From residential IPs to resold data: The hidden economy behind a scraping Service

OWN-CERT
-
29/9/2026
Behind a scraping service, a network of residential proxies and resold data: OWN-CERT's investigation into an hidden economy.OWN Security

Cet article est seulement disponible en anglais.

The IPIDEA network takedown by Google

On the 28th of January 2026, Google Threat intelligence published an article detailing the disruption of what it described as the world’s largest residential proxy network: IPIDEA1.

According to their findings, the entire ecosystem relied on the exploitation and deployment of malicious Software Development Kits (SDKs) within legitimate applications that enabled the transformation of devices into residential proxies servers, allowing third parties to route internet traffic through the devices’ residential Internet Protocol (IP) addresses. Access to these compromised devices was then resold as a commercial proxy service.

Figure 1: how SDK monetize traffic (source: https[:]//proxyway[.]com/research/internet-sharing-sdks-app-monetization)

‍

The IPIDEA proxy network was based on a network of multiple brands used to resell the proxies and Virtual Private Network (VPN) services:

  • 360 Proxy (360proxy[.]com)
  • 922 Proxy (922proxy[.]com)
  • ABC Proxy (abcproxy[.]com)
  • Cherry Proxy (cherryproxy[.]com)
  • Door VPN (doorvpn[.]com)
  • Galleon VPN (galleonvpn[.]com)
  • IP 2 World (ip2world[.]com)
  • Ipidea (ipidea[.]io)
  • Luna Proxy (lunaproxy[.]com)
  • PIA S5 Proxy (piaproxy[.]com)
  • PY Proxy (pyproxy[.]com)
  • Radish VPN (radishvpn[.]com)
  • Tab Proxy (tabproxy[.]com)

According to their findings, these residential proxies providers relied on a few SDKs that were embedded in a large number of legitimate desktop and mobile applications, allowing the providers to turn users’ devices into nodes within their residential proxy networks:

  • Castar SDK (castarsdk[.]com)
  • Earn SDK (earnsdk[.]io)
  • Hex SDK (hexsdk[.]com)
  • Packet SDK (packetsdk[.]com)

The IPIDEA actors also rely on “free VPN” services which do indeed offer free services, but in exchange the device that connects to them also joins the network as a node. The following services were identified:

  • Galleon VPN (galleonvpn[.]com)
  • Radish VPN (radishvpn[.]com
  • Aman VPN (defunct)

Finally, according to their analysis, they also identified infrastructures overlaps between several domains communicating with the SDKs suggesting that different SDKs may ultimately be operated by the same threat actor. Also, some of the domains communicating with the SDKs (what they call tiers-one Command-and-Control (C2) domains) were also observed as part of BadBox 2.0 botnet.

Why are we talking about all this?

Everything started with a scraping service. As part of our anti-scraping research and monitoring activities, we sometimes monitor web-scraping services and analyze their observable behavior to better understand how they operate. This includes studying behavioral patterns and client-side characteristics that may help fingerprint the service, as well as, where legally and technically permissible, identifying publicly observable elements of the infrastructure on which these services rely.

Figure 2: https[:]//www[.]coreclaw.com/

Coreclaw is a web-data extraction and web-scraping platform. In simple terms, it allows users to automatically collect information from public websites and turn it into structured data such as CSV, JSON, Microsoft Excel files, or API responses. The platform provides pre-built “workers” which are essentially ready-made for scraping and automation jobs. For example, it currently advertises workers for:

  1. Google Maps – extract business, contact details, review, opening hours etc...
  1. Google search – structured search result data (often called SERP2)
  1. Amazon – products, prices, reviews, rankings etc...
  1. Instagram / TikTok – public post/profile informations
  1. Youtube – channel and video informations
Figure 3: https[:]//www.coreclaw[.]com/store/categories

‍

Using this service is quite simple, and it's possible to run the workers directly from the website or by using an API.

CoreClaw seems to be part of a HongKong based company3 named “Apex DataWorks Limited”:  

Figure 4: https[:]//www[.]coreclaw[.]com

‍

However, the “/contact” URL references a different company “Vertex Digital CreationsLimited”, suggesting that this entity may be associated with the operation of the service:

Figure 5: https[:]//www[.]coreclaw[.]com/contact

‍

The address remains consistent with Apex Data works: “Unit 9, 1/F, The Cloud, 111 Tung Chau Street, Tai Kok Tsui, Hong Kong”.  

