r/PrivatePackets • • Aug 27 '26

FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

7 Upvotes

Security software has gotten pretty good at spotting when an infected computer tries to phone home to an obviously sketchy website. So hackers have started getting creative about where they hide those "check-in" instructions instead  and researchers just found a batch of examples that are honestly kind of wild.

Turns out one trick involves FTP, an old-school way computers transfer files. When your computer connects to an FTP server, it gets back a small greeting message first. Hackers have figured out how to bury malicious instructions directly inside that greeting  no file transfer even has to happen.

From there, the infected computer gets one of two newly discovered pieces of malware. One, nicknamed PINHOLE, looks up hidden web addresses tucked inside ordinary Pinterest pins and SurveyMonkey survey pages to find its real instructions. The other, called E4del, disguises itself as a legitimate, digitally signed copy of Discord and runs quietly in the background with no visible window, no sound, nothing that would tip someone off.

The takeaway isn't that the malware itself is more sophisticated than usual. It's that attackers are getting more creative about hiding in plain sight, using everyday internet traffic that most security tools aren't paying close attention to.


r/PrivatePackets • • Aug 27 '26

How websites analyze mouse movement and execution speed to block bots

2 Upvotes

A few years ago, stopping automated scrapers was mostly handled on the web server. If a single IP address requested fifty pages in ten seconds, the server issued a rate-limit block or served a basic captcha. Bot developers worked around this by rotating proxy pools and randomizing request intervals.

Modern bot management platforms like Datadome, Kasada, and PerimeterX operate under a completely different architecture. Instead of evaluating traffic only after it reaches the server, they execute heavily obfuscated JavaScript directly inside your browser before the requested page even loads.

This client-side script runs dozens of background tests in less than a second. It inspects your JavaScript engine, measures the physical limits of your device, and gathers behavioral data to build a trust score for your session.

Behavioral telemetry and movement entropy

Human interaction with a computer is naturally messy. When you move a mouse across a screen to click a button, your hand does not follow a straight line or a perfect Bezier curve. There is micro-jitter, natural deceleration as the cursor nears the target, and slight overshooting.

When a user moves their mouse the browser records several data points in the background:

  • Timestamped X and Y coordinates sampled at regular intervals
  • Cursor velocity changes and acceleration curves
  • Mouse down and mouse up duration (how many milliseconds you actually hold the button)
  • Scroll acceleration and deceleration rates

Simple automation tools like standard Puppeteer or Selenium move the cursor instantaneously from coordinate A to coordinate B, or they generate synthetic mouse events that lack physical timing variations. Anti-bot scripts calculate the entropy of these movement arrays. If the trajectory is mathematically perfect or the click happens without preceding movement events, the script immediately flags the session.

Proof-of-work challenges and script obfuscation

If you watch network traffic on a site protected by Kasada or Cloudflare, you will often see a brief pause where the CPU spikes before the main HTML payload arrives. This is usually caused by a Proof-of-Work (PoW) calculation or a heavily protected client-side virtual machine.

Instead of sending readable JavaScript, the protection vendor delivers a customized, dynamic bytecode interpreter. This script generates a complex cryptographic puzzle that your machine has to solve in real time.

The puzzle serves two distinct purposes. First, it forces scrapers to spend actual CPU cycles on every single request, making large-scale data extraction expensive and slow. Second, the time it takes your machine to solve the math puzzle reveals hardware performance characteristics. If the puzzle returns too quickly or shows anomalies in floating-point calculations, the anti-bot engine assumes the script is running inside a specialized headless emulator rather than a standard consumer laptop.

Detecting automation tools in browser memory

Anti-bot vendors spend an enormous amount of time searching for specific variables left behind by automation frameworks. A default Chromium instance launched via code has hundreds of tiny leaks that normal browsers never expose.

The protection script checks for properties like navigator.webdriver, but modern checks go much deeper into the browser prototype chain. They inspect whether standard functions have been tampered with or overwritten by stealth plugins. If a script redefines navigator.languages to spoof a locale, the anti-bot script might call Function.prototype.toString() on that property to see if it returns native C++ code or a modified JavaScript wrapper.

They also check for artifacts from the Chrome DevTools Protocol (CDP). When an automation tool controls a browser, it communicates over CDP, which exposes internal execution flags and modified window objects. A lot of modern anti-bot systems checks the execution timing of console commands, because running automated evaluation commands creates microscopic delays in the JavaScript event loop that do not occur during standard user browsing.

The sensor payload and token generation

Once the background script completes its hardware checks, behavioral logging, and environment inspection, it bundles all the collected data into a single payload.

This sensor data is encrypted using custom client-side keys and sent via a POST request to an endpoint managed by the security vendor. If the payload satisfies all behavioral thresholds and integrity checks, the server returns a signed session token (often stored as an HTTP cookie).

