Follow the Payload ยท 2 โ€” The Proxy: Bandwidth and a Clean Address

Follow the Payload โ€” Case 2. This register takes what an intruder leaves behind and reads it for the one thing it cannot hide: its purpose. Closing each case on the objective the payload serves: STEAL COMPUTE ยท STEAL BANDWIDTH ยท RECRUIT ยท STEAL DATA ยท EXTORT ยท PERSIST.

The miner stole the host's compute and kept its harm at home โ€” the CPU, the electricity, the wear, all the host's own, all consumed in place. This case is the first departure from that clean containment. The proxy payload steals a resource the miner never touched and could not have named: not the host's processor but its place in the network โ€” its bandwidth, and far more valuably, the trust attached to its address. A proxyware payload turns the compromised host into an exit node, a relay through which other people's traffic flows out to the internet wearing the host's identity, so that whatever the traffic does, it appears to have come from here. The objective is STEAL BANDWIDTH, but that name undersells it. What the proxy really takes is a clean address to hide behind, and in taking it, it does something the miner never did: it turns the host's harm outward, against victims who are not the host at all.

This is where the register's map gets its first fold. The miner was a closed loop โ€” one payload, one host, one victim, the harm beginning and ending on the infected machine. The proxy opens the loop. The host becomes infrastructure, a piece of laundering equipment, and the real damage is done wherever the proxied traffic lands: the login page hammered with stolen credentials, the advertiser billed for fake clicks, the account created by the thousand, the site scraped dry, all of it exiting through a residential address that belongs to someone who never agreed to any of it. Reading this payload's intent, therefore, means reading past the host โ€” the machine in hand is not the endpoint of the purpose but the instrument of it, and the purpose is consummated somewhere the honeypot can only infer. The proxy is the register's first lesson that a payload's objective can point away from the host it runs on.

1. The Host's Place in the Network

Begin with what is actually stolen, because it is not what the name suggests. "Bandwidth" implies the theft is of throughput โ€” the host's data allowance, its network capacity โ€” and that theft is real, but it is the cheap part. The valuable part is the host's position: the fact that its traffic, when it reaches a service on the internet, is treated as coming from a particular kind of place. A proxyware payload โ€” a residential-proxy SDK, a SOCKS or HTTP relay, a bandwidth-monetization agent โ€” installs the host as an exit node in a proxy network, and from that moment the host's job is to receive traffic from the operator's customers and forward it out to its destinations, so that the destination sees the host's address as the origin. The host becomes a mask that other traffic wears.

And the mask's value is entirely a function of where the host sits. The internet does not treat all addresses equally. Traffic arriving from a datacenter IP is presumed to be automated โ€” bots, scrapers, tools โ€” and is flagged, throttled, challenged, or blocked accordingly, because legitimate humans do not usually browse from a server farm. Traffic arriving from a residential ISP address is presumed to be a real person at home, and is trusted, because that is where real users actually are. A compromised residential or small-business host therefore occupies a position the operator's own servers can never occupy: a place the internet trusts. That position is the resource. The proxy payload does not primarily want the host's bandwidth; it wants the host's residential-ness, the reputational fact of its address, which it can rent out to make untrusted traffic look trusted.

This is why a modest home router, a small-office NAS, an IoT device on a residential line can be worth more as a proxy than a far more powerful datacenter machine. Compute scales with hardware; position scales with trust, and trust is exactly what the residential address has and the datacenter lacks. The register notes this inversion because it reframes what "a valuable host" means. To the miner, value was cycles, and the beefiest machine was the best target. To the proxy, value is reputation, and the humblest residential device โ€” precisely because it is where a real person lives โ€” is the prize. The payload reads the host not as a processor but as an address, and it steals the address's standing.

2. Laundering: The Clean Place to Come From

Follow what the stolen position is for, because it explains the whole objective. Everything an operator wants to do at scale against internet services โ€” stuff stolen credentials into login forms, click ads for fraudulent revenue, create accounts by the thousand, scrape data past rate limits, evade a geographic or sanctions block โ€” runs into the same wall: the services defend themselves by distrusting where the traffic comes from. Too many requests from one address, or any request from a flagged address, and the service blocks it. The operator's own infrastructure is flagged the moment it is used, because a datacenter sending login attempts to a thousand accounts is obviously an attack. He needs somewhere clean to come from, and somewhere new each time, and residential proxies are exactly that: a rotating supply of trusted addresses, each a real compromised home, through which his traffic can exit looking like a thousand different ordinary users.