We found no reference to this exact company name. However, a company named “Vertex Apex Limited”4 was registered in Hong Kong 2 days before Apex Dataworks Limited was reportedly registered in Hong Kong on 24 of February 2026, two days before Apex Dataworks Limited  

The address leads to almost nothing interesting as this is a corporate building where we can find many offices for a wide variety of activities (industry, technology, and even yoga).

We could go on at length with this type of research, but as it stands, it is not easy to establish a link between what appear to be registration addresses for what seems to be shell companies registered in Hong Kong and actual services.  

Nevertheless, the combination of naming similarities, incorporation dates, and shared or closely associated registration details was sufficient to warrant further scrutiny.

‍

What caught our attention

Our investigation could have ended there, but one option on CoreClaw caught our attention: the possibility to “select an execution node" (covering many countries worldwide). When tested, 129 locations were available as execution nodes.

Figure 6: exit node selection from a worker

The legitimate question that arises at this point is how does the service manage to provide such a large number of geographically distributed locations?  

When using the service within a single country, we were surprised to see the number of different IP addresses they offer. Furthermore, sometimes the fingerprints changed slightly, potentially indicating the use of residential proxy networks.

Despite the main domain is “coreclaw[.]com”, we identified another URL that exposed the exact same website content:

Figure 7: http[:]//www[.]symbol365.com/

At some point during the website loading process, an image is retrieved from an object-storage endpoint hosted at “oss.cafescraper.com”. We can also observed requests to “oss.coreclaw.com” which again confirms the link between the 2 domains:

Figure 8: http[:]//www[.]symbol365.com/

The domain and main website are no longer accessible however, portions of the service’s documentation remain publicly available, mostly because one specific subdomain is still hosted through Mintlify and Vercel:

We then observed that the interface shown in the available screenshots is visually identical, or highly similar, to the CoreClaw interface. This provides an additional technical indication of a relationship between the two services, although visual similarity alone does not conclusively establish common ownership or operation...

Figure 9: https[:]//docs.cafescraper.com/cn/actor-pricing-rule

Also, by default, the documentation is displayed in Chinese, as are some comments within the loaded JavaScript (JS) files, which potentially offers a clue as to the origin of the developers behind these solutions. However, they are not at this stage sufficient to reliably determine their nationality, geographic location, or origin.

Figure 10: https[:]//docs[.]cafescraper[.]com/cn/find-actor

Of course, both the domains were hosted on a common IP:

Domain IP ASN Registrar CreationDate
coreclaw[.]com 43.152.2.154 139341 Alibaba Cloud Computing Ltd 2021-01-06
symbol365[.]com 81.71.150.222 45090 DNSPod, Inc. 2020-06-11
cafescraper[.]com 43.152.2.154 139341 Aceville Pte. Ltd. 2025-07-29

And we finally discover links to a GitHub account “CafeScraper”:

Figure 11: https[:]//docs[.]cafescraper[.]com/cn/actor/actor/what-is-actor#-%E4%BB%A3%E7%A0%81%E7%A4%BA%E4%BE%8B
Figure 12 : https[:]//github[.]com/CafeScraper

CafeScraper is part of an organization called “CoreClaw” on Github, the official account of the CoreClaw service.

Figure 13: https[:]//github[.]com/Core-Claw

Now, where it gets more interesting is that only two accounts list themselves as part of the CoreClaw organization on GitHub: “CafeScraper” already identified above, and another account that is quite well-known: Kael-Odin.

Kael-Odin is a technical writer and developer associated with web-scraping and proxy ecosystem. His public work focuses on technical subjects including residential proxies, anti-bot mechanisms, TLS fingerprinting, browser automation and web-scraping infrastructure. He also maintains scraping-related projects on Apify5, including a Crawl4AI-based web-content extractor and an Amazon search/product scraper.

Kael-Odin, in fact, is also the only listed developer of Thordata, a well-known residential proxy service:

Figure 15: https[:]//www.thordata[.]com/

Thordata currently advertises 100M+ residential IPs across 190+ countries. Its documentation describes the addresses as coming from “real residential networks” and supports country/city/ASN targeting, rotating sessions and sticky sessions.

