Essential storage keeps this site working and remembers your choice. Optional cookies are off until you allow them.

Meet the Synthient team

Loading available times…

Open Cal.com in a new tab

PLAINPROXIES

Provider

proxy provider intelligence profile

Website
plainproxies[.]com

PlainProxies is a German company operated by 3xK Tech GmbH which has been in operation since 2021. They are known for residential, ISP, datacenter, and unlimited proxy products and are considered a medium sized proxy provider. Synthient's Research Team has found proxy resellers or sales gateways such as VaultProxies and an IPRoyal-linked gateway to be providing access to PlainProxies. Shared gateway observations do not establish ownership, but these indirect channels highlight a potential risk due to limited downstream regulation or KYC controls.

PlainProxies is observed leveraging ByteConnect to obtain large swaths of IP addresses with the SDK being distributed across Windows, Android, Linux, and macOS. The ByteConnect SDK is classified as App Monetization and can be observed in TubeFetcher, Shieldway VPN, and ByteConnect desktop carriers.

Synthient's Research Team assigns a HIGH risk score to ByteConnect based on a randomized sample of consent practices observed in the wild.

Research record

Field
Operator / jurisdiction
Finding
3xK Tech GmbH · Germany
Field
Operating history
Finding
Service operating since 2021; current terms updated March 2026
Field
Network type
Finding
Mixed residential, ISP, datacenter, and SDK-sourced proxy network
Field
Verified channels
Finding
VaultProxies and an IPRoyal-linked gateway are observed sales or gateway relationships; shared infrastructure does not prove ownership
Field
SDK / platforms
Finding
ByteConnect · Windows, Android, Linux, and macOS · app monetization
Field
Consent review
Finding
HIGH risk · randomized corpus review; the public report does not state a defensible numeric sample size
Field
Buyer KYC
Finding
PlainProxies says standard proxy access can begin without KYC; identity verification is required for restricted ports and sensitive destinations
Field
Review dates
Finding
Static research updated 2026-09-28 · YARA and artifact review dated 2026-08-31 · use the live lookup for the latest network observation

Reseller Graph

Observed provider, SDK, app, and reseller relationships described in this research profile.
Open full-size diagram

The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.


Yara Rules

rule Proxyware_ByteConnect_MultiPlatform_ProxydCore
{
    meta:
        description = "ByteConnect proxyd Go core, the shared backconnect library behind every desktop white label"
        provider    = "Plainproxies"
        sdk         = "ByteConnect"
        platform    = "Windows PE/DLL, Linux ELF, macOS Mach-O"
        variant     = "proxyd-core"
        category    = "proxyware"
        author      = "Synthient"
        date        = "2026-08-31"
        confidence  = "high"
        reference_pe_sha256 = "944652efa990212d21342f2cde6ba869aa495fd5bc8895e55de4cc4994d110d8"
        reference_elf_sha256 = "9dfcadd5ff4222de72ce868b9793dc37551e1c812376dfef1b5f14f528b98be3"
        reference_macho_sha256 = "31ffa7a92bb2edca8fd797ccdcdb48e04827d8dda74a08bbf12fb2ab49405817"
        intel_family = "byteconnect"
    strings:
        /* Go build info names the vendor's own module as an in-development
           dependency. It survives -trimpath and the stripped builds that carry
           no package paths at all, so it anchors the whole family. */
        $build_dep = "dep\tproxyd\t(devel)" ascii

        $pkg_cmd      = "proxyd/cmd/backconnect" ascii
        $pkg_internal = "proxyd/internal/backconnect" ascii
        $pkg_tunnel   = "proxyd/internal/proxytunnel" ascii
        $pkg_dnscache = "proxyd/internal/dnscache" ascii

        /* Host-facing JNI surface of the desktop core. */
        $jni_desktop = "Java_com_byteconnect_ByteconnectDesktop_" ascii

        $url_eula    = "https://byteconnect.io/sdk/eula" ascii
        $url_consent = "https://byteconnect.io/sdk/web-data-collection" ascii
        $url_meta    = "https://new-endpoints.byteconnect.io/metaruntime" ascii
        $gwd         = "btcgwd.com" ascii

        $pdb_desktop = "libdesktopbackconnect-" ascii
        $pdb_lib     = "libbackconnect-" ascii
    condition:
        (uint16(0) == 0x5a4d or uint32(0) == 0x464c457f or
         uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or
         uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca) and
        filesize > 1MB and filesize < 64MB and
        $build_dep and
        1 of ($pkg_*, $jni_desktop, $url_*, $gwd, $pdb_*)
}

This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.

Indicators of Compromise

File Hashes

Type
SHA-256
Context
TubeFetcher v1.0.57 Linux AppImage
Type
SHA-256
Context
TubeFetcher Android v1.01 (com.byteconnect.tubefetcher), signed as BYTECONNECT LTD
Type
SHA-256
Context
BYTECONNECT LTD-signed libdesktopbackconnect-amd64.dll; Shieldway VPN parent
Type
SHA-256
Context
Linux libdesktopbackconnect-amd64.so; Shieldway VPN parent
Type
SHA-256
Context
macOS libdesktopbackconnect-amd64.dylib; TubeFetcher parent
Type
SHA-256
Context
libbackconnect-amd64.dll signed by BYTECONNECT LTD
Type
SHA-256
Context
TubeFetcher Android libbackconnect-android-v105.so
Type
SHA-256
Context
BYTECONNECT LTD-signed nsis_tauri_utils.dll from TubeFetcher installers
Type
SHA-256
Context
macOS libbackconnect-amd64.dylib
Type
SHA-256
Context
Shieldway VPN v0.1.22 installer; VT compressed parent

Domains

Type
Domain
Context
Tier 1 / bootstrap
Type
Domain
Context
VT-observed embedded ByteConnect domain
Type
Domain
Context
Tier 1 / bootstrap
Type
Domain
Context
Tier 1 / bootstrap
Type
Domain
Indicator
Context
Gateway-domain marker in the ByteConnect detection rule

IP Addresses

Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay
Type
IP address
Context
Backconnect relay

Research updated September 28, 2026. Last-seen observations change continuously; verify an address with the live lookup before acting.

Additional IOCs are hidden.

Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.

7-day activity

Full access

Illustrative preview

See the activity behind the provider.

Unlock daily events and unique IP trends to understand how this provider’s network changes over time.

Compare plans