This is laundering, in the precise sense. The operator's traffic is "dirty" โ€” recognizable as abuse by its origin โ€” and passing it through a residential proxy makes it "clean," indistinguishable at the point of arrival from a genuine resident browsing the web. The compromised host is the laundering machine, and its clean address is the detergent. The credential-stuffing attack that would be blocked instantly from a datacenter succeeds when it trickles in from ten thousand residential IPs, each carrying a few attempts, each trusted, none individually suspicious. The ad fraud that would be obvious from a server farm looks like real engagement when it comes from real homes. The proxy payload's objective is to supply that clean origin โ€” to convert a compromised host into an alibi for someone else's abuse.

And this is the theft that matters, because it is the theft of something the operator cannot buy cleanly. He can rent all the datacenter compute he wants, legally and cheaply, but he cannot rent a genuinely trusted residential identity, because trust is precisely the thing that is withheld from anyone who would pay for it in bulk. The only way to obtain a large supply of trusted residential origins is to take them โ€” to compromise real homes and enroll them as proxies without their owners' knowledge โ€” which is why the residential-proxy underworld exists and why compromised hosts flow into it. The proxy payload steals the one asset that has no legitimate wholesale market: a trusted place to come from. STEAL BANDWIDTH names the mechanism; the objective is really the theft of an address's reputation, laundered into cover for abuse committed elsewhere.

3. The Victim Splits

STEAL BANDWIDTH is the register's first split-victim objective, and the split changes how intent must be read. For the miner, the victim and the host were the same thing: the machine's compute was stolen and consumed in place, and to read the intent you looked no further than the host. For the proxy, the host is not the victim in the usual sense โ€” it is the infrastructure, the equipment through which harm is delivered to others. The real victims are downstream: the services whose logins are stuffed, the advertisers whose budgets are drained, the platforms flooded with fake accounts, the sites scraped, the targets attacked โ€” all of them harmed by traffic that exited through the host's stolen address. The payload's purpose is not done on the host; it is done on whoever the host's position was stolen to reach.

The host is not unharmed โ€” it suffers a distinct and serious injury โ€” but its injury is of a different kind. Its bandwidth is consumed; its address is eventually blacklisted as the abuse it relayed gets noticed and attributed to its IP; its owner may find himself implicated in fraud or attacks he had no part in, his home address appearing in the logs of victims he never heard of. This is real damage, and section 5 returns to it. But it is conduit damage โ€” the injury of being made into an instrument โ€” not the consummation of the payload's purpose. The purpose is consummated on the downstream targets, and the host's harm is a byproduct of its use as the delivery mechanism.

This forces a new reading discipline the miner never required: to read the proxy's intent fully, you must reason past the host. The honeypot sees the relay, the control channel, the transiting flows โ€” it sees the host being used as an exit โ€” but the objective those flows serve is enacted elsewhere, on victims the honeypot cannot see, and naming the intent means naming that downstream purpose (laundering abuse) even though its target is off-screen. This is the first time in the register that reading a payload requires looking beyond the machine the payload sits on. The miner's intent was wholly present on the host; the proxy's intent points off the host, and the register must learn to follow the pointer to victims it can infer but not observe. Every split-victim objective to come โ€” the DDoS cannon, the propagator โ€” will demand the same outward reading, and the proxy is where the register learns it.

4. Reading the Objective, and the First Dual-Use Snag

The proxy objective reads at HIGH when the payload is identified and executed, and its execution leaves distinctive tells. A relaying host opens a listener โ€” a SOCKS or HTTP proxy port, or an outbound tunnel to a proxy-control server โ€” that has no business on a normal residential machine. It maintains a persistent control connection to a proxy-network backend that assigns it traffic and manages its enrollment. And, most tellingly, it carries third-party traffic: flows that arrive at the host and depart to destinations the host's owner has no relationship with, an inbound-then-outbound pattern that is the signature of relaying rather than originating. Seen together โ€” the unexplained listener, the control channel to a proxy backend, the transiting flows โ€” these confirm both the function (this host is an exit node) and its execution (it is relaying now), meeting the unambiguous-and-executed standard the register requires for a HIGH intent reading.