In a February 2025 article6, he explicitly explains how Thordata fuel proxies:

  1. By paying customers directly providing access to their residential IPs
  1. By reselling residential IPs from partners

According to another blog post, he also claims to supply the network using an “opt-in SDK model”7. App developers embed a software development kit (SDK) into consumer apps, like free games or utilities. The final user agrees via terms of service to share their device's internet traffic and unused bandwidth in exchange for using the app.  

Yes, we are indeed talking about the "terms of service", the long document that no one ever really reads. We aren't really at the same level of consent as the cookie opt-out windows mandated by the GDPR.

Finally, when a company develops both web-scraping solutions and the proxy infrastructure capable of supporting large-scale data collection, an obvious question arises: could those capabilities also be used to build and commercialize datasets directly?

We assume, for the purposes of this analysis, that the data was scraped legitimately and with the consent of the platforms involved...

At the time of writing, we identified 60 available datasets being offered. Among the largest ones were likely scraped from major social media platforms (TikTok, X, Youtube and Amazon) or from an AI provider (Anthropic).

Figure 16: https[:]//datamall[.]thordata.com/

In the sample we analyzed, the data from social media platform contains public datas scraped directly from user accounts. In the case of TikTok, for example, actual user images and videos URLs and profile data were scraped and are subsequently being resold.

Figure 17: TikTok data sample (request)
Figure 18: TikTok profile video URL

The Claude opus data samples we downloaded contain likely intercepted (prompt, completion) pairs pulled from live claude-opus-4-8 traffic. This is the standard raw dataset shape that can be used for distilling a model on Claude's outputs or reverse-engineering its system prompts. Also, as it is possible to identify multiple different device_id and different topics (music scraper, care-rental scraping etc...), this dataset is likely aggregated traffic from people's private Claude Code sessions.

As for the question of how they gained access to this data, that is a very good question, but it is likely the access was not so legitimate (potentially the theft of users sessions cookies as it is very common?)

Figure 19: claude-opus-4-8 dataset example

‍

But the proxy network is ethically sourced. Right ...?

That's where things get interesting. Remember the previous infrastructure discovered? We have established a direct link between: coreclaw[.]com (the scraping service) and cafescraper[.]com (the previous/old project). We have shown that behind this scraping project there is also a developer who is part of the Thordata residential proxy network service.

Now where it gets interesting, taking a look at MX records for cafescraper[.]com, we identified this specific mail server hostname “mail.yougan.email”:

Pivoting on domains that answered with the “mail.yougan.email” MX record, yielded some quite interesting results:

  1. cherryproxy[.]net (instead of cherryproxy[.]com mentioned in the IPIDEA proxy network investigation by Google)
  1. castarsdk[.]com mentioned in the IPIDEA proxy network investigation by Google
  1. 360proxy[.]com mentioned in the IPIDEA proxy network investigation by Google
  1. datalabslmtd[.]com (a reference to “DATALABS LIMITED” cert that was mentioned in IPIDEA proxy network investigation by Google?)
CreationDateDomainStatusRegistrarIPASNISP
06/02/2026fancyadsworld.comactiveAceville Pte. Ltd.---
12/12/2025jeless.comactiveNAMECHEAP INC104.17.232.2913335CloudFlare Inc.
25/11/2025haiouchuhai.comactiveAlibaba Cloud Computing Ltd180.163.147.844811ChinaNet Shanghai Province Network
04/11/2025jsbeilazhi.comactiveAlibaba Cloud Computing Ltd---
29/07/2025cafescraper.comactiveAceville Pte. Ltd.43.152.2.154139341ACE
19/05/2025musetron.comactiveAlibaba Cloud Computing Ltd155.102.176.8424429Alibaba Cloud Llc
14/02/2025feralove.comactiveNAMECHEAP INC47.88.27.15345102Alibaba Cloud - Us
10/02/2025aetheriagem.comactiveNAMECHEAP INC104.17.232.2913335CloudFlare Inc.
20/01/2025iping.ccactiveNameCheap, Inc.172.67.221.1213335CloudFlare Inc.
16/01/2025mozaura.comactiveNAMECHEAP INC172.67.198.6413335CloudFlare Inc.
07/11/2024castarsdk.cominactiveNameCheap, Inc.172.67.181.16813335CloudFlare Inc.
29/10/2024sjwhmedia.comactiveAlibaba Cloud Computing Ltd120.27.230.4837963Aliyun Computing Co. Ltd
28/02/2024tingquanxunbao.comactiveAlibaba Cloud Computing Ltd169.254.254.254--
29/12/2023lingyuntechltd.cominactiveNAMECHEAP INC---
14/12/2023datalabslmtd.cominactiveNAMECHEAP INC---
22/11/2023hkguangling.cominactiveNAMECHEAP INC47.76.79.21045102Alibaba Cloud - Hk
22/11/2023jikedatech.cominactiveAlibaba Cloud Computing Ltd8.218.208.24045102Alibaba Cloud (Singapore) Private Limited
22/11/2023romebeldenlimited.cominactiveNAMECHEAP INC---
21/11/2023akesuotech.comactiveAlibaba Cloud Computing Ltd---
21/11/2023fudianinfo.comactiveAlibaba Cloud Computing Ltd---
21/11/2023linglingfakeji.cominactiveAlibaba Cloud Computing Ltd---
21/11/2023marsbrothersltd.comactiveAlibaba Cloud Computing Ltd---
14/11/2023huowangkeji.cominactiveNAMECHEAP INC192.64.119.19522612Namecheap Inc.
14/11/2023wangzichuanshuo.cominactiveNAMECHEAP INC192.64.119.8122612Namecheap Inc.
13/11/2023aikedekeji.cominactiveAlibaba Cloud Computing Ltd8.218.208.24045102Alibaba Cloud (Singapore) Private Limited
13/11/2023sandianyisikeji.cominactiveAlibaba Cloud Computing Ltd---
13/11/2023yingpukeji.comactiveAlibaba Cloud Computing Ltd---
13/11/2023zhimawodekeji.comactiveAlibaba Cloud Computing Ltd---
11/11/2023haiouwuliu.comactiveDNSPod, Inc.106.53.160.2745090Tencent Cloud Computing (Beijing) Co. Ltd.
10/11/2023aidiinfo.comactiveAlibaba Cloud Computing Ltd---
10/11/2023yougan.emailactiveAlibaba Cloud Computing Ltd---
08/10/2023cherryproxy.netinactiveAceville Pte. Ltd.155.102.54.13724429Alibaba Cloud Llc
16/08/2023sheenboge.comactiveAlibaba Cloud Computing Ltd139.224.110.19437963Aliyun Computing Co. Ltd
12/04/2023haioulianmeng.comactive22net, Inc.101.246.176.2384847Beijing Time-Vision Telecommunication Technical Ltd
13/07/2022puliangming.comactiveAlibaba Cloud Computing Ltd47.91.170.22245102Alibaba Cloud - Hk
13/01/2022jskelixin.comactiveGname.com Pte. Ltd.172.67.220.16913335CloudFlare Inc.
09/08/2021beilazhi.comactiveAlibaba Cloud Computing Ltd47.91.170.22245102Alibaba Cloud - Hk
29/10/2020lingjiang.coactiveAlibaba Cloud Computing Ltd203.107.60.19237963Aliyun Computing Co. Ltd
24/10/2019zhimawode.comactiveAlibaba Cloud Computing (Beijing) Co., Ltd.139.196.121.3837963Aliyun Computing Co. Ltd
21/08/2019letshow666.comactiveAlibaba Cloud Computing (Beijing) Co., Ltd.104.21.63.16613335CloudFlare Inc.
27/02/2019jslingjiang.comactiveAlibaba Cloud Computing (Beijing) Co., Ltd.---
01/09/2013360proxy.cominactiveNameCheap, Inc.172.66.41.1813335CloudFlare Inc.
30/10/2000liuxing.comactiveAlibaba Cloud Computing (Beijing) Co., Ltd.163.181.66.21124429Alibaba Cloud Llc

So now we've reached the point where we're starting to wonder if there isn't a direct link between Thordata’s proxy network and the IPIDEA pool or other proxy providers.