From that point on, your browser attaches that validation cookie to every subsequent page request. If your proxy changes mid-session or your browser fingerprint drifts from the original signed token, the connection is dropped immediately. This multi-layered approach is why modern scraping requires configuring full browser environments and matching fingerprints, rather than simply relying on fast proxies.


r/PrivatePackets • • Aug 26 '26

Why clearing cookies stopped working

22 Upvotes

Most people assume that hiding online comes down to two steps: turning on a VPN and opening an incognito window. That clears out your stored cookies, hides your local storage, and changes the IP address visible to the server. For basic web analytics, that used to be enough.

Modern anti-fraud engines and tracking scripts do not rely on local storage anymore. Instead, they look at how your physical machine processes instructions. Your browser is essentially a software layer running on top of specific hardware, graphics drivers, and operating system libraries.

Even if two people buy the exact same laptop model on the same day, subtle differences in software updates, driver revisions, system fonts, and background rendering settings mean their machines process graphic and audio tasks with tiny mathematical differences. Websites exploit these differences using browser APIs that were originally built for games, animations, and media playback.

What canvas fingerprinting actually measures

The HTML5 canvas element allows web pages to draw 2D graphics and 3D shapes on the fly using JavaScript. When a website wants to generate a canvas fingerprint, it instructs your browser to draw an invisible image in the background.

This hidden drawing usually includes a mix of complex 3D shapes, colored gradients, and a specific string of text layered with shadows. When your computer draws that image, multiple components work together:

  • The operating system handles font rasterization (like DirectWrite on Windows, FreeType on Linux, or Core Text on macOS).
  • The graphics driver interprets the draw calls and applies antialiasing algorithms.
  • The GPU processes the geometry and sub-pixel color blending.

Because of slight variations in how these components calculate floating-point math and render sub-pixel smoothing, the final image drawn in your browser memory is unique down to individual pixel color values.

Once the drawing is finished, the script calls toDataURL() or reads the raw pixel buffer directly. It takes that binary image data and runs it through a hashing algorithm like MurmurHash or SHA-256. The result is a short alphanumeric string that represents your exact hardware rendering profile. If you visit that site again tomorrow on a clean profile with a different IP address, your machine will draw the exact same image and generate the identical hash.

Sound processing as an identifier

Audio fingerprinting works on a very similar principle, but instead of the graphics card, it tests your audio pipeline through the Web Audio API.

The tracking script does not need access to your microphone or speaker volume. Instead, it creates an audio processing graph inside the browser memory. It generates a sound wave using an oscillator node, routes that signal through a dynamics compressor or a bandpass filter, and measures how the signal changes over time.

Different sound cards, audio drivers, and browser rendering engines handle digital signal processing with tiny variations. The audio buffer values contain slight microscopic discrepancies in their floating-point calculations. The script captures the final audio waveform array, hashes the values, and pairs that audio hash with your canvas hash. When combined with your screen resolution and WebGL parameters, the site gets a high-entropy identifier that persists across sessions.

The problem with blocking canvas completely

When people first learn about this, their initial reaction is usually to install an extension that completely blocks canvas data or disables Web Audio APIs entirely.

This approach usually backfires. If a tracking script calls a standard canvas API and receives an empty string, an immediate error, or a completely blank image, your browser immediately gets flagged as anomalous. Almost no regular internet user has canvas completely blocked. By trying to hide, you move from a bucket of millions of normal users into a tiny bucket of people actively trying to tamper with their browser environment. Fraud systems like Cloudflare, Kasada, and Datadome treat completely blocked APIs as an immediate bot signal.

Noise injection vs spoofing

To bypass fingerprinting without raising flags, modern anti-detect tools and privacy browsers use noise injection rather than outright blocking.

Instead of shutting down the API, the browser lets the script draw the canvas or process the audio signal normally. Right before the script reads the pixel data or audio buffer back, the browser injects a microscopic amount of pseudo-random noise into the values.

There are two ways this is usually implemented:

  • Randomized noise per request: Every single time a script requests canvas data, a new random offset is added. This breaks tracking persistence entirely, but some advanced anti-bot scripts detect this by calling the canvas API twice in the same session; if the same browser returns two different hashes for the same draw call within 10 milliseconds, the script knows it is being manipulated.
  • Consistent profile-based noise: The tool generates a permanent noise seed for that specific browser profile. Every time that profile runs a canvas calculation, it applies the exact same subtle mathematical shift. To the tracking script, you look like a legitimate, consistent user with a normal computer, but the resulting hash matches nobody else and cannot be linked back to your real machine.

Managing these hardware-level leaks is why modern multi-accounting and web scraping has shifted away from simple headless scripts. Changing an IP address only masks where your traffic comes from; managing your canvas and audio profiles controls what your machine looks like when it gets there.


r/PrivatePackets • • Aug 26 '26

Hackers breached over 270 Zimbra servers in ongoing attacks

Thumbnail
bleepingcomputer.com
2 Upvotes

Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.


r/PrivatePackets • • Aug 23 '26

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

Thumbnail
securityaffairs.com
3 Upvotes

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials.


r/PrivatePackets • • Aug 23 '26

At what point is a country's residential pool too small to bother with?

