Quote · The Journal.
The College Student Who Defeated the World’s Biggest Cyberweapon
Where this was said
Ben's Honeypot: The DIY Trap That Exposed KimWolf's Exploit
At 26:45 · chapter starts 26:38
Ben's big insight was simple but brilliant: if you want to catch something exploiting residential proxy devices, become one [1] — Benjamin Brundage "Ben Brundage installed IP Idea's software on an old Android phone via a pirated streaming app and monitored all traffic coming in and out. …" 26:30 . He installed IP Idea's software on a spare Android phone, downloaded from a website offering pirated streaming content, and built a monitoring setup to capture every byte of traffic coming in and out. Then he waited — balancing the experiment with studying for midterms. Within a week, one domain kept appearing in the traffic logs: xd.resi.to, an address with no obvious connection to IP Idea. Ben immediately flagged it. The domain turned out to be KimWolf's foothold: it was using the residential proxy's own access to the device to pivot from the open internet into the phone's local network — and from there, commandeer the device entirely. As Robert McMillan put it, it was like an Airbnb guest deciding to squat in the rental and rummage through all the locked closets. Ben brought his findings to Big Pipes, and together they confirmed that KimWolf had exploited a bug in IP Idea's own code to pull off this attack at scale.
KimWolf exploited a bug in IP Idea's residential proxy code to break into home networks and install DDoS malware on consumer devices. It was like an Airbnb guest deciding to squat in the rental and rummage through all the locked closets.