Also, while looking at Thordata favicon, we identified 2 IPs where this favicon was identified in early January 2026:

Figure 20: https[:]//en[.]fofa.info/result?qbase64=aWNvbl9oYXNoPT0iMTUyMDM1OTY5MSI=
IPASNISPLocation
119.28.104.114AS132203Tencent Building, Kejizhongyi AvenueSingapore
49.51.72.189AS132203Tencent Building, Kejizhongyi AvenueUnited States

The second IP is interesting as we can identify an overlap between 3 subdomains resolved on this IP:

  • admin-api.thordata[.]net
  • thor.worldrift[.]com
  • thor-admin-api[.]worldrift.com
Figure 21: https[:]//app[.]validin.com/detail?type=ip&find=43.153.121.141#tab=resolutions

The domain “worldrift[.]com” was not mentioned in any report that we searched. We sought to understand the exact role of this domain, but without really managing to determine what it is used for. However, certificate transparency logs provide us with very clear indications regarding the infrastructure associated with this domain:

HostnameFirst cert UTCLast cert UTCIssuing CASObsevation
ownips.worldrift.com23/12/202423/01/2026SSL.com RSA SSL subCAEarliest hostname observed (Dec 2024) and most recently renewed (Jan 2026). ownips[.]com was a residential proxy provider
worldrift.com23/12/202423/01/2026SSL.com RSA SSL subCA | SSL.com TLS Issuing RSA CA R1Appears only as a co-SAN alongside brand/admin hostnames, never certified alone.
pygloadmin.worldrift.com12/03/202512/03/2025Sectigo RSA Domain Validation Secure Server CAPotentially related to PyProxy, another proxy provider mentioned in Google IPIDEA report
adsfancy.worldrift.com23/09/202522/11/2025R12 | R13Only hostname using Let's Encrypt (R12/R13) rather than a commercial CA.
ipidea.new.worldrift.com28/10/202528/10/2025SSL.com TLS Issuing RSA CA R1Staging variant of the IPIDEA endpoint.
ipidea.api.worldrift.com29/10/202529/10/2025SSL.com TLS Issuing RSA CA R1API endpoint named for IPIDEA mentioned in Google report
thor-admin-api.worldrift.com18/11/202518/11/2025TLC DV TLS CAThordata admin api
res-mid-openapi.worldrift.com01/12/202501/12/2025TLC DV TLS CAResidential middleware open API ?
new.ipidea.worldrift.com10/01/202610/01/2026SSL.com RSA SSL subCASecond naming convention for the same staging endpoint; issued Jan 2026.
packetadmin.worldrift.com14/01/202614/01/2026SSL.com RSA SSL subCAPotentially related to Packet SDK mentioned in Google IPIDEA report

‍

We also looked at passive DNS records, and the results (just a sample) speak for themselves. We can identify many residential proxy providers:

HostnameProvider identifiedFirst seenLast seenDistinct IPV4IPV4
worldrift.comApex26/08/201314/08/2026866.96.147.117;69.172.201.153;72.52.4.90;91.195.241.121;139.196.121.38;139.224.19.193;209.99.64.53
2345proxy.worldrift.com2345Proxy04/01/202410/02/2026143.135.99.100
911socks.worldrift.com911 S5 / socks15/05/202309/02/2026443.129.30.253;43.134.220.235;43.135.99.100;43.154.171.107
abcproxy.worldrift.comABC Proxy17/08/202311/02/2026147.254.28.65
wp.cherry.worldrift.comCherry Proxy09/03/202524/02/20261119.28.119.196
ipchange.worldrift.comIP changer10/08/202310/02/2026143.135.99.100
ipchanger.worldrift.comIP changer15/05/202326/02/2026443.129.30.253;43.134.220.235;43.135.99.100;43.154.171.107
ip2world.worldrift.comIP2World16/05/202313/02/202638.217.25.60;47.238.155.34;47.242.40.114
ipdc.worldrift.comIPDC04/09/202325/02/2026147.102.96.178
ipdcworld.worldrift.comIPDC25/10/202325/02/2026147.102.96.178
admin.glo.ipidea.worldrift.comIPIDEA16/05/202325/02/202628.218.139.246;47.76.50.67
ipidea.api.worldrift.comIPIDEA29/10/202526/02/2026147.242.183.49
ipidea.new.worldrift.comIPIDEA28/10/202527/02/2026147.242.183.49
ipidea.test_webui.worldrift.comIPIDEA21/01/202623/02/2026147.76.37.141
ipidea.worldrift.comIPIDEA16/05/202328/02/202628.218.139.246;47.242.183.49
new.ipidea.worldrift.comIPIDEA10/01/202627/02/2026147.242.183.49
ipolyadmin.worldrift.comIPOly05/08/202318/01/2026147.242.248.250
luna.worldrift.comLunaProxy05/08/202309/02/2026443.129.30.253;43.134.220.235;43.135.99.100;43.154.171.107
httpmars.worldrift.comMarsProxy17/10/202424/02/202618.219.131.218
ipmars.worldrift.comMarsProxy17/11/202313/02/202618.219.131.218
moonproxy.worldrift.comMoonProxy26/09/202326/02/202618.219.131.218
novada.worldrift.comNovadaProxy07/04/202526/02/2026218.153.72.49;47.236.113.192
novadablog.worldrift.comNovada09/09/202527/02/2026147.236.115.215
onwips.worldrift.comOwnIPs22/08/202427/02/2026147.238.103.134
ownips.worldrift.comOwnIPs22/12/202323/02/202628.218.139.246;47.238.103.134
pycn.worldrift.comPyProxy20/11/202327/02/2026147.100.123.162
pygloadmin.worldrift.comPyProxy16/05/202326/02/202638.217.66.43;8.218.28.66;47.242.40.114
pyhttp.worldrift.comPyProxy23/02/202426/02/2026147.100.123.162
cn.roxlabs.worldrift.comRoxlabs16/05/202325/02/202628.218.139.246;47.238.113.174