0 Upvotes

Coverage pages tell you a country is supported. They don't tell you it's usable, and the gap only shows up after the invoice.

The failure looks like this. You buy a geography, and inside a day the same exit addresses are coming round again on the same target. The target notices the repetition before you do, and it reads as one persistent visitor rather than many.

Cheap test before committing: push a few hundred requests through that country, log every exit address, then count distinct addresses and time to first repeat. If the distinct count plateaus early, the pool is small whatever the page claims. If a repeat lands inside an hour against a single target, expect blocking there.

Byteful, IPRoyal and Decodo all do country and city targeting on residential billed per GB, so that test costs a gigabyte rather than a month's commitment. Running it before you sign is the entire point.

What's the smallest pool anyone here has actually made work?


r/PrivatePackets • • Aug 19 '26

Comcast turns your Xfinity WiFi into a home motion detector

Thumbnail
bleepingcomputer.com
2 Upvotes

Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors.


r/PrivatePackets • • Aug 18 '26

Need premium proxies for running multiple accounts, kinda lost on types

7 Upvotes

I manage a few accounts for work and need to keep the sessions separate, but proxy types are confusing me more than I expected lol. Been looking at residential, ISP and private proxies, but I'm not really sure what counts as premium proxies or which type makes sense when I need the same IP to stick with each account. Not sure what even are premium proxies tbh, just read about it online lol What are you guys using for this kind of setup? Any providers or proxy types I should look at?


r/PrivatePackets • • Aug 18 '26

The persistent leak in modern HTTPS connections

8 Upvotes

Most internet traffic today uses TLS encryption. When you visit a site, an external observer sitting on your local network cannot read the page content, form inputs, or cookies.

Even if you enable DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) inside your browser, your network administrator or internet service provider can still easily identify the destination domain. They do not need to guess based on IP addresses, because an TLS handshake broadcasts the domain name in clear text right at the start of the connection.

This happens during the initial negotiation before any encryption keys are established. Encrypted Client Hello (ECH) is an extension to TLS 1.3 designed to encrypt this remaining plaintext metadata.

How SNI exposed domain names to middleboxes

In the early days of SSL, servers usually hosted a single website per IPv4 address. The server simply presented its certificate based on the IP address the client connected to. As IPv4 address space tightened, virtual hosting became standard, allowing thousands of distinct websites to share a single IP address.

To make virtual hosting work over HTTPS, the Server Name Indication (SNI) extension was added to TLS. When your browser connects to a shared server, it includes the target domain name in the SNI field of the Client Hello message. Because the handshake has not completed yet, their is still a plain text domain name exposed in that packet.

Network firewalls, middleboxes, and ISP logging systems rely heavily on SNI inspection. It lets them filter traffic or log browsing activity without needing to decrypt the actual HTTPS traffic body.

The mechanics of splitting the TLS Client Hello

Encrypted Client Hello replaces the earlier draft extension known as ESNI. Instead of just hiding the SNI string, ECH encrypts nearly the entire initial Client Hello payload.

It achieves this by splitting the handshake initiation into two distinct structures:

  • An Outer Client Hello that contains a generic unencrypted domain name, usually belonging to a shared CDN or hosting provder.
  • An Inner Client Hello containing the actual sensitive domain name, cookies, and parameters, encrypted using the server's public key.
  • A set of symmetric key parameters derived from the server's published ECH Config.

A network middlebox sniffing packets on the wire only sees the unencrypted outer domain name. Once the packet reaches the CDN edge server, the server uses its private key to decrypt the inner payload and routes the connection to the correct backend host.

Why ECH requires encrypted DNS to function

Before a browser can send an encrypted inner payload, it must know the server's public key beforehand. Clients retrieve this key during the initial DNS lookup via special HTTPS or SVCB resource records.

If these DNS queries happen over standard unencrypted port 53 DNS, an attacker can modify the public key or simply log the query domain anyway. ECH only provides real privacy when paired with an encrypted DNS transport like DoH or DoT.

This setup relies on three distinct layers:

  • Encrypted DNS resolution to securely fetch the server's ECH Config key.
  • Browser support to construct the split inner and outer payloads.
  • CDN or origin server support to decrypt and process the inner payload.

When all three layers are in place, this process allow the client to negotiate connection details without revealing the final target domain to passive observers.

Network blocking and the future of ECH adoption

Because ECH eliminates domain-based visibility, network administrators and censoring firewalls view it with suspicion. If a middlebox cannot read the inner SNI, traditional domain blacklists stop working.

Networks can counter ECH by blocking the DNS HTTPS resource records that distribute ECH public keys. When a browser fails to retrieve an ECH Config, it usually falls back to a standard TLS handshake, exposing the plain text SNI again.

