TI-2026-062D โ€” The Map: What the Proxy Recruiters Add Up To

Classification: MEDIUMโ€“HIGH ยท Forensic threat intelligence ยท Synthesis ยท Published 2026-07-07 ยท Series: The Proxy Recruiters

Three parts into this series, the pieces are on the table: a DNS-canary toolkit (062A), a three-method census of 50,348 forward probes (062B), and a residential exit-node cluster (062C). This closing part does not add a new actor. It draws the map โ€” how the methods, the operators, and the two market layers fit together โ€” and, more importantly, it sets that map against what the wider shuffle-on corpus already knows. The 062 series' contribution is not the discovery that proxy verification happens; a dozen prior dossiers established that. It is the taxonomy of how it happens, and the demonstration that one honeypot renders the whole economy legible from supply to distribution.

1. What This Series Established

PartContributionConfidence
062AThe go_scanner DNS-canary toolkit (a.toโ†’1.1.1.1), one build across two bulletproof operators (ISAEV AS200730, ZornTech AS154383)MEDโ€“HIGH
062BThe whole 50,348-forward corpus partitions into three validation methods, each bound 1:1 to a toolkit by its destinationMEDโ€“HIGH
062CThe ip-who.com mirror method belongs to a 151-IP residential Viettel cluster โ€” the exit-node layerMEDIUM

The through-line is the finding of 062B: the forward destination is the signature. A DNS resolver, a big website, or an IP-echo service โ€” the choice tells you the toolkit and the market in a single field, before any payload is read.

2. The Two-Axis Map

Everything in the series sits on two axes: who runs it (datacenter vs residential) and how it validates (DNS / HTTP / mirror).

DNS-canaryProvider-fetchMirror
Datacenter (sellers / catalog validators)go_scanner โ€” ISAEV, ZornTech (062A)libssh2 / paramiko โ€” Private Layer, w1n (062B, and TI-2026-001/038)โ€”
Residential (workers / exit nodes)โ€”โ€”AsyncSSH โ€” Viettel cluster (062C)

The datacenter operators sit in the top row: they own address space, so they never ask "what IP am I?" โ€” they ask "does my catalogued proxy still relay?" (DNS or HTTP). The residential cluster sits alone in the bottom-right: it does not own its address, so its only question is "what exit IP do I present?" (the mirror). The empty cells are not gaps in the data; they are structural โ€” a residential line has no catalogue to validate, and a datacenter has no exit-IP mystery to resolve.

3. Where This Fits in the Corpus

This is the part the interconnected data makes possible. The 062 series did not discover the proxy-verification market โ€” it inherited a well-documented one and added the missing method layer. The corpus already holds:

Read against that, the 062 series' place is precise: prior work answered who verifies proxies and that it is an industry; 062 answers how โ€” the destination-keyed method taxonomy that lets any forward event be classified by market from a single log field. That is the value of a knowledge base that connects: a new investigation does not restate the market, it slots a new layer onto it.

4. The Same Economy, a Different Sensor

The honeypot watches SSH. But open-proxy recruitment is protocol-agnostic, and the web sensor sees its HTTP face. In the web_threats corpus, the clearest example is 91.103.251.94 (AS201884, ISP SUPPORT LLC, Armenia): 2,084 hits using the HTTP CONNECT method, classified proxy_abuse, and โ€” notably โ€” not present in the honeypot at all. Where the SSH recruiters ask our server to open a direct-tcpip channel, this actor asks it to open a CONNECT tunnel: the identical request ("relay my traffic onward") expressed in the other protocol's grammar.

The lesson is not that these are the same operator โ€” they are not linked. It is that the behaviour is one behaviour, observable wherever a relay might exist. A honeypot that logs SSH direct-tcpip and a web proxy that logs HTTP CONNECT are two windows onto the same economy: someone testing whether your machine will carry traffic it should not.

5. Alternative Interpretation

Steelman: "A synthesis is where analysts over-reach. Co-occurrence on one honeypot is not a network. Drawing a two-axis 'market map' from four unrelated operators plus a residential cluster plus one Armenian web IP risks manufacturing structure that isn't there โ€” the map is a narrative imposed on noise."

Why the map holds:

What is not claimed: that the Armenian CONNECT abuser, the Viettel residential cluster, and the bulletproof validators are operationally connected. They are instances of a common behaviour on a common market, seen from a common sensor โ€” not nodes of one network.

Confidence: MEDIUMโ€“HIGH โ€” HIGH that the two-axis map faithfully organises the series' facts and the corpus' prior findings; MEDIUM that the cross-protocol (SSHโ†”HTTP) and cross-layer (sellerโ†”worker) framing reflects one integrated economy rather than parallel independent ones.

6. Defense โ€” The Consolidated Picture

Everything in this series collapses to a small, durable control set:

7. Investigation Metadata

FieldValue
Dossier IDTI-2026-062D
SeriesThe Proxy Recruiters (synthesis / capstone)
Date2026-07-07
SynthesisesTI-2026-062A (DNS-canary), 062B (method taxonomy), 062C (residential mirror)
Positioned againstTI-2026-021M, 038A/B, 039C, 024D, 001, 007, 019I (the documented proxy market)
Cross-layer datum91.103.251.94 (AS201884, Armenia) โ€” HTTP CONNECT proxy_abuse, 2,084 hits, absent from honeypot
SourcesLSN Cowrie honeypot; web_threats platform; dossier entity graph + Qdrant corpus; AbuseIPDB; Team Cymru
ConfidenceMEDIUMโ€“HIGH

Cristian Liศ™neanu ยท shuffle-on.com ยท Threat Intelligence

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Proxy Recruiters โ€” 4 / 4 Next โ†’