Solo Russian hacker built six-figure proxy empire by brute-forcing neglected routers, VPNs
Hacker modified Claude Code so it listens to all commands, uses any AI model, has full access, and runs without interruptions

Hacker building proxy empire. Image by by Cybernews, Shutterstock / leolintang, Elena Koromyslova
- A threat actor from Russia compromised more than 87,000 IPs by brute-forcing outdated VPN devices and weak credentials.
- The hacker rents its proxy network to multiple residential proxy platforms and over 20,000 end users, earning over $200,000 in two years.
- The attacker modified official Claude Code so it has all security disabled and accepts any large language model.
- Owners should replace outdated devices, restrict internet exposure, check for unauthorized proxies, and rotate exposed credentials.
A single hacker from Russia, LeakySensey, controls a massive 87,000 IP-wide residential proxy network and earns a fortune. The vulture leverages AI to hunt for exposed, end-of-life routers and other devices running deprecated VPN protocols, then rents access to the growing proxy stock.
The Cybernews research team discovered a massive underground proxy network comprising thousands of hijacked devices worldwide. We dubbed the threat actor LeakySensey after their primary domain and the ironic reality that their own infrastructure was both compromised and exposed.
A threat actor believed to be operating from Russia has compromised over 87,000 IPs and is reselling them to residential proxy providers and directly to proxy users via Telegram bots and various websites.
For comparison, the largest public anonymity network in the world, Tor, has over 11,000 IP addresses as active relays.
The operation masquerades as a legitimate Russian software development firm under the sensey24[.]ru frontpage.
It can be described as rudimentary yet highly effective: the attacker automates large-scale internet scans for exposed ports, followed by password-spraying attacks that leverage very weak credentials such as “admin” or “admin123”.
The campaign has been running for around two years and primarily targets devices running legacy VPN protocols, such as PPTP and L2TP, which have long been replaced by more secure alternatives. These devices include very old routers, dedicated VPN devices, network-attached storage (NAS), and other boxes.
Since 2024, the illicit service has processed over 24,000 transactions and received a total of $202,000 in proceeds.
“The brute-forcing campaign monetizes compromised hosts by deploying proxy software and renting access. The hacker’s malicious actions are beyond doubt. Yet it also highlights another issue – owners neglect security by leaving old or unprotected devices running, and malicious actors abuse their environments for cybercrime,” said Aras Nazarovas, information security researcher at Cybernews.
Exposed server brute-forcing exposed VPNs
Cybernews discovered the threat actor’s server on July 20th, 2026 – it was left completely open, unveiling the whole operation. The threat actor was running three separate projects.
The server leaked everything: malicious tools, agentic AI software, lists of clients, an inventory of IPs with working credentials, mostly admin/admin, and even logs that it itself got hacked by other cybercriminals.
The server’s contents also revealed that the operator maintained a parallel professional life – a web developer created websites for various Russian clients and hosted the source code, too.
LeakySensey uses specialized tools for brute-forcing, called PPTP API Server v3.2 and ipgo3, which integrate with payment processing.
The platform performs mass IP scanning – PPTP, L2TP, and SSH service discovery.
PPTP (Point-to-Point Tunneling Protocol) is an old, insecure VPN protocol from the past millennium, running on port 1723 – public scans by Censys reveal that 1.9 million hosts still expose this deprecated service.
Similarly, L2TP is another weak protocol, published in 1999, that is frequently misconfigured and poorly secured. Scans of port 1701, used by L2TP, return over 3 million exposed devices globally.
The threat actor’s proxy server inventory includes the following IPs:
- 63,000+ servers compromised via PPTP brute-forcing.
- 24,000+ servers compromised via L2TP brute-forcing.
- 24 servers compromised via SSH (Secure Shell) brute-forcing.
Only a fraction of the IPs were actively leveraged for residential proxy services. At the time of discovery, 17,858 IPs had proxy credentials configured with a status of “ready” or “connected”.
According to leaked database dumps, the service had over 56,000 users, with over 11,000 having linked Telegram accounts. Some of the illicit proxy users registered using their real names.
All the payments were centralized through the cryptomus.com platform, which supports over 100 various cryptocurrencies.
The server also exposed where LeakySensey resold the proxy access – one of the purchasers included a fairly well-known VPN service provider, VPN Pure. Other names included Pure Connect, Rich Proxy, Opm Proxy, For Friends, SkySocks, among others.
