Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks

Bad Sushi: China-Nexus Phishing Operation Shifts to (TL-2026-2471), also tracked as Bad Sushi, is a high-severity phishing campaign, first published 2026-09-12. It is linked to a China-nexus actor with low confidence, affects SBI SBI online banking customers (brand impersonation, not a software, maps to 10 MITRE ATT&CK techniques (T1090.002, T1204.001, T1566.002), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2471

Threat ID
TL-2026-2471
Also known as
Bad Sushi
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-12
Last reviewed
2026-09-12
Attribution confidence
LOW
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
financial services, banking, payment card services
Target regions
japan, taiwan
Detection rules
9
Indicators of compromise
24

Malware and tooling in Bad Sushi: China-Nexus Phishing Operation Shifts to

Malware and tooling: BadBox, Badbox / Badbox 2.0, Mobdro, Popa botnet, SystemBC - S9001, Tofsee, aisuru, kimwolf, vo1d, IPIDEA, Luna Proxy (lunaproxy.com), NetNut

A China-nexus phishing operation ('Bad Sushi') abandoned its dedicated China Telecom/China Unicom spam-sending subnets in April 2025 for rented residential-proxy infrastructure, jumping from single-country (Japan) targeting to 173 countries and 1.3M+ distinct source IPs within a month while impersonating Japanese financial brands SBI, JCB, and Hodaka.

How Bad Sushi: China-Nexus Phishing Operation Shifts to works

Since at least February 2023, Spamhaus has tracked a China-nexus phishing operation running dedicated spam cannons out of China Telecom (Fujian branch) and China Unicom subnets, primarily targeting Japanese internet users with phishing emails impersonating financial brands SBI, JCB, and Hodaka. Listing of those subnets in the Spamhaus Blocklist (SBL) suppressed deliverability, and in early April 2025 the operator pivoted its sending infrastructure to residential proxy networks built on insecure or pre-compromised consumer/IoT devices (the same abuse model documented in Spamhaus's earlier reporting on malicious proxy SDKs bundled with apps such as Mobdro and on compromised smart doorbells).

The pivot produced an immediate and dramatic scale increase: within the same month the operation was observed churning 3.5-4 million residential-proxy IPs at a rate of roughly 250,000 IPs per day, with Spamhaus noting that source-IP geography (Latin America in particular) 'lit up in Spamhaus's systems like a Christmas tree.' By May 2025 the campaign's source geography had expanded from a single country to 173 countries, with distinct source IPs growing from approximately 4,600 to over 1.3 million spread across 8,893 distinct Autonomous Systems. Alongside the infrastructure shift, the operator changed its email tradecraft: pre-shift messages used brand-impersonating HELO strings tied to the targeted financial institutions, while post-shift traffic consistently uses generic, non-existent HELOs — a reliable discriminator for defenders. Spamhaus additionally observed the operator (and adjacent spam senders) routing messages through legitimate email-forwarding services to 'wash' phishing mail and inherit better sender reputation for deliverability. Phishing landing pages moved from shared file-hosting networks to dedicated VPS instances on Alibaba Cloud and Tencent Cloud, fronted by .top-TLD redirector domains.

The operation demonstrates active, systematic evasion: proxy IPs are discarded within minutes of being added to Spamhaus datasets, and emissions have begun shifting from IPv4 to IPv6 address space, driving a corresponding surge in IPv6 listings. As of the October 2025 Spamhaus report, residential-proxy activity attributable to this and related campaigns accounted for roughly 66% of all Exploits Blocklist (XBL) listings (3.34 million) and 37% of Combined Spam Sources (CSS) listings (1.73 million). Spamhaus separately observed a similar Brazil-nexus campaign abusing ~500,000 residential-proxy IPs for brute-force login attempts in the weeks preceding the China-nexus pivot, and noted comparable phishing activity against Taiwanese internet users, suggesting a broader trend of China-nexus and adjacent actors adopting rented residential-proxy infrastructure as a blocklist-evasion primitive. Bitsight traces the underlying malware lineage to 'backconnect' residential-proxy malware active since at least 2016.