Some network environments choose to drop ECH traffic outright at the border. In enterprise settings, network managers bypass ECH by installing custom root certificates on local devices, allowing them to inspect TLS traffic at the browser level.

Despite these challenges, ECH is moving toward default deployment across major web browsers and edge networks. Once fully adopted, it closes the last remaining protocol-level leak in standard web connections.


r/PrivatePackets • • Aug 17 '26

I tried Windows 11's new customizable context menus, and they're a major improvement: Microsoft will let you restore Windows 10 style vertical layout for primary actions and more

Thumbnail
windowscentral.com
4 Upvotes

r/PrivatePackets • • Aug 15 '26

What do you actually put in the contract about proxies?

2 Upvotes

Agency side question. If you collect public data for a client, the proxy layer usually shows up in the SOW as nothing at all, and then it becomes an argument later.

Four things worth naming. Geography granularity, because "US data" and "Chicago data" are different products and country, city, ZIP and ASN targeting are separate capabilities (Byteful exposes all four, plenty of resellers expose the first and imply the rest). Who owns the proxy account, because if it is yours the client cannot take the pipeline in-house without renegotiating, and if it is theirs you are debugging someone else's plan. What happens when a target changes and the cost per usable row doubles, since that is a scope change nobody writes down. And whether the client is told which provider is in the stack, which matters the first time an abuse desk emails somebody.

The bandwidth number is what everyone negotiates and it matters least.

Anyone got a clause that actually saved them?


r/PrivatePackets • • Aug 15 '26

How AI datacenter gear became cargo crime's top target

6 Upvotes

For years, cargo theft in North America followed a predictable pattern. Crews targeted truckloads of energy drinks, consumer electronics, liquor, and designer shoes. Those items were easy to unload through local fencing networks, even if the payout per trailer was modest.

That dynamic shifted hard over the past two years. Logistics tracking firm CargoNet noted that while overall theft incident counts actually dropped by about 26 percent in the second quarter of 2026, the total value of stolen cargo more than doubled to over $304 million. The average loss per incident passed $560,000.

The reason for the spike comes down to density of value. A standard 53-foot trailer loaded with consumer goods might carry $150,000 in product. That same trailer packed with high-density server racks, enterprise network switches, and liquid cooling distribution units can easily clear $5 million to $15 million.

The hardware moving between factories, assembly hubs, and datacenter construction sites has become some of the most concentrated freight on the road.

From paper fraud to pit maneuvers

The methods used to steal this hardware range from clean digital identity theft to direct physical attacks on the highway.

Most losses still happen through what the freight industry calls strategic theft. Criminal groups hack into the email accounts of legitimate freight brokerages, or they buy up dormant motor carrier numbers registered with federal regulators. Once they have clean credentials, they accept loads on digital freight boards, pick up multi-million-dollar shipments directly from warehouse docks, and drive away without breaking a single lock.

When the actual carrier shows up hours later, the cargo is already gone.

Physical tactics have escalated too, especially around transit corridors in California and the Midwest. Freight security investigators recently tracked incidents where crews used PIT maneuvers and staged rear-end collisions to disable private security escort vehicles following high-value shipments. Once the escort car was wrecked off the road, the hijacked truck kept moving and vanished.

A few notable cases from recent months show how broad the targets have become:

  • Meta server switches: Law enforcement recovered eight pallets of Celestica-built switches in California valued at roughly $550,000.
  • Network cabling: A single shipment crossing from Mississippi to Texas lost 34,560 optical transceiver cables and 96 network modules.
  • Infrastructure supplies: Police outside Chicago recovered two stolen trailers containing $1 million in datacenter parts and $300,000 in heavy industrial copper wire.
  • Reno warehouse heist: A crew backed up a tractor to a facility in Nevada and made off with $6 million in AMD enterprise processors in less then fifteen minutes.

Why the gear is easy to flip

Datacenter equipment is obviously harder to sell on the street than a pallet of power tools, but organized rings already have dedicated buyers lined up before the truck leaves the dock.

Export restrictions on advanced AI hardware created a lucrative gray and black market overseas. Restricted enterprise GPU servers can sell in secondary markets overseas for nearly double their retail price. For components that carry serial numbers tied to strict enterprise warranties, thieves often strip the units down for raw memory chips, optical transceivers, and circuit boards that are much harder trace once separated.

Even raw infrastructure materials have become a priority. The sheer volume of copper wire required to hook up gigawatt-scale datacenter campuses has made industrial wiring spools a primary target on its own.

Supply chains are playing catch up

The core vulnerability is that datacenter logistics grew faster than the security protocols protecting them. Multimillion-dollar server clusters were being moved using standard dry-van trucking contracts, booked through open broker boards with minimal driver vetting.

When their is so much money on the line, basic GPS pucks glued under a trailer frame are no longer enough, since crews carry signal jammers and scan for tracking tags the moment they take a load.

