logo

Bad sushi: China-nexus phishers shift to residential proxies

ID: 63e8692f-c402-5533-af36-9f5d7be839d1

STIX ID: report--63e8692f-c402-5533-af36-9f5d7be839d1

Feed Name: The Spamhaus Project

Threat Score
72/100

Date Published: 2025-10-16

Date Updated: 2026-04-30

Author: Jonas Arnold

...
...

By April–May 2025 a widespread phishing campaign shifted to leveraging residential proxy networks and exploded in scale, moving from thousands to over a million source IPs across 173 countries and 8,893 ASNs. The campaign increased IPv6 spam emissions, used generic/non-existent HELOs, .top redirectors, and hosted phishing landing pages on cloud VPS providers (notably Alibaba and Tencent), enabling rapid, high-volume distribution and regional spikes such as heavy activity in Latin America.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.