A suspected Russian hacker built an illegal residential proxy business by compromising more than 87,000 routers, VPN devices and servers. The operation reportedly earned over $200,000 and used a modified AI coding tool to automate its activity.

Research Exposes Massive Proxy Operation

The Cybernews research team uncovered an underground proxy network containing tens of thousands of compromised devices worldwide.

Researchers named the suspected operator LeakySensey after the campaign’s main domain. They believe a single threat actor from Russia controlled the operation.

The LeakySensey proxy network contained more than 87,000 IP addresses. For comparison, the Tor anonymity network operates through around 11,000 active relay addresses.

The hacker reportedly sold access to the compromised devices through websites, Telegram bots and residential proxy providers. Moreover, the operation presented itself as a legitimate Russian software company through the Sensey24 website.

Weak Passwords Provide Easy Access

LeakySensey used a simple but effective attack strategy.

First, automated tools scanned the internet for exposed ports and vulnerable services. The operator then launched password-spraying attacks with weak credentials such as “admin” and “admin123.”

The campaign mainly targeted outdated routers, dedicated VPN equipment, network-attached storage systems and other neglected devices.

Many of these systems used legacy VPN protocols, including PPTP and L2TP. Modern alternatives have replaced both protocols because they no longer provide adequate protection.

Nevertheless, millions of devices still expose these services to the public internet.

Outdated VPN Protocols Create Risks

PPTP dates back to the 1990s and commonly uses port 1723. Public scanning data reportedly shows around 1.9 million hosts still exposing the obsolete service.

The protocol contains serious weaknesses. Attackers can capture authentication handshakes and attempt to crack them at relatively little cost.

Meanwhile, L2TP dates from 1999 and commonly uses port 1701. Internet scans return more than three million exposed devices running this service.

L2TP does not provide encryption on its own. Instead, it relies on IPsec, which administrators may configure incorrectly or omit entirely.

Therefore, even strong passwords cannot fully address the risks associated with outdated protocols and neglected hardware.

Researchers Find More Than 87,000 Compromised IPs

The leaked infrastructure revealed the scale of the brute-force campaign.

The inventory contained more than 63,000 servers compromised through PPTP attacks. It also included over 24,000 servers accessed through L2TP.

Additionally, the operator had compromised 24 servers through SSH brute-forcing.

However, the hacker did not actively use every address as a residential proxy. At the time of discovery, 17,858 IP addresses had working proxy credentials and a ready or connected status.

The operation routed customer traffic through these systems. Consequently, unsuspecting device owners provided the infrastructure for potentially criminal online activity.

Proxy Business Generates Over $200,000

Researchers found evidence that the operation had continued for around two years.

Since 2024, the service had processed more than 24,000 transactions. It received approximately $202,000 through a cryptocurrency payment platform that supports over 100 digital currencies.

Leaked databases also contained more than 56,000 user accounts. Of those, more than 11,000 had connected Telegram profiles.

Some customers apparently registered with their real names.

The operator sold access directly to end users and through several proxy resellers. Researchers also identified a known VPN provider among the buyers.

These findings raise questions about how commercial proxy and VPN providers obtain their residential endpoints.

Exposed Server Reveals Complete Operation

Cybernews discovered the operator’s server on July 20, 2026.

The server lacked access controls and exposed the campaign’s internal data. Researchers found attack tools, AI software, customer lists and an inventory of compromised IP addresses.

The files also included valid credentials for infected systems. Many devices still used basic username and password combinations such as “admin/admin.”

Moreover, the server revealed logs showing that other cybercriminals had compromised LeakySensey’s own infrastructure.

The researcher also found evidence of a separate professional identity. The operator appeared to work as a web developer and maintained source code for Russian clients on the same infrastructure.

Custom Tools Automate Brute-Force Attacks

LeakySensey used specialised tools called PPTP API Server v3.2 and ipgo3.