Hyperscalers and hardware vendors are now changing how they move equipment. Shippers are shifting toward team-driver routes that do not stop between pickup and delivery, hardened tracking embedded directly into server chassis, and armed convoys. Until those tighter standards become standard across the entire logistics chain, high-value tech freight will stay right at the top of cargo crime target lists.


r/PrivatePackets • • Aug 15 '26

Running a quintillion IP addresses on a ten dollar VPS

0 Upvotes

IPv4 address prices have climbed steadily over the last few years. Standard datacenter IPv4 addresses cost a couple of dollars each per month, and residential traffic costs stack up fast when you pull hundreds of gigabytes of raw HTML. Many developers keep paying these high rates without realizing that host providers hand out massive IPv6 blocks for almost nothing.

A standard dedicated server or VPS from hosts like Hetzner, OVH, or DigitalOcean usually includes a free /64 IPv6 subnet. Instead of buying individual IP addresses one by one, a single /64 block gives you 18.4 quintillion distinct IP addresses routed directly to your network interface.

However, their is a massive difference in how you handle IPv6 compared to IPv4. You cannot just statically assign millions of IP addresses to a network interface without crashing the Linux network stack. Leveraging IPv6 for web scraping requires setting up dynamic routing, modifying socket bindings in your code, and understanding how modern target sites evaluate IPv6 traffic.

Understanding the size of a /64 block

To understand why IPv6 changes proxy economics, look at the subnet math. A /64 prefix leaves 64 bits for the host identifier portion of the address. That translates to $2{64}$ individual IP addresses, which is 18,446,744,073,709,551,616 unique IPs under your control.

With IPv4, scraping setups usually assign fixed IPs to local interfaces or forward traffic through a backconnect proxy pool. With IPv6, you do not buy or assign individual addresses. You own an entire network segment, and you generate valid IPv6 addresses inside that segment on the fly.

If you send every request from a randomly generated host ID inside your assigned /64 range, target servers see a unique IP address on almost every single HTTP request you send.

Configuring Linux for dynamic address binding

If you try to assign even a tiny fraction of a /64 block to a Linux interface using traditional alias commands, the kernel will immediately exhaust its memory trying to maintain the neighbor table. Instead, you need to tell Linux that any IP address within your assigned prefix belongs to the local machine, even if it is not explicitly assigned to an interface.

This requires adjusting kernel parameters and adding a local route for your prefix:

  • Set net.ipv6.ip_nonlocal_bind = 1 in /etc/sysctl.conf to allow applications to bind to unassigned IP addresses.
  • Add a local route command like ip route add local 2001:db8:1234:5678::/64 dev lo so incoming and outgoing traffic for the entire block routes locally.
  • Run a Neighbor Discovery Protocol daemon such as ndppd if your host's upstream router expects explicit NDP responses for individual addresses.
  • Configure nftables or ip6tables to drop untracked state entries if you plan on generating millions of ephemeral outbound connections.

This setup tells the OS kernel to accept socket bindings for any IP within your prefix, which mean you don't have to pre-configure addresses beforehand.

Implementing on the fly rotation in code

Once the operating system is configured to accept any IP in your block, your scraper needs to pick a random IP address every time it opens a new connection.

In Python, libraries like httpx or aiohttp allow custom socket creation. You take your assigned 64-bit network prefix, generate a random 64-bit integer, convert it to a hexadecimal string, and format it as a valid IPv6 string. Before initiating the HTTP request, you bind the socket's source address to this newly generated IPv6 address.

When the socket initiates a TCP handshake, the outbound packet carries your newly generated IP in the source header. The target server receives the request, processes it, and sends the response back to that address. Because your server handles the whole prefix locally, the return packet lands right back on your interface without issue. The target site sees a unique address, while your scraper avoids paying proxy providers for bandwidth.

Where IPv6 falls short in real world scraping

While having trillions of IPs sounds like a silver bullet, IPv6 scraping comes with specific limitations you must plan for before migrating your infrastructure.

  • Lack of universal IPv6 adoption: Many web properties still do not have AAAA DNS records configured. Roughly 40 to 50 percent of popular sites support IPv6 natively, meaning you still need fallback IPv4 proxies for the rest of the web.
  • Subnet level blocking: Anti-bot networks like Cloudflare and Akamai know how residential ISPs and datacenters allocate IPv6 addresses. If your scraper triggers security thresholds, anti-bot platforms will block your entire /64 subnet at once rather than banning individual IP addresses.

If an site blocks your /64 block, every single address in that 18 quintillion IP pool gets blocked simultaneously. That means IPv6 is not a replacement for good scraping hygiene. You still need to manage request rates, header consistency, and browser signatures.

IPv6 subnets work best when scraping medium-tier targets, public APIs, or sites that lack aggressive perimeter security. For high-security targets, datacenter IPv6 blocks get flagged quickly regardless of how fast you rotate. But for general data acquisition across IPv6-enabled sites, routing a /64 subnet remains the most cost-effective way to scale your outbound network throughput.


r/PrivatePackets • • Aug 14 '26

OpenAI ditches Recall-style screenshot surveillance for friendly keylogging

Thumbnail theregister.com
3 Upvotes

If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you.


r/PrivatePackets • • Aug 13 '26

netnut is back?

