TI-2026-062D โ The Map: What the Proxy Recruiters Add Up To
Classification: MEDIUMโHIGH ยท Forensic threat intelligence ยท Synthesis ยท Published 2026-07-07 ยท Series: The Proxy Recruiters
Three parts into this series, the pieces are on the table: a DNS-canary toolkit (062A), a three-method census of 50,348 forward probes (062B), and a residential exit-node cluster (062C). This closing part does not add a new actor. It draws the map โ how the methods, the operators, and the two market layers fit together โ and, more importantly, it sets that map against what the wider shuffle-on corpus already knows. The 062 series' contribution is not the discovery that proxy verification happens; a dozen prior dossiers established that. It is the taxonomy of how it happens, and the demonstration that one honeypot renders the whole economy legible from supply to distribution.
1. What This Series Established
| Part | Contribution | Confidence |
|---|---|---|
| 062A | The go_scanner DNS-canary toolkit (a.toโ1.1.1.1), one build across two bulletproof operators (ISAEV AS200730, ZornTech AS154383) | MEDโHIGH |
| 062B | The whole 50,348-forward corpus partitions into three validation methods, each bound 1:1 to a toolkit by its destination | MEDโHIGH |
| 062C | The ip-who.com mirror method belongs to a 151-IP residential Viettel cluster โ the exit-node layer | MEDIUM |
The through-line is the finding of 062B: the forward destination is the signature. A DNS resolver, a big website, or an IP-echo service โ the choice tells you the toolkit and the market in a single field, before any payload is read.
2. The Two-Axis Map
Everything in the series sits on two axes: who runs it (datacenter vs residential) and how it validates (DNS / HTTP / mirror).
| DNS-canary | Provider-fetch | Mirror | |
|---|---|---|---|
| Datacenter (sellers / catalog validators) | go_scanner โ ISAEV, ZornTech (062A) | libssh2 / paramiko โ Private Layer, w1n (062B, and TI-2026-001/038) | โ |
| Residential (workers / exit nodes) | โ | โ | AsyncSSH โ Viettel cluster (062C) |
The datacenter operators sit in the top row: they own address space, so they never ask "what IP am I?" โ they ask "does my catalogued proxy still relay?" (DNS or HTTP). The residential cluster sits alone in the bottom-right: it does not own its address, so its only question is "what exit IP do I present?" (the mirror). The empty cells are not gaps in the data; they are structural โ a residential line has no catalogue to validate, and a datacenter has no exit-IP mystery to resolve.
3. Where This Fits in the Corpus
This is the part the interconnected data makes possible. The 062 series did not discover the proxy-verification market โ it inherited a well-documented one and added the missing method layer. The corpus already holds:
- TI-2026-021M "The Phantom Pipes" โ "proxy verification is a market function, not a side effect," and the first identification of the AsyncSSH/
ip-who.comresidential pattern. - TI-2026-038A "The Proxy Verifier" โ Private Layer's proxy verification as an industrial operation (86,239 events, keepalive + monthly bulk sweeps).
- TI-2026-038B "The Permanent Residents" โ the Yahoo-vs-Yandex market split (Western vs CIS).
- TI-2026-039C "The Proxy Economy" โ the same Viettel AS7552 / AsyncSSH
fda360b1/ip-who.comresidential pattern, framed as legal-and-criminal shared infrastructure. - TI-2026-024D "The w1n Network", TI-2026-001, TI-2026-007, TI-2026-019I โ w1n and Private Layer as bulletproof operators, the underground pricing, the multi-pronged methodology.
Read against that, the 062 series' place is precise: prior work answered who verifies proxies and that it is an industry; 062 answers how โ the destination-keyed method taxonomy that lets any forward event be classified by market from a single log field. That is the value of a knowledge base that connects: a new investigation does not restate the market, it slots a new layer onto it.
4. The Same Economy, a Different Sensor
The honeypot watches SSH. But open-proxy recruitment is protocol-agnostic, and the web sensor sees its HTTP face. In the web_threats corpus, the clearest example is 91.103.251.94 (AS201884, ISP SUPPORT LLC, Armenia): 2,084 hits using the HTTP CONNECT method, classified proxy_abuse, and โ notably โ not present in the honeypot at all. Where the SSH recruiters ask our server to open a direct-tcpip channel, this actor asks it to open a CONNECT tunnel: the identical request ("relay my traffic onward") expressed in the other protocol's grammar.
