Essential storage keeps this site working and remembers your choice. Optional cookies are off until you allow them.

Meet the Synthient team

Loading available times…

Open Cal.com in a new tab

MASKIFY

Provider

proxy provider intelligence profile

Website
maskify[.]su

Maskify is a Russia-oriented company which has been in operation since 2025. They are known for no-KYC access-token accounts, cryptocurrency payments, SOCKS/HTTP/UDP residential proxies, and reseller and white-label services and are considered a medium sized proxy provider. Synthient's Research Team has found proxy resellers such as BudgetProxy, VaultProxies, qProxy, and SousMarket to be providing access to Maskify. These indirect sales channels and the absence of customer KYC create a significant abuse and accountability risk.

Maskify is observed leveraging Earnify to source IP addresses, with the SDK distributed across Android. The Earnify SDK is classified as Malware and can be observed in Ambient Display Core and Android system-service packages. Recovered variants include system-component masquerading, boot persistence, IPFS-delivered updates, multi-hop residential proxying, remote shell execution, and TCP, UDP, TLS, SSH, and HTTP traffic-flooding handlers.

Synthient's Research Team assigns a HIGH risk score to Earnify based on a randomized sample of consent practices observed in the wild. The sampled packages did not present a clear user-facing bandwidth-sharing or reward flow and instead used Android system-service names, watchdogs, boot receivers, dynamic native payload replacement, and campaign-gated enrollment.

Research record

Field
Operator / jurisdiction
Finding
Russia-oriented operation · legal operator not publicly identified in this profile
Field
Operating history
Finding
Operating since 2025
Field
Network type
Finding
Residential and Android SDK-sourced proxy network supporting SOCKS, HTTP, and UDP
Field
Verified channels
Finding
BudgetProxy, VaultProxies, qProxy, and SousMarket; reseller and white-label services advertised
Field
SDK / platforms
Finding
Earnify · Android · malware-classified proxyware
Field
Consent / KYC
Finding
HIGH consent-risk rating from a randomized review; numeric sample size is not public; no-KYC token accounts and cryptocurrency payments are advertised
Field
Infrastructure
Finding
Ambient Display Core and Android system-service packages are observed hosts; domains, certificates, hashes, and IPs appear below
Field
Review dates
Finding
Research updated 2026-09-28 · use the live lookup for current last-seen network observations

Reseller Graph

Observed provider, SDK, app, and reseller relationships described in this research profile.
Open full-size diagram

The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.


Yara Rules

rule Proxyware_Earnify_Android_NativeSDK
{
    meta:
        description = "Earnify/Maskify Android Rust/QUIC proxy SDK"
        provider    = "Maskify"
        sdk         = "Earnify"
        category    = "proxyware"
        author      = "Synthient"
        date        = "2026-08-31"
        confidence  = "high"
        platform    = "android"
        variant     = "native-sdk"
        intel_family = "earnify"
    strings:
        $jni_1 = "Java_io_earnify_sdk_EarnifySDK_nativeInit" ascii fullword
        $jni_2 = "Java_io_earnify_sdk_EarnifySDK_nativeStart" ascii fullword
        $jni_3 = "Java_io_earnify_sdk_EarnifySDK_nativeGetBytesProxied" ascii fullword
        $abi_1 = "earnify_sdk_init" ascii fullword
        $abi_2 = "earnify_sdk_start" ascii fullword
        $abi_3 = "earnify_sdk_stats" ascii fullword
        $abi_4 = "earnify_sdk_set_consent" ascii fullword
        $session_1 = "expected control stream from server" ascii
        $session_2 = "expected ConnectToServer" ascii
        $session_3 = "relayserver did not assign client_id" ascii
        $session_4 = "session auth rejected" ascii
        $mesh_1 = "peer exchange: truncated node_id" ascii
        $mesh_2 = "no resolver set for this ENS name" ascii
        $mesh_3 = "IPFS seed resolution not yet implemented" ascii
        $mesh_4 = "Za Rodinu mesh config found" ascii
        $relay_1 = "earnify-core/src/tunnel.rs" ascii
        $relay_2 = "TCP connected, relaying" ascii
        $relay_3 = "UDP connected, relaying" ascii
        $relay_4 = "received ConnectToServer signal" ascii
    condition:
        uint32(0) == 0x464c457f and filesize > 1MB and filesize < 5MB and
        2 of ($jni_*) and 3 of ($abi_*) and 2 of ($session_*) and
        (2 of ($mesh_*) or all of ($relay_*))
}

This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.

Indicators of Compromise

File Hashes

Type
SHA-256
Context
Unstripped Earnify Rust/QUIC native SDK
Type
SHA-256
Context
Stripped Android Earnify SDK
Type
SHA-256
Context
Earnify Android native library version 1.0.0
Type
SHA-256
Context
Earnify Android native library version 3.1.0
Type
SHA-256
Context
com.android.server.ambient APK
Type
SHA-256
Context
Earnify Android loader DEX
Type
SHA-256
Context
Guardian downloader and launcher DEX
Type
SHA-256
Context
Persistent guardian ELF
Type
SHA-256
Context
Confirmed files; Earnify
Type
SHA-256
Context
Confirmed files; Earnify

Domains

Type
Domain
Indicator
Context
Commercial proxy provider
Type
Domain
Indicator
Context
Declared bandwidth-sharing network
Type
Domain
Context
Earnify update and fallback service
Type
Domain
Context
Shared gateway alias used by Maskify, BudgetProxy, and VaultProxies
Type
Domain
Context
BudgetProxy gateway sharing the Maskify alias and three rotated IPs
Type
Domain
Context
ENS dead-drop used for server and update discovery
Type
Domain
Context
VaultProxies gateway sharing the Maskify alias and four rotated IPs
Type
Domain
Context
qProxy gateway sharing four Maskify gateway IPs
Type
Domain
Context
Historical direct CNAME to resi.maskify.su

IP Addresses

Type
IP address
Context
Current resi.maskify.su gateway observed by VirusTotal
Type
IP address
Context
Rotated Maskify gateway
Type
IP address
Context
Maskify, VaultProxies, and qProxy gateway overlap
Type
IP address
Context
Maskify, VaultProxies, qProxy, and SousMarket gateway overlap
Type
IP address
Context
Maskify, VaultProxies, qProxy, and SousMarket gateway overlap
Type
IP address
Context
Maskify and BudgetProxy gateway overlap
Type
IP address
Context
Maskify, BudgetProxy, VaultProxies, qProxy, and SousMarket gateway overlap
Type
IP address
Context
Historical Maskify gateway; shared hosting, not reseller evidence
Type
IP address
Context
Historical Maskify gateway shared by BudgetProxy and other proxy storefronts
Type
IP address
Context
Historical Maskify gateway; shared hosting, not reseller evidence

Research updated September 28, 2026. Last-seen observations change continuously; verify an address with the live lookup before acting.

Additional IOCs are hidden.

Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.

7-day activity

Full access

Illustrative preview

See the activity behind the provider.

Unlock daily events and unique IP trends to understand how this provider’s network changes over time.

Compare plans