Residential proxies evaded IP reputation checks in 78% of 4B sessions
ID: 128d2f54-66cb-58a5-9f2c-ac8b4046eb2e
STIX ID: report--128d2f54-66cb-58a5-9f2c-ac8b4046eb2e
Feed Name: Bleeping Computer
GreyNoise analyzed ~4 billion malicious sessions over three months and found that a large portion of attack traffic appears to come from residential IPs (proxy networks and infected consumer devices), with 78% of those sessions invisible to IP-reputation feeds. The report details the short-lived and rotating nature of these residential proxies, their primary use for scanning/reconnaissance rather than direct exploitation, major contributing countries, the role of IoT botnets and abused SDKs in free apps, the partial disruption of the IPIDEA network, and recommends moving from IP-reputation to behavior-based detection (tracking sequential probing, blocking illegitimate ISP-space protocols, and persistent device fingerprints).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