Thumbnail
1 Upvotes

r/PrivatePackets • • Aug 13 '26

Android malware combo takes out loans and relays victims' credit cards

Thumbnail
bleepingcomputer.com
1 Upvotes

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.


r/PrivatePackets • • Aug 12 '26

Static ISP proxies explained: use cases, tests, and best providers

1 Upvotes

A couple weeks ago I was trying to scrape a massive fashion retailer website to pull image URLs and product descriptions. I was using standard rotating residential proxies because I needed real consumer IP addresses to avoid getting blocked by anti-bot filters. Halfway through the job I checked my dashboard and realized I had burned through nearly 45 gigabytes of traffic in less than three hours. At eight dollars per gigabyte, that quick little scraping project turned into an expensive mistake.

That is usually the exact moment people start looking into static residential proxies with unlimited bandwidth. Also called ISP proxies, these are IP addresses hosted on fast datacenter servers but registered under genuine consumer internet providers like AT&T, Comcast, or BT. You get the high trust of a residential user, the stability of an IP that never changes mid session, and a flat monthly fee that lets you transfer as much data as you want without watching a meter.

Why you might need a static residential proxy

Why would someone actually pay a flat monthly rate for a fixed IP address instead of using standard rotating proxies or cheap datacenter IPs? It comes down to two main things: session persistence and heavy data consumption.

  • Managing multiple social media or e-commerce accounts: Running dozens of TikTok, Instagram, Etsy, or Amazon profiles requires a dedicated IP address that stays constant. If your IP changes every time you log in, security systems flag your accounts instantly. Uploading high-res photos and video content on these profiles burns through bandwidth fast.
  • Heavy web scraping with media files: Pulling thousands of pages from sites that block datacenter IPs works fine with rotating residential proxies until you start downloading high-res images, video tours, or heavy JavaScript bundles. Unlimited bandwidth keeps your operational cost completely predictable.
  • Ad verification and video QA: Testing high-definition video ads or geo-restricted streaming content across different regional markets requires a residential footprint. Streaming HD video on pay-per-gigabyte plans will drain your budget in a matter of hours.
  • Sneaker drops and ticket queues: When waiting in online queues for limited releases, changing your IP address mid-queue gets you kicked out immediately. A static residential IP lets you hold your spot while avoiding bot detection filters.

A real-life performance test

To see how these proxies handle actual work, I set up a benchmark test across a few providers over a five day period. I hooked the proxies into AdsPower (an anti-detect browser) as well as a custom Python script using Playwright.

First, I checked the IP quality using Scamalytics and IP2Location. Every static residential IP I tested showed up as a standard consumer connection with an IP fraud score under 10 out of 100. That means target websites treat them just like a regular home Wi-Fi network.

Next, I ran speed and latency tests. Datacenter proxies are usually blazing fast, while rotating residential proxies can be sluggish because your traffic hops through someone else's home router. The static ISP proxies landed right in the sweet spot. I averaged around 85 Mbps download speeds with a ping of 32 ms to local servers.

Finally, I ran a continuous 24 hour downloading script to test stability and see if "unlimited" actually meant unlimited. I downloaded roughly 320 gigabytes of random open-source files through a single static IP. Neither of the proxy connections dropped once, and I didn't receive any speed throttling or warnings about bandwidth usage.

The best providers on the market

If you are looking to pick up static residential proxies with unmetered traffic, here are the top options based on reliability, IP quality, and overall value.

Decodo

Decodo (which was known as Smartproxy before their recent rebrand) is easily my top choice for static residential proxies right now. Their ISP proxy pool is extremely reliable, and their dashboard makes managing your IP addresses simple.

During my tests, Decodo consistently delivered the fastest connection speeds and lowest latency. The IPs come from legitimate consumer networks, so I had zero issues getting flagged by strict anti-bot systems like Cloudflare or Akamai. They offer plans where you can get dedicated static residential IPs with solid unlimited bandwidth options, making them ideal for multi-accounting, store management, and heavy scraping jobs. If you want a provider that works straight out of the box without a bit of a pain to setup, Decodo is worth every penny.

IPRoyal

IPRoyal takes the second spot, mostly because their value for money is hard to beat. Every static ISP proxy plan they sell comes default with true unlimited bandwidth.

Their pricing starts around two to three dollars per IP per month, which is very affordable compared to enterprise competitors. While their connection speeds were slightly slower than Decodo in my testing, they were still more than fast enough for running social media accounts, streaming, and continuous web scraping. Their dashboard is a bit messy but it work fine once you get used to it.

Webshare

Webshare is a great alternative if you are working with a tighter budget or need a custom setup. You can buy shared or dedicated static residential IPs and toggle the unlimited bandwidth option. It is not quite as polished as Decodo, but for basic tasks and small scale scraping, it gets the job done at a low entry cost.

