David Brunsdon
David Brunsdon is a Threat Researcher at Infoblox, specializing in uncovering malicious activity through DNS—the glue that holds the Internet together. By following the trails DNS creates, he uncovers a fascinating array of nefarious activity. Before transitioning to cybersecurity, David worked in operational technology, a background that gives him a unique perspective on networks and a deep appreciation for digging through logs. With a focus on threat hunting and domain hijacking, David tracks how cyber attackers exploit DNS infrastructure across multiple stages of their campaigns. His recent work has exposed subdomain compromises affecting major organizations.
2026 Talk
Talk Title: Your TV, My Exit Node - Inside the Residential Proxy Economy
Talk Abstract:
In January 2026, we published our findings on the Kimwolf botnet, which had quietly embedded itself in roughly 25% of Infoblox's enterprise customer networks, using residential proxies to blend in and, more alarmingly, to probe internal network infrastructure. Kimwolf was our wake-up call, and where this journey begins.
This presentation will explain the ecosystem of residential proxies, provide visualizations of what Infoblox is seeing within their cloud customer networks, speak to how IP addresses are sourced, and finish with a fascinating case study on a proxyware actor we track as Lurking Lizard.
On residential proxies
Residential proxies route traffic through everyday consumer devices like smart TVs, routers, phones, and "free" VPNs. Unlike obfuscation tools such as VPNs and Tor, which produce traffic the destination knows is anonymized, residential proxies produce laundered traffic; the destination believes it knows exactly who is connecting, but it's wrong. That distinction is what makes them so valuable to attackers: they evade IP reputation systems, bypass fraud detection, and let malicious traffic disguise itself behind ordinary household and corporate noise.
And as Kimwolf showed, the danger doesn't stop at disguise. When that traffic reaches into a corporate network, it doesn't just create legal and reputational exposure for the unwitting host…in some cases, it can open a path to scan and attack the network from the inside.
What are we seeing?
Kimwolf turned out to be the tip of a much larger iceberg. Following that research, we pulled hundreds of billions of DNS resolutions from our own customer telemetry and found that over 65% of Infoblox Threat Defense Cloud customers queried residential-proxy infrastructure in 2026, with traffic up 25% year-over-year to over 500 billion queries a month, present in risk-averse industries from pharma to banking to government.
On the ethics of sourcing
Much of the debate over whether a given residential proxy service is "ethical" or not comes down to a single question: how did they get the IP? In practice, that spans a spectrum.
At one end, some of the industry's major players are explicit about it: partnering directly with passive-income apps that tell users plainly that they're "selling their unused bandwidth." A step down from that, some "free" apps carry residential proxy SDKs voluntarily embedded by their developers as a monetization source; these SDKs typically come with their own terms requiring that end users be notified, though enforcement of that disclosure varies widely in practice. Further along the spectrum, some applications and devices operate the same capability quietly, with no meaningful user notice at all — often bundled with pirated content or disguised as unrelated utilities. And at the far end, some networks source IPs outside any user relationship entirely, through exclusive arrangements with ISPs or, in the worst cases, outright hijacked IP space.
The result is an industry where the same underlying technology (routing traffic through a residential IP) can mean anything from a fully consensual bandwidth-sharing arrangement to an unauthorized, undisclosed compromise of someone's device. For defenders, that ambiguity is a critical challenge: you can't tell which end of the spectrum you're looking at from DNS traffic alone.
Lurking Lizard
To understand how this ecosystem operates end to end, we go deep on a single case study: an actor we track as Lurking Lizard. Using a trojanized fake 7-Zip installer as our entry point, we pivoted through WHOIS clusters, drop-catch domains, and a stray IPLogger URL to uncover a sprawling network of 230+ lookalike domains, fake proxy storefronts impersonating real providers like SmartProxy and IPIDEA, fake proxy review sites designed to build trust in the actor's own products, and a free VPN app with over a million downloads. The VPN app represents the latest iteration of the proxyware campaign, which operationally has considerable overlap with the original fake 7-Zip campaign.
Where defenders should start
With all of these elements, I'd argue the first place a network defender should look isn't a threat feed or a blocklist. It's policy. What is your organization's policy on the use of residential proxies on your network? Do you even have one?
Most organizations have clear policies around VPN use, BYOD, and acceptable use of corporate bandwidth — but residential proxy participation rarely gets named explicitly, even though it's functionally the same category of risk: an outbound relationship that hands a third party access to your IP space. Without an explicit policy, there's nothing to enforce, nothing to point to when a proxy-enabled app turns up on a managed device, and no baseline for what "authorized" even looks like on your network. Detection and DNS hunting matter, but they're a response to a gap that policy should have closed first.
2025 Talk
2025 Talk
Talk Title: Unwanted Guests
Talk Abstract:
In this talk, David will demonstrate how threat actors abuse compromised or misconfigured infrastructure at various stages of the attack chain. Whether it's launching attacks from equipment installed at homes or offices, or hijacking domains, or compromising websites sites so they host malware stages and redirect site visitors to malicious content, threat actors seem to have little need to host their own infrastructure.