are the most valuable and expensive proxy type, providing superior anonymity and evasion capabilities.
  • Broad Spectrum of Use Cases: These proxies are employed by a diverse range of actors, from legitimate businesses (ad verification, market research) to gray-hat operators (sneaker bots, AI scraping like Perplexity) and black-hat entities (social media manipulation, botnets).
  • Legal Gray Area Fuels Growth: Many activities facilitated by these proxies, particularly "gray hat" operations, are not strictly illegal, contributing to the thriving market for proxy services and making legal recourse challenging.
  • Cat-and-Mouse Game: The battle between proxy providers/anti-detect browser developers and anti-bot vendors is an ongoing, evolving "cat-and-mouse" race, requiring continuous innovation from both sides.
  • Professional Defense is Crucial: While basic DIY detection methods exist, effective and scalable defense against sophisticated residential and mobile proxy threats necessitates investment in advanced bot management solutions, such as those offered by Cloudflare, which leverage heuristics, behavioral analysis, and innovative tools like Turnstile.

About the Speaker(s)

Christo Roberts, a speaker from Cloudflare, shared his insights at BSides NYC. Originally from California, Christo spent two decades living across various neighborhoods in New York City, including the Upper West Side, Manhattan, Alita, Park Slope, Williamsburg, and Greenpoint, before moving back to Northern California six years ago to be closer to his mother. He built his career in New York City and expressed a strong affinity for the city, even staying out late enjoying it the night before his talk. Roberts' journey into this specific research topic began somewhat unconventionally; after an initial abstract for BSides San Francisco was generated with the help of Chat GPT, he realized the need for genuine, in-depth research to fulfill the conference's non-commercial focus. This led him to delve deeply into the subject of residential and mobile IP proxies, resulting in presentations at BSides San Francisco (themed "There Be Dragons") and the Houston Security Conference (Hugh Seccon, themed "Space Cowboys") before his talk at BSides NYC.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A surface-level survey of residential and mobile proxy infrastructure that reads more like a Cloudflare product pitch than original research. Roberts clearly did background reading and assembled a competent explainer, but this is fundamentally a vendor rep presenting publicly available information and pointing audiences toward his employer's paid services.

Heather Calloway (CISO) — WEAK

Roberts clearly knows the proxy ecosystem, and the technical survey is competent — but this is a threat landscape tour with no institutional weight behind it. The defensive guidance is thin, the governance angle is absent, and the talk never tells anyone with real accountability what to do differently.

→ Top-rated talks at BSides NYC 2025 (0x05)

All talks from BSides NYC 2025 (0x05)