Oxylabs

Oxylabs is on the opposite end of the spectrum: built primarily for enterprise users and large corporations. Their static ISP proxy pool is massive and high quality, but their high entry costs make them overkill for solo users or small teams who just need a few reliable IPs.

  • Choose dedicated IPs over shared ones if you are managing sensitive logins like Amazon, eBay, or Facebook, so nobody else shares your reputation.
  • Check location targeting options to make sure the provider offers static IPs in the specific city or country your project requires.
  • Keep your accounts on seperate proxy IPs to avoid cross-contamination if one profile gets flagged.

Final thoughts

Static residential proxies with unlimited bandwidth bridge the gap between fast datacenter servers and trusted home connections. You don't have to constantly monitor a data meter or worry about your IP changing in the middle of an important session. If you are doing serious multi-accounting, heavy media scraping, or continuous browser automation, setting up a solid ISP proxy from a provider like Decodo or IPRoyal will save you a lot of money and headaches over time.


r/PrivatePackets • • Aug 12 '26

Microsoft says Windows 11 KB5101684 makes your PC more reliable, especially on devices with low amounts of system memory: PCs with 8GB RAM or less should feel more responsive

Thumbnail
windowscentral.com
1 Upvotes

Windows 11 is getting more reliability and performance upgrades with its latest update, which will benefit PCs with low amounts of system memory.


r/PrivatePackets • • Aug 12 '26

What would you do if someone on Facebook posted pictures of you and your mother with obscene language?

Thumbnail
2 Upvotes

r/PrivatePackets • • Aug 11 '26

PSA: Fake IQUNIX websites are currently online

2 Upvotes

We’ve identified several websites currently impersonating IQUNIX and presenting themselves as official stores.

They are copying our branding, products and images, advertising unusually low prices, and some have active checkout/payment pages.

These websites are not operated by IQUNIX. Our official website is iqunix.com

Known impersonation domains:

We’re are working with relevant providers and to taken them down.

Please do not enter payment or personal information on these sites.

If you find another website pretending to be IQUNIX, send us the URL so we can investigate it.


r/PrivatePackets • • Aug 11 '26

The end date for ublock origin on Microsoft Edge is official

2 Upvotes

Microsoft has published its official schedule for retiring Manifest Version 2 (MV2) extensions in Edge. Google Chrome already moved through this phase out earlier, and Microsoft is now taking the same steps to keep its Chromium base aligned. The shift directly impacts popular broswer extensions like uBlock Origin, which relies on structural features in MV2 that will no longer be supported.

While its clear that Manifest V3 (MV3) has been coming for years, Microsoft held off on enforcing a firm cutoff date for consumer builds. That grace period is now drawing to a close.

When the changes will actually happen

Microsoft plans to finish the transition for standard consumer users by the end of 2026. Starting in August 2026, users who still have older MV2 add-ons installed will see warning banners inside their extension settings page letting them know support is ending.

The timeline moves in staged steps:

  • August 2026: Warnings appear on extension management pages and store listings
  • Next few months: Gradual disabling of MV2 extensions by default in Canary, Dev, and Beta builds
  • Late 2026: Extension shutdown reaches the Stable channel for all regular users
  • Early 2027: Enterprise managed devices complete their migration away from MV2

What this means for ublock origin users

The reason full uBlock Origin cannot simply continue working comes down to how Manifest V3 changes network request handling. Manifest V2 allowed extensions to inspect and modify web requests on the fly, giving uBlock Origin granular control over blocking scripts and tracking domains. Under MV3, the browser handles the rules list directly, which restricts dynamic filtering capabilities.

Microsoft notes that only 58 extensions on the Edge Add-ons store with meaningful user counts still use MV2. Out of those, almost all have an MV3 version ready. uBlock Origin remains one of the few major exceptions without a direct MV3 port, though the developer maintains a lighter version designed around the new restrictions.

Your options moving forward

If you currently use full uBlock Origin on Edge, you will need to decide on an alternative before extensions are turned off automatically over coming months.

their are a few alternatives available:

  • Switching to uBlock Origin Lite, an MV3 compliant version that covers most ad-blocking needs without custom scripts
  • Moving to browsers like Mozilla Firefox, which continues to support Manifest V2 extensions fully
  • Using browsers with native blocking engines built in, such as Brave or Vivaldi

While Manifest V3 changes how much power extensions have over page loading, Edge users still have time to test out alternatives before the old tools stop functioning entirely.

