Essential storage keeps this site working and remembers your choice. Optional cookies are off until you allow them.

Meet the Synthient team

Loading available times…

Open Cal.com in a new tab

OXYLABS

Provider

proxy provider intelligence profile

Website
oxylabs[.]io

Oxylabs is a Lithuanian company operating since 2015. It is known for enterprise residential, mobile, and ISP proxies, scraper APIs, datasets, and large-scale web intelligence and is considered a large proxy provider. Synthient's Research Team has identified reseller relationships involving TorchProxies, WiredProxies, and ShieldProxies. These indirect sales channels may introduce risk where downstream regulation or KYC controls are limited.

Oxylabs is observed leveraging Honeygain to source IP addresses. Honeygain is distributed across Android, iOS, Windows, macOS, and Linux, is classified as Pay-Bandwidth and App Monetization, and has been observed in Cinema HQ, DooFlix, and RapidStreams.

Synthient's Research Team assigns a MEDIUM risk score to Honeygain based on a randomized sample of consent practices observed in the wild.

Reseller Graph

Observed provider, SDK, app, and reseller relationships described in this research profile.
Open full-size diagram

The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.


Yara Rules

rule Proxyware_Honeygain_Android_VoblerEngine
{
    meta:
        description = "Honeygain vobler/hgsdk Android QUIC exit-node engine"
        provider    = "Oxylabs"
        sdk         = "Honeygain"
        platform    = "Android DEX/APK"
        variant     = "vobler-hgsdk"
        category    = "proxyware"
        author      = "Synthient"
        date        = "2026-08-27"
        confidence  = "high"
        intel_family = "honeygain"
    strings:
        /* Kotlin data-class toString() prefix for the registration payload;
           only removable by dropping the data-class modifier. */
        $specs = "StaticSpecs(cid=" ascii

        $sdk_class = "Lcom/honeygain/hgsdk/HgSdk;" ascii
        $quic_pkg  = "com/honeygain/vobler/lib/sdk/quic" ascii
        $consent   = "Lcom/honeygain/hgsdk/ui/ConsentUiActivity;" ascii

        /* Protobuf enum value names shared with the server .proto: renaming
           them is a wire-compatibility break, so R8 leaves them intact. */
        $enum_connect = "FAILED_CONNECT_TO_TARGET" ascii
        $enum_resolve = "UNABLE_TO_RESOLVE_HOSTNAME" ascii
        $enum_limit   = "REQUEST_LIMIT_REACHED" ascii

        $prefs   = "fg-storage" ascii
        $consent_key = "didConsent" ascii
        $cid     = /HSDK(AN|AMZ|IOS)[A-Z0-9]{2,18}[0-9]{6}[A-Z0-9]{0,6}/ ascii
        $appsalt_class = "Lcom/appsalt/Appsalt;" ascii
        $appsalt_cid = "HASDKAN" ascii
        $appsalt_control = "connect.sdk.absolut.fit/ws/v2" ascii
    condition:
        (uint32(0) == 0x0a786564 or uint32(0) == 0x04034b50) and
        filesize < 300MB and
        1 of ($specs, $sdk_class, $quic_pkg) and
        2 of ($consent, $enum_connect, $enum_resolve, $enum_limit, $prefs, $consent_key, $cid) and
        none of ($appsalt_*)
}

This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.

Indicators of Compromise

File Hashes

Type
SHA-256
Context
Rave iOS carrier signed by Effective Enterprises Limited
Type
SHA-256
Context
Cinema HQ v5.3 (com.app.mlounge)
Type
SHA-256
Context
Honeygain libhgsdk.so, embedded in DooFlix and Rave packages
Type
SHA-256
Context
DooFlix / Honeygain SDK v6.7 (com.chatbot.robochatai); VT compressed parent
Type
SHA-256
Context
System Security embedded Android DEX
Type
SHA-256
Context
System Security v1.4.7 (in.one89.kids); VT compressed parent
Type
SHA-256
Context
RapidStreams embedded Android DEX
Type
SHA-256
Context
RapidStreams v4.8.1 (com.zentrix.app); VT compressed parent
Type
SHA-256
Context
ScareTV embedded Android DEX
Type
SHA-256
Context
ScareTV v6.0.0 (com.amazon.scaretv); VT compressed parent

Domains

Type
Domain
Context
Tier 1 / bootstrap
Type
Domain
Context
Tier 1 / bootstrap
Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay

IP Addresses

Type
IP address
Context
Backconnect Relays; Honeygain

Additional IOCs are hidden.

Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.

7-day activity

Full access

Illustrative preview

See the activity behind the provider.

Unlock daily events and unique IP trends to understand how this provider’s network changes over time.

Compare plans