‍

HostnameProvider identifiedFirst seenLast seenDistinct IPV4IPV4
starproxy.worldrift.comStarProxy21/09/202324/02/202618.218.139.246
tabproxy.worldrift.comTabProxy11/10/202325/02/202618.219.131.218
ipcheck.worldrift.comIP tooling18/04/202521/02/2026147.102.96.178
iping.admin.worldrift.comIP tooling11/07/202523/02/2026147.254.79.94
ipping.worldrift.comIP tooling20/05/202524/05/2025147.102.96.178
es-mid-openapi.worldrift.comOpenAI middleware18/01/202618/02/2026147.83.115.94
res-mid-openapi.worldrift.comOpenAI middleware01/12/202514/08/2026147.83.115.94
res-mid.worldrift.comOpenAI middleware11/12/202526/02/2026147.86.44.243
staticres.worldrift.comStatic proxy05/11/202327/02/2026443.129.30.253;43.134.220.235;43.135.99.100;43.154.171.107
xc-static-mid-api.worldrift.comStatic proxy middleware11/11/202514/08/2026243.134.78.102;43.156.112.50
proxy-test.worldrift.comTesting16/02/202617/02/20261107.150.96.37
b.castar.worldrift.comSDK: CastarSDK11/01/202619/02/2026143.153.53.151
earnsdk-web.worldrift.comSDK: EarnSDK01/07/202427/02/2026343.153.18.201;43.153.25.95;170.106.197.45
earnsdk-webapi.worldrift.comSDK: EarnSDK29/06/202426/02/2026343.153.18.201;43.153.25.95;170.106.197.45
packetadmin.worldrift.comSDK: PacketSDK25/05/202327/02/202638.217.82.48;47.238.112.60;47.242.248.250
packetsdk-web.worldrift.comSDK: PacketSDK05/07/202427/02/2026243.135.163.100;43.153.18.201
packetsdk-webapi.worldrift.comSDK: PacketSDK20/10/202427/02/2026143.153.18.201
sdk-aggr-web.worldrift.comSDK: aggregator11/06/202517/02/2026147.239.58.232
sdk-aggr-webapi.worldrift.comSDK: aggregator13/10/202526/02/2026147.239.58.232
grafana-sdk-server.worldrift.comSDK: monitoring06/11/202524/02/2026143.134.187.163
b.galleonvpn.worldrift.comVPN22/07/202515/02/2026143.153.44.10
hm.galleonvpn.worldrift.comVPN24/08/202525/02/2026143.135.155.198
pptp.log.worldrift.comVPN20/11/202323/02/20261175.27.159.141
b.ad360.worldrift.com360Proxy27/09/202325/02/2026343.134.175.150;43.156.2.25;101.32.246.29
b.ad922.worldrift.com922Proxy11/12/202327/02/2026243.133.59.91;43.134.175.150
ipnews.worldrift.comIP tooling22/04/202524/02/2026147.102.96.178
thor-admin-api.worldrift.comThodata18/11/202527/02/2026243.153.121.141;49.51.50.72
thor.worldrift.comThodata11/11/202426/02/2026343.153.121.141;49.51.50.72;124.156.201.72
cheescoin.worldrift.comMonetisation20/11/202326/02/2026243.154.40.89
coinruning.worldrift.comMonetisation12/04/202426/02/202648.219.168.31;43.135.99.100
chm.caster.worldrift.comSDK: CastarSDK13/03/202527/02/202618.219.168.31;43.134.220.235;43.154.171.107;101.32.126.53
hm.caster.worldrift.comSDK: CastarSDK16/02/202525/02/2026143.153.93.56
b.adsdk.worldrift.comSDK: other22/01/202523/02/2026143.159.146.73
b.adsdkapp.worldrift.comSDK: other21/07/202524/02/2026143.153.53.151
b.wpsdk.worldrift.comSDK: other20/04/202525/02/2026143.153.93.56