“This raises serious concerns over the ethics regarding how some providers source their proxy endpoints,” Nazarovas said.
While hacking others, LeakySensey had to deal with cybersecurity incidents of its own. Artifacts found on the server suggest that the infrastructure operator was solving multiple breaches.
“At some point, a Monero crypto-miner was deployed on the server hosting their git repository. The threat actor noticed it and removed 37 unauthorized users created on their git repository instance,” Nazarovas noted.
Another incident occurred when LeakySensey’s API keys – proxy credentials – were stolen, and other criminals started abusing its proxy service. Ultimately, the operator identified compromised API keys and attackers’ IP addresses.
Tradecraft: hacking Claude Code binaries
Claude Code did most of the hacking – not the official Anthropic release, but a heavily modified, “patched” version that enabled the attacker to bypass all built-in security and safety protocols.
The server hosted an automatic Claude Code Binary patching pipeline, consisting of five Python scripts for different phases: discovery, analysis, implementation, integrity verification, and distribution.
Whenever a new version of Claude Code is released, the pipeline triggers and applies multiple alterations:
- No trust dialog, full filesystem access without confirmation.
- Any model ID is accepted regardless of Anthropic’s allowlist.
- Subagents can target any provider (OpenAI, Google, etc.).
- Subagents can use OpenAI, Gemini, Qwen, or any model ID.
- No prompt-level safety filtering – any instruction accepted.
- Zero-click plan execution – plans auto-approve silently.
The hacked Claude Code binaries are then hosted as private NPM packages on the server for various architectures, including Apple, Windows, and Linux.
“Patched binaries allow clients to continuously work on tasks without any human supervision, bypass any client-side prompt safety checks, and allow for the use of any AI model, including locally hosted,” Nazarovas said.
The research team found 12 Antigravity accounts, 1 Claude account, 5 Codex accounts, and 2 Gemini accounts. They were all routed through a tool in the middle, CLI Proxy API, a project with over 50,000 stars on GitHub.
LeakySensey replaced the default Claude Code endpoints with this router, adding support for many different models, as well as additional functionality, such as modifying prompts to save costs – enforcing a ceiling for thinking budget, reasoning level, and other provider-specific constraints.
It appears that the threat actor uses legitimate accounts – email addresses did not appear in previous data breaches.
“What is interesting about this Claude Code deployant is that it uses a lot of LLM service accounts, likely designed to distribute AI agent requests to circumvent rate limits or increase throughput,” Nazarovas said.
“It is possible that the threat actor is selling this unshackled AI access as a service to other users.”
Cybernews disclosed these findings to Anthropic. Full source code for the Claude Code tool leaked earlier this year.
Server in France, operator likely Russian
The exposed infrastructure was hosted on OVH SAS, a French cloud computing company, using IP address 37[.]187[.]136[.]86[:]9999. This port is no longer active – the threat actor likely migrated the server.
Multiple artifacts suggest that the operator is located in Russia. All code comments, configuration files, LLM prompts, and outputs are in Russian, as is the storefront website.
But the server also hosted the Xray client binary, the primary censorship-circumvention tool used to bypass “great firewalls” in Russia and China. The threat actor also actively researched ways to bypass Russia’s censorship measures, including TSPU (Technical Means to Counter Threats, Russia's national internet censorship and traffic filtering system) and deep packet inspection (DPI).
The Sensey24 website didn’t list a legal entity name, but offered software engineering and IT consulting services.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
What do we learn from this?
The success of LeakySensey’s brute-forcing operation is an example of how the legacy tech debt effectively rolls out a red carpet for criminals.
PPTP is essentially broken, and even with strong passwords, the handshakes can be captured and brute-forced fairly cheaply.
L2TP has no built-in encryption and relies on another protocol, IPsec, for security. This means that instances are often left misconfigured.
Simply rotating usernames and passwords won’t be enough to protect the servers – it’s time to replace EOL devices or install newer software. Operators who are stuck with legacy systems should avoid exposing them on the open internet and segregate weak devices from the main trusted network.
Check if your data has been leaked
“Investigate these servers for indicators of compromise such as the presence of unauthorized Socks5 proxies and related artifacts,” Nazarovas suggests.
Any other credentials or secrets that might be exposed on compromised systems should be immediately rotated.
AI vendors, in this case Anthropic, should refactor the codebase to counter known patching and jailbreak methods and prevent future exploits.