PLAINPROXIES
Providerproxy provider intelligence profile
- Website
plainproxies[.]com
PlainProxies is a German company operated by 3xK Tech GmbH which has been in operation since 2021. They are known for residential, ISP, datacenter, and unlimited proxy products and are considered a medium sized proxy provider. Synthient's Research Team has found proxy resellers or sales gateways such as VaultProxies and an IPRoyal-linked gateway to be providing access to PlainProxies. Shared gateway observations do not establish ownership, but these indirect channels highlight a potential risk due to limited downstream regulation or KYC controls.
PlainProxies is observed leveraging ByteConnect to obtain large swaths of IP addresses with the SDK being distributed across Windows, Android, Linux, and macOS. The ByteConnect SDK is classified as App Monetization and can be observed in TubeFetcher, Shieldway VPN, and ByteConnect desktop carriers.
Synthient's Research Team assigns a HIGH risk score to ByteConnect based on a randomized sample of consent practices observed in the wild.
Research record
| Field | Finding |
|---|---|
| Operator / jurisdiction | 3xK Tech GmbH · Germany |
| Operating history | Service operating since 2021; current terms updated March 2026 |
| Network type | Mixed residential, ISP, datacenter, and SDK-sourced proxy network |
| Verified channels | VaultProxies and an IPRoyal-linked gateway are observed sales or gateway relationships; shared infrastructure does not prove ownership |
| SDK / platforms | ByteConnect · Windows, Android, Linux, and macOS · app monetization |
| Consent review | HIGH risk · randomized corpus review; the public report does not state a defensible numeric sample size |
| Buyer KYC | PlainProxies says standard proxy access can begin without KYC; identity verification is required for restricted ports and sensitive destinations |
| Review dates | Static research updated 2026-09-28 · YARA and artifact review dated 2026-08-31 · use the live lookup for the latest network observation |
- Field
- Operator / jurisdiction
- Finding
- 3xK Tech GmbH · Germany
- Field
- Operating history
- Finding
- Service operating since 2021; current terms updated March 2026
- Field
- Network type
- Finding
- Mixed residential, ISP, datacenter, and SDK-sourced proxy network
- Field
- Verified channels
- Finding
- VaultProxies and an IPRoyal-linked gateway are observed sales or gateway relationships; shared infrastructure does not prove ownership
- Field
- SDK / platforms
- Finding
- ByteConnect · Windows, Android, Linux, and macOS · app monetization
- Field
- Consent review
- Finding
- HIGH risk · randomized corpus review; the public report does not state a defensible numeric sample size
- Field
- Buyer KYC
- Finding
- PlainProxies says standard proxy access can begin without KYC; identity verification is required for restricted ports and sensitive destinations
- Field
- Review dates
- Finding
- Static research updated 2026-09-28 · YARA and artifact review dated 2026-08-31 · use the live lookup for the latest network observation
Reseller Graph
The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.
Yara Rules
rule Proxyware_ByteConnect_MultiPlatform_ProxydCore
{
meta:
description = "ByteConnect proxyd Go core, the shared backconnect library behind every desktop white label"
provider = "Plainproxies"
sdk = "ByteConnect"
platform = "Windows PE/DLL, Linux ELF, macOS Mach-O"
variant = "proxyd-core"
category = "proxyware"
author = "Synthient"
date = "2026-08-31"
confidence = "high"
reference_pe_sha256 = "944652efa990212d21342f2cde6ba869aa495fd5bc8895e55de4cc4994d110d8"
reference_elf_sha256 = "9dfcadd5ff4222de72ce868b9793dc37551e1c812376dfef1b5f14f528b98be3"
reference_macho_sha256 = "31ffa7a92bb2edca8fd797ccdcdb48e04827d8dda74a08bbf12fb2ab49405817"
intel_family = "byteconnect"
strings:
/* Go build info names the vendor's own module as an in-development
dependency. It survives -trimpath and the stripped builds that carry
no package paths at all, so it anchors the whole family. */
$build_dep = "dep\tproxyd\t(devel)" ascii
$pkg_cmd = "proxyd/cmd/backconnect" ascii
$pkg_internal = "proxyd/internal/backconnect" ascii
$pkg_tunnel = "proxyd/internal/proxytunnel" ascii
$pkg_dnscache = "proxyd/internal/dnscache" ascii
/* Host-facing JNI surface of the desktop core. */
$jni_desktop = "Java_com_byteconnect_ByteconnectDesktop_" ascii
$url_eula = "https://byteconnect.io/sdk/eula" ascii
$url_consent = "https://byteconnect.io/sdk/web-data-collection" ascii
$url_meta = "https://new-endpoints.byteconnect.io/metaruntime" ascii
$gwd = "btcgwd.com" ascii
$pdb_desktop = "libdesktopbackconnect-" ascii
$pdb_lib = "libbackconnect-" ascii
condition:
(uint16(0) == 0x5a4d or uint32(0) == 0x464c457f or
uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or
uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca) and
filesize > 1MB and filesize < 64MB and
$build_dep and
1 of ($pkg_*, $jni_desktop, $url_*, $gwd, $pdb_*)
}This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.
