Back to blog

Threat Actor Tradecraft – The Residential Proxy Problem

Will Poole and Jordan Newman

Authors

Oct 6, 2026

Published

6 min

Read time

Strand has been used to investigate thousands of Business Email Compromise (BEC) incidents over the last 18 months. Almost all of these followed a similar pattern:

  • Victim user receives a phishing email and clicks a link or opens a malicious document (e.g., a PDF containing an external link).

  • Threat actor gains access to the victim’s mailbox using credentials or tokens (cookies) stolen via the link.

  • They search for invoices or other upcoming financial transactions and, if a worthy candidate is found, try to divert the payment to a bank account they control by sending “change in bank details” emails.

  • If they do not find a payment to divert, they resort to sending phishing emails out from the mailbox, in order to compromise other businesses where the cycle begins again.

Investigating these incidents often follows a simple workflow.

  • Identify the threat actor’s initial access to the mailbox through a review of sign-in logs, identifying where sign-ins occurred from anomalous IP addresses.

  • Review downstream activity, such as the sending or accessing of emails, that originate from anomalous IP addresses or sessions, using a combination of logs provided by Microsoft/Google (the most common email system providers).

  • Review emails received into the mailbox before the compromise in the hope of identifying the initial phishing email which caused the incident.

Strand automates much of this process for external incident response teams and internal security teams. However, a successful investigation relies on one key fact: can we differentiate the legitimate user’s IP address from those used by the threat actor?

How threat actors hide their identity

Threat actors use a variety of techniques to hide their own identity. Historically, this includes the use of VPNs, other proxy infrastructure, or so-called “throwaway” hosting infrastructure. The goal is always the same – ensure that logs never show or reveal the threat actor’s own location or IP by inserting an additional layer or device between the threat actor and the cloud tenant. A brief example of how this works via VPN usage is shown below:

Diagram comparing internet traffic without a VPN, where websites see your home IP address, and with a VPN, where traffic travels through an encrypted tunnel to a VPN server and websites see the VPN server's IP address instead.
How a VPN changes what your internet provider and the websites you visit can see.

For investigators and incident responders, this can often make differentiating the threat actor’s IP from the legitimate user’s IP address straightforward. If you saw:

  • Login at 10:00 from a BT Home IP address

  • Login at 10:34 from a BT Home IP address

  • 3 emails sent at 11:01 from a BT Home IP address

  • Login at 11:30 from a NordVPN owned IP address

  • 100 emails sent at 14:00 from a NordVPN owned IP address

  • 3000 emails downloaded from an IP address associated with a foreign hosting provider

It should be clear which of those are suspicious and require further investigation, and when the incident likely began.

Proxy services – predominantly VPNs – which allow threat actors to hide their identity have grown significantly in popularity across all factions of the internet in recent years. Lower costs for internet infrastructure, increased awareness of online privacy, and the desire to bypass region-based restrictions/censorship have all contributed to their widespread adoption. There are many legitimate reasons for VPNs to exist and be used, privacy being the most common, but there is no doubting they are also the favourite tool of malicious entities conducting cyberattacks.

This shift has made internet service and infrastructure providers far more adept at identifying traffic originating from these services. Many now actively detect, challenge, or block connections originating from known proxy and VPN infrastructure, creating an arms race between those looking for anonymity and the services attempting to identify or track them.

In the background, regulatory bodies in various regions have also been applying increased pressure on VPN and proxy providers. The regulations aim to place higher accountability on the providers through strengthened record keeping and better cooperation with law enforcement.

In short, traditional proxies and VPN services are becoming increasingly risky for threat actors, are increasingly easy to detect and block by incident responders and security controls alike, and offer diminishing anonymity for criminals looking to mask their identity.

Enter, the residential proxy

Residential proxies route internet traffic through IP addresses belonging to consumer ISPs, rather than through conventional datacentres or hosting providers. To the destination service, the traffic appears to originate from a normal household or small-business connection.

Residential proxy networks can be built from legitimately enrolled devices, compromised systems, or IoT devices that have been incorporated into a botnet.

Residential proxy infrastructure is summarised below:

Diagram showing how hidden proxy code turns devices in ordinary homes into proxies, and how a threat actor's traffic is routed through someone else's home so the website only sees an ordinary home IP address.
How a residential proxy hides the threat actor behind someone else's home internet connection.

In short: threat actors can now route their malicious activity via residential IPs, masking their identity and blending their traffic in with other legitimate activity. The devices on your home WiFi network are by no means excluded from this. Embedded systems are infamously plagued by critical vulnerabilities – and extremely recent reporting over the summer of 2026 has highlighted horrors in the security of smart TVs.

Spur have reported that over 40% of the apps available for LG smart TVs contain hidden residential proxy software, ready to route threat actor traffic through them. LG has since announced it will suspend apps that do this.

Strand also recently reported how AI-generated software can be abused to hide malicious functionality – which can include traffic proxying capability.

Why this matters for incident responders

This gives threat actors a significant advantage. Rather than defenders and incident responders seeing clearly anomalous traffic from a VPN or hosting provider, they now see legitimate-seeming home internet IP addresses. The activity and intent of the threat actors haven’t changed, but security teams must adapt in order to detect them and prevent investigations from becoming a messy web of interwoven legitimate and malicious activity occurring from relatively indistinguishable IP addresses.

Using our above example, imagine if the logs showed:

  • Login at 10:00 from a BT Home IP address

  • Login at 10:34 from a BT Home IP address

  • 3 emails sent at 11:01 from a BT Home IP address

  • Login at 11:30 from a Sky Home IP address

  • Further activity from both Sky and BT IP addresses

How would you separate the two?

Strand has identified a sharp uptick in the use of residential proxies during recent phishing/business email compromise incidents. This can have a large impact on the speed and effectiveness of incident response investigations still relying on traditional IP anomaly detection.

Strand Residential Proxy Detection

Strand is committed to providing best-in-class investigation software to respond to ever-changing cyber threats and novel tactics, techniques and procedures deployed by adversaries. As a result, we are today announcing residential proxy detection, built directly into our email security investigation system. When responding to an email compromise incident, rather than trying to separate legitimate and malicious IPs through slow analysis of downstream activity – Strand will flag which sign-ins come from known residential proxy infrastructure, and which are ordinary home IPs:

The Strand Authentication Anomalies page listing sign-ins from home broadband providers flagged as Residential Proxy, alongside a genuine home sign-in that is not flagged.
Residential proxy sign-ins flagged in Strand, alongside a genuine home sign-in that is not (placeholder data).

So whether you are an incident response provider, work in an internal SOC, or otherwise spend far too many hours far too often combing through logs to understand “what happened?” following an incident, we’re here to help.

Residential proxy detection is available now in Strand’s email compromise investigations.

Written by

Will Poole and Jordan Newman

The Strand team specialises in digital forensics, incident response, and cybersecurity threat analysis.