The lesson is not that these are the same operator โ they are not linked. It is that the behaviour is one behaviour, observable wherever a relay might exist. A honeypot that logs SSH direct-tcpip and a web proxy that logs HTTP CONNECT are two windows onto the same economy: someone testing whether your machine will carry traffic it should not.
5. Alternative Interpretation
Steelman: "A synthesis is where analysts over-reach. Co-occurrence on one honeypot is not a network. Drawing a two-axis 'market map' from four unrelated operators plus a residential cluster plus one Armenian web IP risks manufacturing structure that isn't there โ the map is a narrative imposed on noise."
Why the map holds:
- It claims structure, not conspiracy. The map explicitly does not assert shared operators (062AโC each say so). It asserts a shared market structure โ supply, distribution, validation methods โ which is a claim about an industry, not a cabal.
- The structure is corroborated by independent investigations. The market reading is not this series' invention: 021M, 038A, and 039C reached it separately, from different actors and data. When multiple independent analyses converge on "proxy verification is an industry with residential supply and bulletproof distribution," the convergence is the evidence. The 062 series adds the method axis; it does not carry the market claim alone.
- The empty cells predict correctly. A fabricated map would fill every cell. This one is empty exactly where the economics say it must be (residential lines don't run catalogues; datacenters don't wonder about their exit IP) โ a sign the axes are real, not decorative.
What is not claimed: that the Armenian CONNECT abuser, the Viettel residential cluster, and the bulletproof validators are operationally connected. They are instances of a common behaviour on a common market, seen from a common sensor โ not nodes of one network.
Confidence: MEDIUMโHIGH โ HIGH that the two-axis map faithfully organises the series' facts and the corpus' prior findings; MEDIUM that the cross-protocol (SSHโHTTP) and cross-layer (sellerโworker) framing reflects one integrated economy rather than parallel independent ones.
6. Defense โ The Consolidated Picture
Everything in this series collapses to a small, durable control set:
- One server control ends all of it.
AllowTcpForwarding no(plusPermitTunnel no,GatewayPorts no) defeats every SSH method โ DNS-canary, provider-fetch, and mirror alike โ at the channel-open step. For the HTTP face, disable proxy/CONNECThandling on any server not meant to be a forward proxy. Neither the toolkit nor the destination matters once forwarding is off. - Detection is one field per protocol. SSH: log the
direct-tcpipdestination โ1.1.1.1:53/ big-provider:80/ip-who.comclassifies the recruiter by market with no payload inspection. HTTP: theCONNECTverb to an external host on a non-proxy service isproxy_abuseby definition. - Invert your trust in reputation for the residential layer. The exit-node cluster scores ~0 on AbuseIPDB because it is residential and rotating (062C). Weight the HASSH-cluster and forward-destination over per-IP reputation; a clean score on a residential ASN forwarding to
ip-who.comis the signal, not the all-clear. - Kill the credentials. Every actor in the series depends on
admin/adminor vendor-default logins (062A, 062C). On real hosts and especially embedded devices, non-default credentials remove the entire foothold before forwarding is ever attempted.
7. Investigation Metadata
| Field | Value |
|---|---|
| Dossier ID | TI-2026-062D |
| Series | The Proxy Recruiters (synthesis / capstone) |
| Date | 2026-07-07 |
| Synthesises | TI-2026-062A (DNS-canary), 062B (method taxonomy), 062C (residential mirror) |
| Positioned against | TI-2026-021M, 038A/B, 039C, 024D, 001, 007, 019I (the documented proxy market) |
| Cross-layer datum | 91.103.251.94 (AS201884, Armenia) โ HTTP CONNECT proxy_abuse, 2,084 hits, absent from honeypot |
| Sources | LSN Cowrie honeypot; web_threats platform; dossier entity graph + Qdrant corpus; AbuseIPDB; Team Cymru |
| Confidence | MEDIUMโHIGH |
Cristian Liศneanu ยท shuffle-on.com ยท Threat Intelligence