These tools automated large-scale scans for PPTP, L2TP and SSH services. They also supported password attacks and integrated with the operation’s payment system.

The setup allowed one operator to manage a large number of compromised devices. Automation handled discovery, credential testing and proxy deployment.

Once the hacker gained access, the system installed proxy software and added the device to the commercial inventory.

Other Criminals Attack LeakySensey

Despite running a large hacking campaign, LeakySensey also became a victim of cyberattacks.

Researchers found evidence that another attacker installed a Monero cryptocurrency miner on the server hosting the operator’s code repository.

LeakySensey later removed the miner and deleted 37 unauthorised repository accounts.

In another incident, criminals stole API keys that controlled access to the proxy service. They then used the stolen credentials to consume LeakySensey’s infrastructure.

The operator eventually identified the compromised keys and recorded the IP addresses involved in the abuse.

Modified Claude Code Removes Safeguards

The exposed server also contained a heavily modified version of Claude Code.

According to the researchers, LeakySensey patched the official software to remove security controls and confirmation prompts. The altered version reportedly played a major role in automating the operation.

The operator maintained five Python scripts that discovered, analysed, modified, verified and distributed new Claude Code releases.

Whenever Anthropic released an update, the pipeline automatically applied the changes again.

The modified binaries removed trust prompts and granted unrestricted file-system access. They also approved planned actions without user confirmation.

In addition, the patched software accepted any model identifier instead of following Anthropic’s allowlist.

Patched Tool Supports Multiple AI Providers

LeakySensey modified the coding agent to work with models from several providers.

Subagents could reportedly use OpenAI, Gemini, Qwen and other model identifiers. The operator also removed prompt-level safety checks, allowing the tool to accept any instruction.

The system distributed the altered binaries as private packages for Apple, Windows and Linux devices.

Researchers found 12 Antigravity accounts, one Claude account, five Codex accounts and two Gemini accounts. A routing tool managed requests across these services.

The operator replaced Claude Code’s standard endpoints with this intermediate router. Consequently, the modified client could send requests to different AI models and providers.

The setup also changed prompts to reduce costs. For example, it limited thinking budgets and adjusted model-specific reasoning levels.

Multiple Accounts May Increase AI Capacity

Researchers believe LeakySensey may have used several accounts to distribute requests and bypass rate limits.

This approach could increase the number of simultaneous AI tasks and provide greater automation capacity. It could also prevent one provider’s limits from interrupting the operation.

The researchers suggested that LeakySensey may have sold access to the modified AI system. However, they did not confirm this possibility.

Cybernews disclosed its findings to Anthropic.

Evidence Points Toward a Russian Operator

The exposed server operated through a French cloud provider. However, the service on the identified port later disappeared, suggesting that the operator moved the infrastructure.

Researchers found several indicators connecting the operator to Russia. The code comments, configuration files, AI prompts and generated outputs all used Russian.

The Sensey24 storefront also appeared in Russian. In addition, the operator researched methods for bypassing Russian internet censorship and deep packet inspection.

The server contained an Xray client, which users commonly deploy to evade internet filtering in Russia and China.

Nevertheless, these clues indicate a likely location rather than proving the operator’s identity.

Device Owners Should Replace Legacy Hardware

The LeakySensey proxy network demonstrates how neglected infrastructure can support large criminal businesses.

Changing usernames and passwords may not provide enough protection when devices rely on obsolete protocols. Therefore, organisations should replace end-of-life equipment and install supported software whenever possible.

Administrators who cannot immediately replace legacy systems should remove them from the public internet. They should also isolate weak devices from trusted networks.

Furthermore, organisations should inspect potentially exposed systems for unauthorised SOCKS5 proxies and other suspicious software.

Finally, administrators should rotate any credentials or secrets stored on compromised devices. These measures can help prevent attackers from turning neglected infrastructure into commercial proxy networks.


0 responses to “Hacker Builds Massive Proxy Network From 87,000 Devices”