Residential proxies
Residential proxies are IP addresses assigned to real residential devices, such as smartphones and computers, by Internet Service Providers, often used to disguise the true origin of network traffic.
What are residential proxies?
Residential proxies are IP addresses assigned to real residential devices (such as smartphones and computers) by Internet Service Providers (ISPs). Unlike data center proxies, which use IP addresses from servers hosted in data centers, residential proxies leverage IP addresses from real devices.
These proxy servers act as an intermediary between the user and the internet, hiding the user's real IP address and allowing them to browse the web anonymously.
Why do cybercriminals use residential proxies?
Cybercriminals use residential proxies for several reasons:
- Anonymity: Residential proxies provide a high level of anonymity because they use IP addresses associated with real residential devices. This makes it harder for websites and security systems to detect and block the proxy traffic.
- Bypassing restrictions: Many websites and online services block or restrict access from IP addresses associated with data centers or known proxy servers. Residential proxies can be used to bypass these restrictions.
- Evading detection: Security systems often use IP reputation to detect malicious activity. Since residential IPs are associated with legitimate users, they are less likely to be flagged as malicious.
Sekoia.io's Cyberdefense's World Watch teams provide in-depth analysis on malware campaigns that use residential proxies. To discover their latest analysis :
You can also discover our other glossary entries on the topic of anonymization tools: Proxy, VPN, Tor.


