Essential storage keeps this site working and remembers your choice. Optional cookies are off until you allow them.

Meet the Synthient team

Loading available times…

Open Cal.com in a new tab
Skip to content

PACKETSTREAM

Provider
Website
packetstream[.]io

PacketStream is a United States company which has been in operation since 2018. They are known for their low-cost peer-to-peer residential proxy network and direct paid bandwidth-sharing client and are considered a small sized proxy provider. Synthient's Research Team has found proxy resellers such as HydraProxy, TorchProxies, and WiredProxies to be providing access to PacketStream. These indirect sales channels highlight a potential risk due to limited downstream regulation or KYC controls.

PacketStream is observed leveraging its PacketStream client to obtain large swaths of IP addresses. PacketStream is distributed across Windows, Linux, and macOS, is classified as Pay-Bandwidth, and has been observed in the PacketStream Windows, Linux, and macOS clients.

Synthient's Research Team assigns a LOW risk score to PacketStream based on a randomized sample of consent practices observed in the wild.

Reseller Graph

Observed provider, SDK, app, and reseller relationships described in this research profile.
Open full-size diagram

The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.


Yara Rules

rule Proxyware_Packetstream_MultiPlatform_PsclientCore
{
    meta:
        description = "PacketStream Packeter Go exit-node core for Linux, Windows, and macOS"
        provider    = "Packetstream"
        sdk         = "Packetstream"
        platform    = "Linux ELF, Windows PE, macOS Mach-O"
        variant     = "psclient"
        category    = "proxyware"
        author      = "Synthient"
        date        = "2026-08-27"
        confidence  = "high"
        intel_family = "packetstream-packeter"
    strings:
        $module = "github.com/packetstream/ecosystem/exit-node/core" ascii

        $api    = "https://api.packetstream.io/exitnode/ipinfo/" ascii
        $master = "client.packetstream.io" ascii
        $update = "client-dl.packetstream.io/dist/version.json.asc" ascii

        $auth   = "PS_CLIENT_AUTH" ascii
        $docker = "PS_IS_DOCKER" ascii
        $http   = "HTTP/1.1 200 Connection Established\r\nProxy-agent: Proxy\r\n\r\n" ascii
    condition:
        (uint32(0) == 0x464c457f or uint16(0) == 0x5a4d or
         uint32(0) == 0xfeedfacf) and
        filesize > 1MB and filesize < 80MB and
        $module and
        3 of ($api, $master, $update, $auth, $docker, $http)
}

This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.

Indicators of Compromise

File Hashes

Type
SHA-256
Context
psclient.exe signed by PacketStream Inc
Type
SHA-256
Context
PacketStream psclient ELF
Type
SHA-256
Context
psclient.exe.traybak signed by PacketStream Inc
Type
SHA-256
Context
Unnamed PacketStream ELF client component
Type
SHA-256
Context
Confirmed files; Packetstream
Type
SHA-256
Context
Confirmed files; Packetstream
Type
SHA-256
Context
Confirmed files; Packetstream
Type
SHA-256
Context
Confirmed files; Packetstream
Type
SHA-256
Context
Confirmed files; Packetstream
Type
SHA-256
Context
Confirmed files; Packetstream

Domains

Type
Domain
Context
Backconnect relay
Type
Domain
Context
Backconnect relay
Type
Domain
Context
VT-observed client API endpoint
Type
Domain
Context
VT-observed client download endpoint

IP Addresses

No confirmed ip addresses are included in the reviewed source corpus.

Additional IOCs are hidden.

Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.

7-day activity

Full access

Illustrative preview

See the activity behind the provider.

Unlock daily events and unique IP trends to understand how this provider’s network changes over time.

Compare plans