But here the register hits a complication the miner spared it, and it is worth flagging precisely because it is the first of its kind: proxyware is dual-use. Unlike a cryptominer, which has no legitimate reason to be quietly enrolling a stranger's machine, residential-proxy software exists as a semi-legitimate consumer product. Several companies operate above-board businesses paying users a few pennies a month to install an agent that shares their home bandwidth as a residential proxy; that agent is a legal commercial SDK, and running it consensually is a lawful, if grubby, way to monetize spare bandwidth. So the same binary โ€” quite possibly byte-for-byte identical โ€” is a benign consumer app when a user chose to install it and a theft when an intruder dropped it on a machine whose owner never agreed. The binary alone cannot tell you which.

This means intent, here, is not fully in the payload โ€” a departure from the miner, where the binary settled everything. The proxy's intent lives in the consent and the context: did the host's owner agree to share his bandwidth, or was the agent installed without his knowledge by someone who compromised his machine? On a honeypot, or any provably compromised host, the context settles it cleanly โ€” no owner consented to an intruder's installation, so the objective reads unambiguously as theft. But the register flags the general lesson: for a dual-use payload, reading intent from the binary alone fails, and you must read the surrounding facts โ€” how it got there, whether the owner consented, what context it runs in. This is the first appearance of a problem the register will devote a full later case to, and the proxy is where it announces itself. The author, meanwhile, stays LOW as always: proxyware is commodity, dropped by many unrelated intruders who monetize hosts by enrolling them into proxy networks they own or resell to, so a shared agent implies a shared objective and maybe a shared network, but not a shared hand.

5. The Quiet Payload and the Burned Address

For the defender, the proxy is the miner's opposite in temperament, and the contrast is instructive. The miner is loud because its objective demands it โ€” maximum hashrate means maximum CPU, the noisiest thing a process can do. The proxy is quiet because its objective demands the opposite: a proxy wants the host healthy, unnoticed, and long-lived, because every day the host keeps relaying is another day of revenue, and any behavior that gets the host noticed and cleaned kills the asset. So the proxy consumes bandwidth modestly, hides in normal-looking traffic, avoids pinning any resource, and generally tries to be the best-behaved process on the machine. This makes it harder to find than a miner and more persistent once established โ€” the proxy's whole survival strategy is to not be worth noticing.

Because it hides in the traffic rather than the CPU, the proxy is detected at the network layer, not the host's performance graphs: the unexpected listener, the transiting flows, the persistent connection to a known proxy-network backend are the tells, and a defender watching only for resource abuse will miss it entirely. And its harm has a blast radius the miner's never had. When the proxied abuse is eventually noticed by its downstream victims, it is the host's address that gets blacklisted, reported, and blamed โ€” so the compromised host's owner inherits a reputation for credential-stuffing or fraud he never committed, his residential IP burned across the many services that logged its abuse, an address often shared with an entire household or business now flagged for everyone behind it. Cleaning the proxy payload does not undo this; the reputational damage is already delivered to third parties who will keep blocking the address. So the proxy's remediation is twofold: remove the agent, yes, but also recognize that the host's address was used as a weapon and its standing must be actively repaired.

And this sharpens a fairness point the register holds firmly: the host's owner is a victim, not a culprit. The credential-stuffing, the fraud, the attacks that exited through his address were not his acts โ€” they were laundered through his machine precisely so that they would wear his identity instead of the operator's. To read the downstream abuse as the host owner's doing would be to blame the laundered for the laundering, to convict the alibi. The register names the objective โ€” bandwidth and reputation theft โ€” and records the host as the conduit it was made into, explicitly not as the author of the traffic it was forced to carry. The vectors do not lie: the flows transited this host, the relay ran here, the objective was to launder abuse through a stolen address. But the abuse belongs to the operator who stole the address, not to the owner whose address was stolen. We name the objective, we mark the host as victim-conduit, we decline the commodity author, and we do not blame the home whose door was used. We read the payload, we name the purpose it executes, and we let people judge.