Indicators of Compromise
File Hashes
| Type | Indicator | Context |
|---|---|---|
| SHA-256 | dd51447041c59013157dcaecd1eeded5047dabfed2dbab7cec31fb55d026527d | TubeFetcher v1.0.57 Linux AppImage |
| SHA-256 | a421fc7e026c2fb407ed8f0b99cee611ad5bf4bcc37a503cc9dfcd748086fefc | TubeFetcher Android v1.01 (com.byteconnect.tubefetcher), signed as BYTECONNECT LTD |
| SHA-256 | 944652efa990212d21342f2cde6ba869aa495fd5bc8895e55de4cc4994d110d8 | BYTECONNECT LTD-signed libdesktopbackconnect-amd64.dll; Shieldway VPN parent |
| SHA-256 | 9dfcadd5ff4222de72ce868b9793dc37551e1c812376dfef1b5f14f528b98be3 | Linux libdesktopbackconnect-amd64.so; Shieldway VPN parent |
| SHA-256 | 31ffa7a92bb2edca8fd797ccdcdb48e04827d8dda74a08bbf12fb2ab49405817 | macOS libdesktopbackconnect-amd64.dylib; TubeFetcher parent |
| SHA-256 | 803ef6caf2442cd6ab156c45655a24182cb2298ebd2b0d5c9325b806918ef64c | libbackconnect-amd64.dll signed by BYTECONNECT LTD |
| SHA-256 | 0014c99040a0b9b0b383afc3e2e7a80b7e94c0d26e3fc35efa55c493d345632e | TubeFetcher Android libbackconnect-android-v105.so |
| SHA-256 | 00e2be4a7223b027dd72849b64260fb4bd51d4778f05e60ed0ef40be527efa2d | BYTECONNECT LTD-signed nsis_tauri_utils.dll from TubeFetcher installers |
| SHA-256 | 0171fbe0d48989591f74beed21c0fec31b71371a542c3bbe6fbc6278b60058e9 | macOS libbackconnect-amd64.dylib |
| SHA-256 | ccd1147b95f64b64777236aaa64361a6b3b456f7a85eb08a16eacc6d8c8ff1a7 | Shieldway VPN v0.1.22 installer; VT compressed parent |
- Type
- SHA-256
- Context
- TubeFetcher v1.0.57 Linux AppImage
- Type
- SHA-256
- Context
- TubeFetcher Android v1.01 (
com.byteconnect.tubefetcher), signed as BYTECONNECT LTD
- Type
- SHA-256
- Context
- BYTECONNECT LTD-signed
libdesktopbackconnect-amd64.dll; Shieldway VPN parent
- Type
- SHA-256
- Context
- Linux
libdesktopbackconnect-amd64.so; Shieldway VPN parent
- Type
- SHA-256
- Context
- macOS
libdesktopbackconnect-amd64.dylib; TubeFetcher parent
- Type
- SHA-256
- Context
libbackconnect-amd64.dllsigned by BYTECONNECT LTD
- Type
- SHA-256
- Context
- TubeFetcher Android
libbackconnect-android-v105.so
- Type
- SHA-256
- Context
- BYTECONNECT LTD-signed
nsis_tauri_utils.dllfrom TubeFetcher installers
- Type
- SHA-256
- Context
- macOS
libbackconnect-amd64.dylib
- Type
- SHA-256
- Context
- Shieldway VPN v0.1.22 installer; VT compressed parent
Domains
| Type | Indicator | Context |
|---|---|---|
| Domain | byteconnect[.]independentdvpn[.]com | Tier 1 / bootstrap |
| Domain | byteconnect[.]io | VT-observed embedded ByteConnect domain |
| Domain | cdn[.]byteconnect[.]io:8080 | Tier 1 / bootstrap |
| Domain | new-endpoints[.]byteconnect[.]io | Tier 1 / bootstrap |
| Domain | btcgwd[.]com | Gateway-domain marker in the ByteConnect detection rule |
- Type
- Domain
- Indicator
- Context
- Tier 1 / bootstrap
- Type
- Domain
- Indicator
- Context
- VT-observed embedded ByteConnect domain
- Type
- Domain
- Indicator
- Context
- Tier 1 / bootstrap
- Type
- Domain
- Indicator
- Context
- Tier 1 / bootstrap
- Type
- Domain
- Indicator
- Context
- Gateway-domain marker in the ByteConnect detection rule
IP Addresses
| Type | Indicator | Context |
|---|---|---|
| IP address | 74[.]50[.]75[.]170:7649 | Backconnect relay |
| IP address | 74[.]50[.]77[.]126:7649 | Backconnect relay |
| IP address | 74[.]50[.]95[.]246:7649 | Backconnect relay |
| IP address | 74[.]119[.]149[.]7:7649 | Backconnect relay |
| IP address | 74[.]119[.]149[.]11:7649 | Backconnect relay |
| IP address | 74[.]119[.]149[.]13:7649 | Backconnect relay |
| IP address | 74[.]119[.]149[.]21:7649 | Backconnect relay |
| IP address | 74[.]119[.]149[.]26:7649 | Backconnect relay |
| IP address | 74[.]119[.]149[.]28:7649 | Backconnect relay |
| IP address | 74[.]119[.]149[.]32:7649 | Backconnect relay |
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
- Type
- IP address
- Indicator
- Context
- Backconnect relay
Research updated September 28, 2026. Last-seen observations change continuously; verify an address with the live lookup before acting.
Additional IOCs are hidden.
Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.
7-day activity
Illustrative preview
See the activity behind the provider.
Unlock daily events and unique IP trends to understand how this provider’s network changes over time.