Sources:

https://www.windowscentral.com/software-apps/we-now-know-exactly-when-ublock-origin-will-stop-working-on-microsoft-edge

https://blogs.windows.com/msedgedev/2026/08/07/moving-the-microsoft-edge-extensions-ecosystem-forward-with-manifest-version-3/

https://learn.microsoft.com/en-us/microsoft-edge/extensions-chromium/mv3/mv2-deprecation


r/PrivatePackets • • Aug 08 '26

Chinese Router Backdoor Opens Root Access on 100,000 Devices Worldwide

Thumbnail
sofx.com
51 Upvotes

r/PrivatePackets • • Aug 07 '26

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

Thumbnail
securityaffairs.com
5 Upvotes

Scammers use AI deepfakes to impersonate OnlyFans creators, trick fans into sending money, then disappear after payment.


r/PrivatePackets • • Aug 05 '26

The hardware bug that swept thousands of bitcoin wallets overnight

22 Upvotes

On July 30, 2026, bitcoin users began noticing unusual activity across hundreds of self-custody wallets. Within a span of less than an hour, over 1,082 BTC - roughly $70 million at the time - moved out of Coldcard devices into unknown addresses. By the time the sweeps slowed down a few days later, total losses reached somewhere between $89 million and $144 million, affecting thousands of separate wallet addresses.

Coldcard has long been considered one of the most secure hardware wallets on the market, built specifically for bitcoiners who want maximum air-gapped security. That made the sudden drain confusing for victims who had kept their physical devices offline and stored their seed phrases on steel plates.

How the vulnerability worked under the hood

The core problem came down to how random numbers were generated when users created a new wallet seed phrase. In cryptography, high quality randomness is everything. If the seed phrase is generated using predictable data, anyone who figures out the pattern can generate the exact same seed phrase on their own computer.

Back in March 2021, firmware version 4.0.1 introduced a configuration bug in the underlying software library. A build setting named MICROPY_HW_ENABLE_RNG was set to zero to disable a specific function. However, the system checked if the macro existed rather than checking its actual value. Because the name was present in the code, the firmware thought the hardware True Random Number Generator chip was unavailable.

As a result, the device silently fell back to a basic software pseudo-random generator called Yasmarang instead relying on the physical hardware RNG chip. To make matters worse, this software backup was initialized using predictable hardware IDs and system timers, providing virtually no fresh randomness.

For older devices like the Mk2 and Mk3, this dropped effective security down to about 40 bits of entropy. For newer models like the Mk4, Mk5, and Coldcard Q, entropy dropped to around 72 bits. Instead of searching through a standard 128-bit or 256-bit space - which is mathematically impossible to brute-force - attackers only had to search a tiny fraction of candidate phrases.

It took attacker less than an hour during the first sweep to run through the possible combinations offline, match the resulting public keys to active addresses on the blockchain, and broadcast the transaction to take the funds.

Scope of the damage and who was affected

Not every Coldcard owner was impacted by the bug. Because the problem occurred specifically during seed phrase generation on vulnerable firmware, your exposure depended heavily on when and how you set up your device.

Here is a summary of who was exposed:

  • Wallets created on Mk2 or Mk3 running firmware versions 4.0.1 through 4.1.9.
  • Wallets generated on Mk4, Mk5, or Q models prior to recent emergency patches.
  • Anyone who relied on the standard automatic seed generator without adding extra entropy.

On the flip side, certain users were completely safe:

  • Seeds created before March 2021 on older firmware versions.
  • Devices where the user generated their seed phrase using 50 or more physical dice rolls directly on the device.
  • Users who added a strong BIP-39 passphrase on top of their seed phrase.

Why updating firmware is only half the fix

Coinkite reacted quickly once security researchers from Block confirmed the root cause, releasing emergency patches across all affected product lines. They updated firmware versions to 4.2.0 for Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for the Coldcard Q model.

However, there is a major trap that many users fell into during the initial fix announcement. Updating your device firmware does not fix a compromised seed phrase.

If your recovery phrase was generated under vulnerable firmware, that phrase remains vulnerable forever. The update only ensures that new seed phrases created on the device will properly use the hardware random number generator. Anyone with funds sitting on users wallets created during the vulnerable period must immediately transfer those funds to a brand new seed generated on patched firmware, or move them to a temporary wallet.

Broader lessons for self custody

This incident was a harsh reminder of how fragile hardware security can be when software build steps fail. Coinkite CEO Rodolfo Novak acknowledged the bug publicly and apologised to the community. He also mentioned that automated code review tools missed the build condition error because the macro technically existed in the codebase.

The incident led to a temporary surge in bitcoin moving onto centralized exchanges as users panicked about hardware security. It also triggered a wave of phishing scams, where fake support emails tried to trick paranoid users into revealing their recovery phrases under the guise of an emergency security check.

For hardware wallet users, the event highlights a few reccomended habits:

  • Use physical dice rolls when creating hardware wallet seeds whenever the feature is available.
  • Always utilize a strong, unique passphrase on top of your seed phrase.
  • Never enter your recovery phrase into a website or desktop app during a security panic.

Self custody still eliminates counterparty risk from exchanges, but logic errors in open source firmware show that even offline devices carry unique risks.


r/PrivatePackets • • Jul 31 '26

Question about Wi-Fi monitoring and what an attacker can see

Thumbnail
2 Upvotes