6. The counter-narrative, steelmanned

The strongest objection to this case is that its two central features โ€” proxyware is dual-use and the proxy is quiet โ€” combine to make STEAL BANDWIDTH an over-reading: a relay agent found on a host might simply be the owner's own consensual bandwidth-sharing, a legal product he installed for pocket money, and calling it "theft" reads malice into what may be a lawful, if unglamorous, consumer choice. Since the binary is identical either way and the behavior is quiet either way, the objection says, the register cannot actually distinguish the stolen relay from the consensual one, and so its confident HIGH reading of theft is unearned โ€” it may be convicting a legitimate agent of a crime that only exists in the analyst's assumption of compromise.

The objection is genuinely sharp, and the register conceded its premise in advance: the binary alone cannot distinguish consensual proxyware from stolen proxyware, because they are the same binary. If the register's reading of theft rested on the binary, the objection would be fatal. And the concern is not academic โ€” real users do install these agents, real machines do run consensual residential proxies, and an analyst who saw a relay and cried "compromise" every time would indeed convict legitimate installs. The dual-use nature of proxyware is precisely the kind of thing that produces false positives when intent is read carelessly from an artifact, and the objection is right that quietness removes the behavioral tell (the resource abuse) that might otherwise separate the two cases. On the artifact and the behavior alone, consensual and stolen proxyware are genuinely indistinguishable.

The register answers that it never reads this intent from the binary alone โ€” it reads it from consent-plus-context, and context is exactly what a compromised host settles. The whole point of section 4's dual-use flag is that for a dual-use payload the binary is not the evidence of intent; the circumstances of its arrival are. And on a honeypot โ€” or any host where compromise is independently established โ€” those circumstances are not ambiguous: the agent was installed by an intruder who broke in, not by an owner who opted in, and an installation the owner did not consent to is, definitionally, non-consensual, whatever the binary's legal status in other hands. The register does not say "a relay agent exists, therefore theft"; it says "a relay agent was installed by an intruder on a compromised host, therefore theft," and the second premise โ€” the compromise โ€” is established independently of the agent, by the intrusion that dropped it. Where compromise is not established, the register would correctly decline to read theft, because then the consent is genuinely unknown; the HIGH reading is licensed only when the context settles the consent, and the context is a separate fact from the binary. So the objection correctly identifies that the artifact is silent on consent and incorrectly assumes the register relies on the artifact; the register relies on the compromise, which speaks. And there is a second answer that holds even if one somehow doubted the consent: the split-victim harm is real regardless of the agent's legality โ€” laundered credential-stuffing and fraud exit the host and land on downstream victims whether the relay was installed with consent or without it, so the objective STEAL BANDWIDTH describes a real theft-and-laundering happening through the host, and the only thing consent changes is whether the host's owner is also a victim (non-consensual) or a paid participant (consensual). Either way the downstream victims are harmed and the objective is enacted; consent relocates the host owner's status, not the reality of the laundering. The register reads the objective from the context that settles consent, declines the reading where context is absent, and notes that the downstream harm stands on its own โ€” which is exactly the calibrated, context-dependent reading the dual-use nature demands, not the careless artifact-reading the objection feared.

7. Objective Signal โ€” STEAL BANDWIDTH

Case 2 read the register's second objective and its first departure from the miner's clean containment. Where the miner stole the host's COMPUTE and consummated its harm in place, the proxy payload steals the host's NETWORK POSITION โ€” a resource the miner never touched. A proxyware payload (a residential-proxy SDK, a SOCKS/HTTP relay, a bandwidth-monetization agent) turns the compromised host into an EXIT NODE through which other people's traffic flows out wearing the host's address. Bandwidth is the cheap part; the real prize is a CLEAN RESIDENTIAL IP โ€” because the internet trusts residential addresses and distrusts datacenters, routing malicious or fraudulent traffic (credential-stuffing, ad fraud, scraping, mass account creation, sanctions evasion) through a compromised home LAUNDERS it, converting dirty traffic into traffic indistinguishable from a real resident's. The payload steals the one asset the operator cannot buy cleanly: a trusted place to come from.