‍

2 other domains were also seen using the Thordata favicon (3ab85cc6a6b88ce6c6)

CreationDateDomainStatusRegistrarIPASNISP
2025-10-22 raiseproxy.com Active Xin Net Technology Corporation 172[.]67.170.160 13335 CloudFlare Inc.
104[.]21.55.71
2025-10-10 dingproxy.com Active Alibaba Cloud Computing Ltd. 172[.]67.133.115 13335 CloudFlare Inc.
104[.]21.5.125

‍

‍

Thordata x NetNut connection?

From one of the thordata[.]com subdomains, we also identified a direct reference to “NetNut”. This name might not ring a bell if you don't actively follow reports on residential proxy networks and other botnets.

NetNut is another commercial residential and ISP proxy provider. A recent publication from Synthient8 describes how NetNut also offers datasets and curated web-scraping services. This publication also provides evidence that NetNut’s proxy network is, at least in part, supplied through an SDK that turns consumer devices into proxy nodes (the “Popa” Android proxyware SDK).

Figure 22: https[:]//alt[.]thordata.com

Service observation results

Alright, so one question remains: is this proxy network truly legitimate or not?

That is open to debate : after all, if the user accepts the Terms of Service, the responsibility is arguably theirs to some extent. The real issue arises with proxy providers operating in a "gray area" that populate their networks using botnets and compromised devices.

We tried to answer that question by using the service. Our observations are based on a relatively small sample (9k+ distinct requests made from 2.6k IPs) but remain quite interesting.  

Figure 23: most observed ASNs IP’s

We looked at the geographic distribution of the SpaceX / Starlink IPs we identified: Madagascar, Venezuela, Samoa, Kenya, Maldives etc... This is not the IP we were expecting when the service is heavily used by subscribers in the United States, Canada, United-Kingdom or Germany (based on external observations from electroiq9 as Starlink don’t publish official statistics about its consumer base).

As it is probably not economically viable at scale to buy Starlink services to resell proxy infrastructure, these IPs are likely not operator-owned infrastructure, but end-user devices recruited via proxyware SDKs, bundled apps (or malware ?).

Using Synthient lookup API10, we would then classify the observed IPs by type and identifying the proxy provider.

As we expected, most of the IPs are residentials which makes perfect sense for a service that also operates a residential proxy network:

Figure 24: IP’s classification

Finally, we could also identify IPs classified as belonging to the IPIDEA pool (initial hypothesis) as well as those from other providers, notably BottingTool.

Figure 25: Most observed proxy providers

From a detection perspective, it’s worst mentioning some weird user-agents behaviors observed:

ObservationUser-Agent sample
Legacy EdgeHTML token on modern Chromium11Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36 Edge/12.246
Malformed two-part Chrome version12Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36
Non-zeroed build number on Chrome >= 110Chrome/122.0.6261.95 | Chrome/125.0.6422.60 | Chrome/116.0.5845.97 (SE 2.X MetaSr 1.0)
Non-zeroed build number in Edge tokenEdg/109.0.1518.140 | Edg/111.0.1661.44 | Edg/100.0.1185.36
Frozen ChromeOS platform version across 10+ chrome milestonesMozilla/5.0 (X11; CrOS x86_64 14541.0.0) ... Chrome/114, 126, 133, 134, 135, 136, 137, 138, 139, 140

‍

Conclusion

Unsurprisingly, our investigation identified strong correlations between scraping services, residential proxy networks, and data resale (specifically, data scraped using those proxy networks).

