How residential proxy SDKs turn ordinary apps and the devices running them into malicious infrastructure.
One residential proxy network. Seven days. 550+ threat groups, including state-linked actors. The devices were enrolled through everyday apps, mostly without consent.
What's inside:
The SDK supply chain: from proxy operator to developer to enrolled device
The consent gap: opt-in, buried in terms, or covert
IPIDEA case study: Google's January 2026 disruption and why capacity migrated
Enterprise exposure: enrolled devices scanned home networks, including routers, NAS and cameras
Mitigations: for defenders, enterprises and individuals
By Sandra Cantero Rodríguez, Technical CTI Analyst, QuoIntelligence. Published September 2026.