Bandwidth Supply

What is Proxyjacking?

Proxyjacking is installing proxyware on a machine you have broken into, so that its bandwidth and IP address can be sold through a proxy network for the attacker's benefit. Sysdig's Threat Research Team defined the term in April 2023, comparing it to cryptojacking: the attacker profits from stolen network access instead of stolen processor time.

Sysdig's report of 4 April 2023 described the case that gave the attack its name. The attacker exploited the Log4j vulnerability, CVE-2021-44228, in Apache Solr to run code on the server, then deployed a legitimate proxyware command-line client registered to the attacker's own account. From then on the victim's machine carried proxy traffic and the payments went to the attacker. The victim paid for the bandwidth and, as the visible source address, absorbed whatever that traffic did.

It is not limited to servers. Cisco Talos described modified proxyware clients with hardcoded credentials enrolling infected PCs under attacker accounts as early as August 2021, and AhnLab ASEC reported on 17 September 2026 that a group it tracks as Larva-25012 was installing proxyware without the user's consent on Windows systems it had already infected, through a loader registered in Task Scheduler that ran PowerShell commands. ASEC defines proxyjacking the same way Sysdig does: installing proxyware without the user's consent so that the profits go to the attacker.

Detection differs from cryptojacking because a relay needs network rather than processor time, so CPU alerts that catch miners may never fire. Look instead for a process you did not deploy that holds a long-lived outbound TLS or WebSocket connection, new services, scheduled tasks or containers, and steady egress that matches no workload. On a server, the proxyware is rarely the only thing an intruder left; patch the entry point, rebuild if you cannot account for every change, and rotate credentials.

Supply rules on the proxy network side decide how much a proxyjacked machine is worth to an attacker. At PROXIES.SX, only residential and mobile IPs can be listed for customer traffic and hosting or datacenter IPs are rejected, so a compromised cloud server is not routed customers. That does nothing for an infected home PC on a residential line. There the controls are contractual: bandwidth only from devices whose owners gave informed consent, an agreement signed in the partner's legal name and an account-linked key. Supplier declarations are not independently verified, so reports of software installed without consent matter.

Where you meet it

You meet proxyjacking in incident reports about exposed servers, in cloud-provider abuse notices, and when an unexpected egress bill arrives for a machine that should be idle. It is also why bandwidth-sharing guides tell you to run a client only on hardware you own and control, and never on a work, school or client network.

Common questions

What is the difference between proxyjacking and cryptojacking?

Both monetise a compromised machine for the attacker. Cryptojacking uses its processor to mine cryptocurrency; proxyjacking uses its network connection and IP address, enrolled in a proxy network under the attacker's account. Proxyjacking uses little CPU, so it can go unnoticed by monitoring tuned for miners.

How do I know if my server has been proxyjacked?

Look for an unfamiliar process or container holding a persistent outbound connection, services or scheduled tasks you did not create, and steady outbound traffic with no matching workload. Check what the process connects to and which account its configuration references. Then look for the original way in, which Sysdig traced to an unpatched vulnerability.

What should I do if I find proxyware I did not install?

Keep a copy of its configuration for the vendor, then remove it along with its service, task or container. Patch or rebuild the machine, rotate credentials and review other hosts on the same network. Report the enrolled account to the proxyware vendor so it stops being paid for your bandwidth.

Related terms

Proxyware
Proxyware is software that turns a device into an exit point for a proxy network, relaying other people's traffic through that device's internet connection. The term comes from security research, where it covers legitimate bandwidth-sharing clients the owner chose to install and the same clients planted on machines without the owner's knowledge.
Bandwidth Sharing
Bandwidth sharing means letting a proxy network route other people's internet traffic through your connection, usually by running a small client on a phone, computer or server, in exchange for payment for the traffic carried. To the destination site, that traffic appears to come from your IP address, which is what the network actually sells.
Exit Node
An exit node is the device whose IP address a proxied request finally leaves from, so the destination site sees and logs that device's address instead of the customer's. In residential and mobile proxy networks the exit is usually a phone, computer or router running bandwidth-sharing software; in Tor the same term names a circuit's last relay.
Datacenter Proxy
A datacenter proxy runs on a server in a hosting facility, using an IP address registered to a cloud or colocation provider rather than to a consumer ISP or a mobile carrier. It is fast and cheap, and it is the easiest kind for a website to identify, because hosting ranges are public knowledge.
Peer Relay
A peer relay is the server that bandwidth-sharing devices connect out to, and through which customer traffic is handed down to those devices. Because each device dials the relay and keeps the connection open, it needs no public address and no open port, which is how phones and home lines behind NAT or CGNAT can act as proxy exits.
Bandwidth-Sharing SDK
A bandwidth-sharing SDK is a library an app developer embeds so the app can relay proxy traffic through its users' connections, with the developer paid for the traffic carried. Google Play allows proxy services for third parties only in apps where that is the primary, user-facing core purpose, and holds developers responsible for the SDKs they ship.
Informed Consent
Informed consent, in bandwidth sharing, means the device owner understands that their connection will carry other people's internet traffic, what that involves and how to stop, and agrees before any traffic flows. It separates a bandwidth-sharing app a person chose to run from proxyware placed on their device without their knowledge.
USDC on Solana
USDC on Solana is Circle's dollar stablecoin issued as a token on the Solana blockchain, identified by the mint address EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v. A Solana wallet can hold it alongside native SOL, but they are different assets, so a payout setting has to name the currency and the network.

Real 4G/5G mobile and residential IPs

PROXIES.SX runs carrier IPs in 100+ countries with HTTP and SOCKS5 on every endpoint. $4/GB down to $2.40/GB at volume, free endpoints and rotation, and your GB never expire.