Shop for a mobile proxy and you build a shortlist that feels like a real market. Coronium, XenProxy, WaterProxy, a dozen names you have never heard of, each with its own site, its own pricing, its own promise of private 5G devices. It looks like competition. A lot of it is one program.
In April 2026, an infrastructure intelligence firm called Infrawatch published research, carried by Help Net Security, showing that at least 24 "different" commercial mobile proxy brands run on a single piece of software: ProxySmart, built and operated out of Minsk, Belarus. Same control panel, same rotation trick, same fingerprint spoofing, different logos on the checkout page.
We run a mobile proxy network, so we read this the way a buyer should, not as gossip but as a sourcing question. When you rent a mobile proxy, what are you actually renting, and how many other brands are renting the exact same thing? Here is what the researchers found, what it does and does not mean, and how to tell what is really behind the brand you are about to pay.
What ProxySmart actually is
ProxySmart is management software for mobile proxy farms. A mobile proxy needs physical hardware: a phone or a USB modem with a SIM (subscriber identity module) card, sitting on a real carrier network. We wrote the full explainer in what is a mobile proxy, but the short version is that the carrier IP is the whole product. Running one modem is easy. Running a farm of dozens or hundreds, renting each one out, rotating the IPs, and dressing the traffic up to pass as human, is a software problem. ProxySmart is the software that solves it.
Per Infrawatch, the platform is written in Python, operated from Minsk, and provides "device management, automated IP rotation, customer provisioning, plan enforcement, and anti-bot countermeasures." In plain terms, it turns a room full of modems into a proxy business with a billing page. It decides who gets which modem, how often the IP changes, and how the traffic is presented to the target.
That last part is the interesting bit. ProxySmart can spoof the operating-system fingerprint of a connection, presenting a chosen profile (macOS, iOS, Windows, or Android) so the low-level network signature matches the device the traffic claims to be. It rotates IPs with a blunt, effective trick: it flips the modem into airplane mode for about three seconds, forcing a reconnect and a fresh carrier IP. And it offers several tunnel types, OpenVPN, SOCKS5, VLESS, and plain HTTP, to carry your requests. None of this is exotic, and that is exactly the point. It is a commodity stack, and it is the same commodity stack sitting under a lot of separate storefronts.
The word for that arrangement is OEM, original equipment manufacturer: one company builds the product, and other companies put their own brand on it and resell it. Your kitchen appliances work this way. So, it turns out, does a large slice of the mobile proxy market.
What the researchers found
Infrawatch did not take anyone's word for the scale. They fingerprinted the software. Every ProxySmart control panel exposed to the internet carries the same identifiable signature (Infrawatch published the SHA-256 hash 739f2252...4bf164 for it), and the Android enrollment app carries its own. Scanning the internet for that signature is how you count something that would rather not be counted.
The tally, once they did:
Read those numbers as a single sentence. Eighty-seven exposed control panels, running ninety-four SIM farms, in at least seventeen countries, feeding twenty-four commercial proxy brands, across thirty-five carriers. The farms are not confined to the usual grey-market corners either. Infrawatch placed them in nineteen US states, alongside Canada, the UK, Germany, Spain, Portugal, France, Italy, the Netherlands, Ireland, Poland, Romania, Ukraine, Latvia, Georgia, Brazil, and Australia.
Infrawatch's CEO, Lloyd Davies, was careful about the accusation, and we will be too: "The legal grey area that SIM farms sit in has allowed that model to scale with limited disruption and we assess that it's highly likely to be facilitating large-scale fraud operations." That is an assessment of likelihood, not a court verdict. It is also precisely the kind of thing you want to know before you route your own business through the same pipes.
ProxySmart pushed back. Its Technical Consultant and, yes, "Director of Public Relations," Alex Zak, disputed the characterization, and the company published a written response to the research in which it named the industrial modem makers behind its deployments (Quectel and Sierra Wireless). Sit with that for a second: a piece of SIM-farm management software has a director of public relations and issues press statements. Whatever else it is, this is a real, resourced commercial operation, not a hobby project in a basement.
Twenty-four brands, one back end
Here is the part that changes how you shop.
Infrawatch named one brand outright, Coronium, as an established operator on the platform. The rest of the picture comes from ProxySmart itself. Its own site has published a partner roster, the brands that resell its stack, and those names include Coronium, XenProxy, WaterProxy, MobileProxyNow, RoxyProxy, RAWProxy, MyProxies, ProxyFella, ProxyStyler, ProxiedBy.Mobi, MountProxies, and KingsProxy, among others. Several of them, checked independently, run ordinary-looking websites with ordinary-looking checkout flows. You could compare three of them, pick the one with the cleanest dashboard, and never learn that all three hand your traffic to the same Minsk-built control panel.
The reason this matters is simple. The brand is the part they let you see, and the brand is the part that is different. Almost everything underneath it is shared.
| What each brand advertises | What ProxySmart hands all of them |
|---|---|
| Its own name, site, and pricing | One control-panel codebase, built in Minsk |
| "Private, dedicated 5G devices" | Shared device management and airplane-mode IP rotation |
| "Undetectable" traffic | The same OS-fingerprint spoofing profiles (macOS, iOS, Windows, Android) |
| A distinct provider you chose | One slot among roughly two dozen resellers on the same stack |
Why "brand diversity" is mostly a mirage
If you have read our map of who owns your proxy provider, this rhymes with it. There, a surprising share of "independent" proxy and VPN brands traced back to one Lithuanian venture builder. Here it is one Belarusian software stack. Different mechanism, same lesson: the variety on your shortlist is often thinner than it looks. Three practical consequences follow, and each one costs money.