The objective is STEAL BANDWIDTH, and it is the register's first SPLIT-VICTIM objective. The host is INFRASTRUCTURE โ€” a laundering machine โ€” and the real victims are downstream: the services stuffed, advertisers defrauded, sites scraped, platforms flooded, parties attacked through the host's stolen address. The host suffers conduit-damage (bandwidth consumed, address blacklisted, owner implicated in traffic he never sent), but the purpose is consummated on the downstream targets, so reading the intent requires reasoning PAST the host to victims the honeypot can infer but not observe โ€” a new outward-reading discipline every later split-victim objective will demand. The objective reads at HIGH when the relay is identified and executed (an unexplained listener, a persistent proxy-control channel, third-party traffic transiting the host). But it is the register's FIRST DUAL-USE complication: proxyware exists as a semi-legitimate consumer product (users paid pennies to share bandwidth), so the SAME agent is benign under consent and theft when dropped by an intruder โ€” intent is NOT in the binary alone but in the CONSENT and CONTEXT, which a compromised host settles. The author stays LOW (commodity, often rented into a proxy-network-as-a-service).

Defensively the proxy is the miner's opposite: QUIET (it wants the host healthy, unnoticed, and long-lived, because every relaying day is revenue), hence harder to detect โ€” found at the NETWORK layer, not the CPU โ€” and more persistent; and its harm has a reputational BLAST RADIUS (the host's IP burned across the services that logged its abuse, its owner implicated in fraud, a shared address flagged for everyone behind it), so remediation must repair the address, not just remove the agent. The host's owner is a VICTIM of the theft, not a party to the downstream fraud his address was forced to carry. The steelmanned objection โ€” that dual-use plus quietness makes STEAL BANDWIDTH an over-reading, since a relay might be the owner's consensual bandwidth-sharing โ€” is answered by the register reading intent from consent-plus-context (a compromised host settles the consent, which the binary cannot), declining the reading where compromise is not established, and by the split-victim harm being real regardless of the agent's legality (consent relocates the host owner's status, not the laundering itself). No individual named โ€” the host's owner named as victim, the downstream actor left unnamed. Classification: TLP:WHITE. We read the payload, we name the purpose it executes, and we let people judge.

Follow the Payload โ€” Case 2. Objective signal: STEAL BANDWIDTH. Confidence: HIGH for the objective when executed (a listening proxy port, a persistent proxy-control channel, and third-party traffic transiting the host โ€” the unambiguous-and-executed signature of relaying, not originating); LOW for the author (proxyware is COMMODITY and often rented into a proxy-network-as-a-service, so a shared agent implies a shared objective/network, not a shared hand). The proxy steals the host's NETWORK POSITION โ€” bandwidth and, chiefly, its clean RESIDENTIAL IP reputation โ€” to LAUNDER malicious/fraudulent traffic (credential-stuffing, ad fraud, scraping, account creation, sanctions evasion) by making it appear to originate from a trusted residential address; it steals the one asset the operator cannot buy cleanly, a trusted place to come from. FIRST SPLIT-VICTIM objective: the host is a CONDUIT (bandwidth consumed, IP blacklisted, owner implicated), the real victims are DOWNSTREAM (the parties the proxied traffic hits), so reading intent requires reasoning PAST the host โ€” a new outward-reading discipline. FIRST DUAL-USE complication: proxyware is a semi-legitimate consumer product, so the SAME agent is benign under consent and theft under compromise โ€” intent is in CONSENT + CONTEXT, not the binary alone (a compromised host settles it). Defensively the proxy is QUIET (wants the host healthy) โ€” detected at the NETWORK layer, persistent, with a reputational BLAST RADIUS; the host's owner is a VICTIM, not a culprit. Steelmanned objection (dual-use + quiet = over-reading; the relay might be consensual) answered by reading consent-plus-context (compromise settles consent; decline where compromise is unestablished) and by the downstream laundering harm being real regardless of the agent's legality (consent relocates the owner's status, not the theft). No individual named. Classification: TLP:WHITE. Include everything โ€” the relay ran, the flows transited, the objective was to launder abuse through a stolen address; we name the objective, mark the host as victim-conduit, and decline the commodity author.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Follow the Payload โ€” 2 / 26 Next โ†’