MASKIFY
Providerproxy provider intelligence profile
- Website
maskify[.]su
Maskify is a Russia-oriented company which has been in operation since 2025. They are known for no-KYC access-token accounts, cryptocurrency payments, SOCKS/HTTP/UDP residential proxies, and reseller and white-label services and are considered a medium sized proxy provider. Synthient's Research Team has found proxy resellers such as BudgetProxy, VaultProxies, qProxy, and SousMarket to be providing access to Maskify. These indirect sales channels and the absence of customer KYC create a significant abuse and accountability risk.
Maskify is observed leveraging Earnify to source IP addresses, with the SDK distributed across Android. The Earnify SDK is classified as Malware and can be observed in Ambient Display Core and Android system-service packages. Recovered variants include system-component masquerading, boot persistence, IPFS-delivered updates, multi-hop residential proxying, remote shell execution, and TCP, UDP, TLS, SSH, and HTTP traffic-flooding handlers.
Synthient's Research Team assigns a HIGH risk score to Earnify based on a randomized sample of consent practices observed in the wild. The sampled packages did not present a clear user-facing bandwidth-sharing or reward flow and instead used Android system-service names, watchdogs, boot receivers, dynamic native payload replacement, and campaign-gated enrollment.
Research record
| Field | Finding |
|---|---|
| Operator / jurisdiction | Russia-oriented operation · legal operator not publicly identified in this profile |
| Operating history | Operating since 2025 |
| Network type | Residential and Android SDK-sourced proxy network supporting SOCKS, HTTP, and UDP |
| Verified channels | BudgetProxy, VaultProxies, qProxy, and SousMarket; reseller and white-label services advertised |
| SDK / platforms | Earnify · Android · malware-classified proxyware |
| Consent / KYC | HIGH consent-risk rating from a randomized review; numeric sample size is not public; no-KYC token accounts and cryptocurrency payments are advertised |
| Infrastructure | Ambient Display Core and Android system-service packages are observed hosts; domains, certificates, hashes, and IPs appear below |
| Review dates | Research updated 2026-09-28 · use the live lookup for current last-seen network observations |
- Field
- Operator / jurisdiction
- Finding
- Russia-oriented operation · legal operator not publicly identified in this profile
- Field
- Operating history
- Finding
- Operating since 2025
- Field
- Network type
- Finding
- Residential and Android SDK-sourced proxy network supporting SOCKS, HTTP, and UDP
- Field
- Verified channels
- Finding
- BudgetProxy, VaultProxies, qProxy, and SousMarket; reseller and white-label services advertised
- Field
- SDK / platforms
- Finding
- Earnify · Android · malware-classified proxyware
- Field
- Consent / KYC
- Finding
- HIGH consent-risk rating from a randomized review; numeric sample size is not public; no-KYC token accounts and cryptocurrency payments are advertised
- Field
- Infrastructure
- Finding
- Ambient Display Core and Android system-service packages are observed hosts; domains, certificates, hashes, and IPs appear below
- Field
- Review dates
- Finding
- Research updated 2026-09-28 · use the live lookup for current last-seen network observations
Reseller Graph
The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.
Yara Rules
rule Proxyware_Earnify_Android_NativeSDK
{
meta:
description = "Earnify/Maskify Android Rust/QUIC proxy SDK"
provider = "Maskify"
sdk = "Earnify"
category = "proxyware"
author = "Synthient"
date = "2026-08-31"
confidence = "high"
platform = "android"
variant = "native-sdk"
intel_family = "earnify"
strings:
$jni_1 = "Java_io_earnify_sdk_EarnifySDK_nativeInit" ascii fullword
$jni_2 = "Java_io_earnify_sdk_EarnifySDK_nativeStart" ascii fullword
$jni_3 = "Java_io_earnify_sdk_EarnifySDK_nativeGetBytesProxied" ascii fullword
$abi_1 = "earnify_sdk_init" ascii fullword
$abi_2 = "earnify_sdk_start" ascii fullword
$abi_3 = "earnify_sdk_stats" ascii fullword
$abi_4 = "earnify_sdk_set_consent" ascii fullword
$session_1 = "expected control stream from server" ascii
$session_2 = "expected ConnectToServer" ascii
$session_3 = "relayserver did not assign client_id" ascii
$session_4 = "session auth rejected" ascii
$mesh_1 = "peer exchange: truncated node_id" ascii
$mesh_2 = "no resolver set for this ENS name" ascii
$mesh_3 = "IPFS seed resolution not yet implemented" ascii
$mesh_4 = "Za Rodinu mesh config found" ascii
$relay_1 = "earnify-core/src/tunnel.rs" ascii
$relay_2 = "TCP connected, relaying" ascii
$relay_3 = "UDP connected, relaying" ascii
$relay_4 = "received ConnectToServer signal" ascii
condition:
uint32(0) == 0x464c457f and filesize > 1MB and filesize < 5MB and
2 of ($jni_*) and 3 of ($abi_*) and 2 of ($session_*) and
(2 of ($mesh_*) or all of ($relay_*))
}This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.