As the global race to train LLMs, which demands ever-increasing volumes of data, questions arise regarding the level of protection platforms offer against increasingly aggressive scraping actors. Detection can no longer rely solely on IP-based methods; instead, it must focus on behavioral analysis and client-side fingerprinting to distinguish genuine users from automated or potentially compromised clients. Furthermore, we remain highly skeptical of the "ethical" angle promoted by certain residential proxy providers. Indeed, infrastructure overlaps observed by many in the industry (Lumen, BitSight, Google...) suggest a close link between botnet networks and proxy providers, indicating that they all share, to varying degrees, the same IP pools.

‍

Figure 26: https://www.lumen.com/blog/en-us/symbiotic-parasites-the-modern-proxy-ecosystem

‍

The underlying risk exists at several levels:

  1. It has now been proven that there is a very strong correlation between residential proxy networks and a set of malware strains deployed specifically to achieve this goal and build a botnet. For instance, BitSight found a 15–26% overlap between the IP addresses of certain providers and malware such as Vo1d, Badbox, or RootSTV/Pandoraspear

‍

Figure 27: https://www.bitsight.com/blog/residential-proxy-services-malware-ecosystems

‍

  1. These residential proxy networks are not used solely for bypassing censorship in certain countries (Iran, Russia, or China) or for data scraping. Naturally, they are also constantly employed in various attacks and are particularly notable for their role in DDoS attacks. Notably, the Aisuru botnet was behind a series of record-smashing DDoS attacks in 202513.

  1. The central risk in any investigations resting on IP evidence is that a residential proxy inverts the meaning of the address: the IP you observe belongs to a victim, not a threat actor. In the 911 Socks5 case1415, the FBI describes how customers could commit cyberattacks, bomb threats, fraud, child exploitation, harassment, and export violations, knowing that the digital footprint would point back to the IP address of one of the botnet's victims. The scale makes clear this is not an edge case: over 19 million compromised IP addresses across more than 190 countries, including 613k in the United States alone. In our dataset for example, the problem compounds further: the Starlink addresses sit behind a carrier NAT, where a single public IP is shared among many subscribers while any one subscriber cycles through many IPs. So even a correct, timestamped ISP lookup cannot isolate a specific device.

The security recommendations regarding this issue are obvious:  

  • be wary of free apps and limit the number of applications installed on your devices (especially on Android, whether on mobile or smart TVs)
  • If a product is free or very cheap (hi there AliExpress), it likely comes with a little gift designed to monetize traffic at the users' expense. Read the terms of service carefully (or use AI to help spot the clause explaining that your internet connection might be used as a relay point)
  • Ensure your devices are up-to-date and do not expose your connected devices to the internet

Finally, I felt it was important to mention Pierluigi Vinciguerra’s blog on scraping.club16, which addresses the ethics surrounding proxy providers and the persistent issues associated with residential and mobile proxies. Regarding the FBI’s takedown of NetNut, he notably stated:  

"How do you source your IPs, and can you prove consent? [...] What happens, both in contracts and technically, when abuse is found? If your provider can’t answer these questions, someone else will, maybe with a seizure banner."

References

‍

Footnotes

1. https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network

2. https://en.wikipedia.org/wiki/Search_engine_results_page

3. https://www.ltddir.com/companies/apex-dataworks-limited/

4. https://www.ltddir.com/companies/vertex-apex-limited/

5. https://apify.com/kael_odin

6. https://www.thordata.com/blog/residential-proxies/residential-ip-address

7. https://www.thordata.com/blog/residential-proxies/thordata-residential-proxy-the-ultimate-guide-to-ai-powered-data-collection-and-web-scraping-success

8. https://synthient.com/blog/popa-from-sourcing-to-distribution

9. https://electroiq.com/stats/starlink-statistics/

10. https://synthient.com/context/ip/{IP}

11. https://learn.microsoft.com/uk-ua/previous-versions/windows/desktop/legacy/dn904497(v=vs.85)

12. https://www.chromium.org/updates/ua-reduction/

13. https://krebsonsecurity.com/2025/10/aisuru-botnet-shifts-from-ddos-to-residential-proxies/

14. https://www.fbi.gov/news/podcasts/inside-the-fbi-podcast-the-911-s5-cyber-threat

15. https://www.ic3.gov/PSA/2024/PSA240529

16. https://www.scraping.club/p/when-the-fbi-knocks-on-your-proxy

Partager l'article :

Your OWN cyber expert.