Your redundancy might be fictional. Serious operators split traffic across two or three providers so that if one degrades, the others carry the load. If the two mobile providers you picked for that safety net are both reselling ProxySmart farms, you do not have two suppliers. You have one, billed twice. The day the shared stack has a bad day, both of your "independent" backups go down together.
Your detectability is shared. When a target site learns the tells of one ProxySmart exit, the same rotation timing, the same tunnel behavior, the same spoofed fingerprints, it has learned them for every brand on the stack at once. You also inherit the reputation of two dozen other brands' customers, whoever they are and whatever they are doing with it. We get into the mechanics in how websites detect proxies, and a shared software fingerprint is a gift to the defender.
Your neighbors are strangers. On a shared back end you share infrastructure with every other customer of every other brand riding it, including whoever is running the "large-scale fraud operations" Infrawatch flagged as highly likely. That is the same trap as the NetNut botnet takedown, where the problem was never the technology but the company you unknowingly kept on the same IPs.
This is not a botnet, and that is the point
It would be easy to file ProxySmart next to the NetNut case and call it another botnet. It is not, and the difference is worth getting right, because the honest version is more useful than the scary one.
The botnet cases, NetNut and Popa, or 911 S5 before them, were about hijacking real people's devices without consent, turning a stranger's smart TV or laptop into an exit node they never agreed to run. ProxySmart is a different animal. These are operator-run farms: someone bought the modems, bought the SIMs, and racked them in an apartment or a dedicated room. The person whose device it is, is the operator. The consent problem that defines the botnet stories is mostly absent here.
So the risk is not that you are renting a hijacked household. The risk is quieter, and for a buyer it is just as real. It is false diversity, the mirage above. It is shared detectability. And it is the carrier relationship: SIM farms run large banks of SIM cards in ways carriers do not intend, which is why researchers describe them as living in a legal grey area and reach for the "facilitating fraud" language rather than calling the proxies themselves a crime. The party whose terms are being stretched is the mobile network, not a family in the suburbs.
The meta-lesson is the one that connects all of these stories. With NetNut it was the sourcing. With the Tesonet map it was the ownership. With ProxySmart it is the software. In every case, the label on the box is not the product, and apparent choice hides a shared reality. A mobile proxy is only ever as trustworthy as the operation actually running it, and the brand name tells you almost nothing about that operation.
How to tell what is really behind your mobile proxy
You cannot fingerprint a provider's stack from the outside the way Infrawatch can. But you can ask the questions that separate an accountable operator from an anonymous reseller, and you can verify what you are handed.
Ask who runs the farm, and where. A provider that can name a city, a company, or a person is giving you something you can check. Here is the counterintuitive part: an operator who tells you "our modems are in Bordeaux" (a real example from this market) is more accountable than a nameless Telegram channel selling the same software, precisely because they attached a real place to their name. Disclosure is the trust signal. Shared tooling on its own is not the crime.
Ask whether the proxy is dedicated or shared, and if dedicated, dedicated to how many. "Dedicated" should mean the modem is yours and nobody else exits through it. If the answer is vague, treat the vagueness as the answer.
Watch for the shared tells. If two "different" brands both rotate with a three-second drop and reconnect, and both offer the same odd mix of tunnels, you are probably looking at the same stack in two skins. That is not proof, but it is a reason to stop treating them as independent options.
Verify the IP itself. Run any proxy you are given through a checker before you trust it. Our free proxy checker makes a real connection through the proxy and reports the exit location and the network it actually belongs to, so you can confirm the address sits on a genuine mobile carrier ASN (autonomous system number, the public ID of the network that owns an address block) rather than a datacenter wearing a mobile label. We put the rest of this into a full checklist in how to vet a proxy provider.
Where HProxy fits
We wrote this because the honest question it raises is one you should put to any mobile proxy seller, and that includes us: what am I actually buying, and who else is on it. We would rather answer it than dodge it.
Our mobile proxies are real 4G and 5G carrier IPs. You can take them shared, where you split a modem and its cost with other customers, or dedicated, where the modem is yours, with rotating or sticky sessions and rotation on a timer or on demand, and unlimited bandwidth on a flat monthly rate. You can verify any IP we hand you with the free checker before you believe a word of this page. If mobile is more trust than your target actually demands, our residential pools clear most defended jobs at $0.65/GB pay as you go, no KYC, with a balance that does not expire, and the what is a mobile proxy explainer walks the whole ladder so you buy the cheapest tier that works. The one thing we will not do is sell you a shortlist of "rivals" that are secretly the same thing.
Sources
- Help Net Security, Infrawatch SIM-farm proxy network investigation (April 21, 2026)
- Infrawatch, "Inside the Mobile Farm: The OEM Stack Powering US 4G/5G Proxy Networks"
- ProxySmart, published partner roster and response to third-party research
- TechRadar, "SIM farm as a service: how a Belarus-based network hijacked UK and US telcos to enable global fraud"
- Infosecurity Magazine, researchers link the ProxySmart platform to a wave of exposed SIM-farm panels
- GBHackers, "SIM Farm as a Service operation spanning 87 panels in 17 nations"