LIVE · cybersecurity feed
Live wire
fraudmedium

Cybercriminals Seek Clean Residential Proxies for Fraud

Fraudsters are finding that traditional residential proxies are becoming less effective for carding operations. To bypass advanced fraud detection systems, criminals are now combining these proxies with other identity information, such as browser fingerprints and device profiles.

zeroday.news · 15d ago

Cybercriminals engaged in carding, the illicit use of stolen payment card data, are increasingly seeking "clean" residential proxies to bypass advanced fraud detection systems. Analysis of 2,889 underground forum posts over the past two years reveals a shift in how these actors evaluate and utilize proxy infrastructure. Rather than viewing residential proxies as a standalone anonymity tool, carders now integrate them into a comprehensive identity-simulation stack that includes device fingerprints, browser profiles, billing information, time zones, cookies, and transaction behavior.

A key finding is that the term "residential" is no longer considered sufficient; carders now distinguish between "clean" and "dirty" proxy pools. This distinction arises from the understanding that even residential IP addresses can accumulate poor reputations if repeatedly used for fraudulent activities. An underground guide titled "Getting the Cleanest Possible IPs for Carding" emphasizes that an IP's history, particularly its prior use against banks or payment processors, is more critical than its residential status alone. Forum discussions indicate a belief that proxy reputation is dynamic and influenced by all users sharing the infrastructure.

The demand for precision in geographic consistency has also intensified. Older carding advice focused on matching an IP's country with the stolen card's origin. However, recent discussions highlight the need for a far narrower standard, extending to matching an IP's approximate location with the billing ZIP code, device time zone, operating-system language, and browser characteristics. Some users have expressed concern over major residential proxy providers removing ZIP code targeting, fearing that city-level targeting may no longer be precise enough to evade fraud controls. This reflects a strategic shift towards constructing a coherent digital identity rather than merely masking a real IP address.

Residential proxies are rarely considered sufficient on their own and are frequently paired with antidetect browsers and fingerprint manipulation techniques. Guides circulating in underground forums warn that even a perfect residential proxy will fail if the browser profile exposes contradictory information. The consensus among carders is that a successful fraudulent setup requires evaluating the device, proxy, account history, payment information, and target merchant holistically. This approach mirrors modern fraud detection systems, which combine multiple signals such as transaction history, identity data, and card information.

Furthermore, many established proxy providers restrict access to financial services, government portals, and other fraud-sensitive targets. This limitation has created a secondary market for services advertised as "finance-enabled" or "bank-compatible." Some carders speculate that restricted residential pools might contain cleaner IPs precisely because they haven't been overused against financial institutions. However, the reliability of these specialized proxy advertisements is often difficult to verify, and some may be scams.

The search for usable residential infrastructure occurs within a broader, increasingly contested proxy ecosystem. In July 2026, law enforcement agencies, including the FBI, collaborated with industry partners to seize hundreds of domains associated with the NetNut residential proxy platform and the Popa botnet. This network reportedly comprised at least two million compromised devices, including smart TVs and streaming boxes, which were converted into residential proxy nodes used for activities such as advertising fraud and account takeovers. An FBI alert in March 2026 also warned that criminals can select residential IPs based on specific criteria.

fraudcardingproxiescybercrime
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.