Indicators of Compromise
File Hashes
- Type
- SHA-256
- Context
- Unstripped Earnify Rust/QUIC native SDK
- Type
- SHA-256
- Context
- Stripped Android Earnify SDK
- Type
- SHA-256
- Context
- Earnify Android native library version 1.0.0
- Type
- SHA-256
- Context
- Earnify Android native library version 3.1.0
- Type
- SHA-256
- Context
com.android.server.ambientAPK
- Type
- SHA-256
- Context
- Earnify Android loader DEX
- Type
- SHA-256
- Context
- Guardian downloader and launcher DEX
- Type
- SHA-256
- Context
- Persistent guardian ELF
- Type
- SHA-256
- Context
- Confirmed files; Earnify
- Type
- SHA-256
- Context
- Confirmed files; Earnify
Domains
| Type | Indicator | Context |
|---|---|---|
| Domain | maskify[.]su | Commercial proxy provider |
| Domain | earnify[.]su | Declared bandwidth-sharing network |
| Domain | empty-violet-63e1[.]maskify[.]workers[.]dev | Earnify update and fallback service |
| Domain | aryasingh[.]xmjrratudgn8qs1hmbvoufhocmb7cijlizt62ajpvth2xphazo8wflj5[.]su | Shared gateway alias used by Maskify, BudgetProxy, and VaultProxies |
| Domain | myproxy[.]budgetproxy[.]com | BudgetProxy gateway sharing the Maskify alias and three rotated IPs |
| Domain | russianaltushkawantsdickinside[.]eth | ENS dead-drop used for server and update discovery |
| Domain | resi-gb[.]vaultproxies[.]com | VaultProxies gateway sharing the Maskify alias and four rotated IPs |
| Domain | xv[.]qproxy[.]pro | qProxy gateway sharing four Maskify gateway IPs |
| Domain | proxy[.]sousmarketfranchize[.]shop | Historical direct CNAME to resi.maskify.su |
- Type
- Domain
- Indicator
- Context
- Commercial proxy provider
- Type
- Domain
- Indicator
- Context
- Declared bandwidth-sharing network
- Type
- Domain
- Context
- Earnify update and fallback service
- Type
- Domain
- Context
- Shared gateway alias used by Maskify, BudgetProxy, and VaultProxies
- Type
- Domain
- Indicator
- Context
- BudgetProxy gateway sharing the Maskify alias and three rotated IPs
- Type
- Domain
- Indicator
- Context
- ENS dead-drop used for server and update discovery
- Type
- Domain
- Indicator
- Context
- VaultProxies gateway sharing the Maskify alias and four rotated IPs
- Type
- Domain
- Indicator
- Context
- qProxy gateway sharing four Maskify gateway IPs
- Type
- Domain
- Indicator
- Context
- Historical direct CNAME to
resi.maskify.su
IP Addresses
| Type | Indicator | Context |
|---|---|---|
| IP address | 45[.]88[.]228[.]19 | Current resi.maskify.su gateway observed by VirusTotal |
| IP address | 37[.]49[.]224[.]199 | Rotated Maskify gateway |
| IP address | 194[.]46[.]59[.]250 | Maskify, VaultProxies, and qProxy gateway overlap |
| IP address | 164[.]37[.]110[.]202 | Maskify, VaultProxies, qProxy, and SousMarket gateway overlap |
| IP address | 205[.]237[.]104[.]189 | Maskify, VaultProxies, qProxy, and SousMarket gateway overlap |
| IP address | 37[.]49[.]224[.]110 | Maskify and BudgetProxy gateway overlap |
| IP address | 164[.]37[.]101[.]2 | Maskify, BudgetProxy, VaultProxies, qProxy, and SousMarket gateway overlap |
| IP address | 172[.]65[.]216[.]193 | Historical Maskify gateway; shared hosting, not reseller evidence |
| IP address | 37[.]49[.]230[.]40 | Historical Maskify gateway shared by BudgetProxy and other proxy storefronts |
| IP address | 172[.]65[.]224[.]137 | Historical Maskify gateway; shared hosting, not reseller evidence |
- Type
- IP address
- Indicator
- Context
- Current
resi.maskify.sugateway observed by VirusTotal
- Type
- IP address
- Indicator
- Context
- Rotated Maskify gateway
- Type
- IP address
- Indicator
- Context
- Maskify, VaultProxies, and qProxy gateway overlap
- Type
- IP address
- Indicator
- Context
- Maskify, VaultProxies, qProxy, and SousMarket gateway overlap
- Type
- IP address
- Indicator
- Context
- Maskify, VaultProxies, qProxy, and SousMarket gateway overlap
- Type
- IP address
- Indicator
- Context
- Maskify and BudgetProxy gateway overlap
- Type
- IP address
- Indicator
- Context
- Maskify, BudgetProxy, VaultProxies, qProxy, and SousMarket gateway overlap
- Type
- IP address
- Indicator
- Context
- Historical Maskify gateway; shared hosting, not reseller evidence
- Type
- IP address
- Indicator
- Context
- Historical Maskify gateway shared by BudgetProxy and other proxy storefronts
- Type
- IP address
- Indicator
- Context
- Historical Maskify gateway; shared hosting, not reseller evidence
Research updated September 28, 2026. Last-seen observations change continuously; verify an address with the live lookup before acting.
Additional IOCs are hidden.
Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.
7-day activity
Illustrative preview
See the activity behind the provider.
Unlock daily events and unique IP trends to understand how this provider’s network changes over time.