
π―Basically, a huge network of phone farms was found that helps criminals commit fraud.
What Happened
A recent investigation by Infrawatch uncovered a massive mobile proxy ecosystem known as ProxySmart. This network features 87 exposed control panels across 17 countries, enabling large-scale fraud, bot activity, and identity evasion. The operation relies on physical phone farms, which consist of real smartphones and 4G/5G modems connected to carrier networks.
Who's Affected
The investigation identified at least 94 physical farm locations primarily in North America, Europe, and South America. The U.S. has the highest concentration, with deployments in 19 states. This widespread infrastructure poses risks to various sectors, including finance, social media, and telecommunications.
What Data Was Exposed
The exposed control panels linked to ProxySmart allow for a range of illicit activities, such as:
SMS-based OTP bypass
Fake account creation
Automated engagement
Geo-restriction circumvention
Payment fraud
What You Should Do
Organizations should be aware of the risks posed by this SIM Farm-as-a-Service network. Here are some recommended actions:
Identify
- 1.Enhance fraud detection measures to identify unusual patterns in user behavior.
- 2.Implement multi-factor authentication to protect accounts from unauthorized access.
Protect
- 3.Monitor for unusual IP address activity, especially from mobile proxies.
- 4.Educate users about the risks of SIM swapping and account takeover attempts.
Conclusion
The findings from Infrawatch highlight the alarming capabilities of ProxySmart and similar platforms, which significantly lower the barriers for malicious actors to operate mobile proxy infrastructures. The combination of rapid IP rotation, multi-carrier access, and OS fingerprint spoofing complicates detection and enforcement, posing ongoing challenges for security teams worldwide.
π Pro insight: The ProxySmart ecosystem exemplifies the evolving landscape of cybercrime, where traditional barriers to entry are rapidly diminishing.