No specific actor group or malware family is named by Spamhaus for this operation; the 'Bad Sushi' designation is the vendor's campaign label, not a confirmed threat-actor identity. The residential-proxy pools abused for delivery are themselves built and monetized by a distinct criminal ecosystem that Spamhaus, Bitsight, and Google's Threat Intelligence Group (GTIG) have separately documented as the supply chain enabling this and comparable phishing/fraud campaigns. GTIG's January 2026 disruption of the IPIDEA conglomerate (operating 13 proxy/VPN storefront brands including Luna Proxy, 922 Proxy, ABC Proxy, and IPIDEA itself, all signed with Hong Kong shell-company code-signing certificates) found over 550 distinct threat groups — including China-, DPRK-, Iran-, and Russia-nexus clusters — using IPIDEA exit nodes in a single 7-day window for SaaS access, on-premises intrusions, and password-spray attacks, backed by roughly 7,400 Tier Two C2 servers, 3,075 malicious Windows PE hashes, and 600+ compromised Android apps (PacketSDK, CastarSDK, HexSDK, EarnSDK — the last a rebrand of prior Badbox 2.0 botnet infrastructure); Google, Cloudflare, and Lumen/Black Lotus Labs jointly disrupted the Tier One C2 domains and Google Play Protect blocked the malicious SDK-bearing apps. GTIG's July 2026 follow-up disruption of the separate NetNut platform (built on the ~2-million-device Popa botnet, seized with FBI and IRS-CI involvement) found 316 distinct threat clusters using suspected NetNut exit nodes in a single week and identified NetNut botnet-plugin components shared with Badbox 2.0 — evidence that the same underlying device-compromise supply chain feeds multiple competing residential-proxy storefronts. Those entities are recorded here as sourced infrastructure context establishing the delivery mechanism's provenance, not as confirmed operators of the Bad Sushi campaign itself.

MITRE ATT&CK techniques used in TL-2026-2471

Command and Control

T1090.002 External Proxy

Execution

T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.003 Virtual Private Server; T1583.005 Botnet; T1585.002 Email Accounts; T1585.003 Cloud Accounts

command-and-control

T1665 Hide Infrastructure

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Bad Sushi: China-Nexus Phishing Operation Shifts to

  • SBI — SBI online banking customers (brand impersonation, not a software vulnerability)
  • JCB — JCB payment-card customers (brand impersonation, not a software vulnerability)
  • Hodaka — Hodaka customers (brand impersonation, not a software vulnerability)

Remediation for Bad Sushi: China-Nexus Phishing Operation Shifts to

Immediate actions

  • Block or flag inbound SMTP sessions presenting generic, non-existent, or non-resolvable HELO/EHLO strings
  • Enforce SPF, DKIM, and DMARC on inbound mail flows to catch spoofed financial-brand senders
  • Disable or restrict automatic forwarding rules that accept unauthenticated inbound messages
  • Monitor for and block known IPIDEA/NetNut Tier One C2 domain patterns (e.g. *.packetsdk.xyz/.net/.io, holadns.com, *.hexsdk.com) as a proxy-supply-chain compromise indicator on managed endpoints

Workarounds

  • Identify and disconnect residential IoT devices (smart doorbells, streaming boxes, routers) exhibiting proxy-like outbound connection patterns
  • Rate-limit or geofence unexpected authentication/login traffic sourced from residential ASN space when it does not match customer geography

Longer-term hardening

  • Subscribe to and act on Spamhaus XBL/CSS/SBL and ZEN (not SBL alone) feeds, since PBL/ZEN coverage catches residential-proxy-sourced traffic that SBL-only filtering misses
  • Deploy egress monitoring for residential-proxy SDK / proxyware traffic patterns on managed endpoints and IoT device fleets
  • Educate Japanese financial-brand customers (SBI, JCB, Hodaka) on current lure patterns and .top-domain redirector abuse
  • Audit mobile fleets for applications bundling known proxy SDKs (PacketSDK, CastarSDK, HexSDK, EarnSDK) and rely on Google Play Protect enforcement signals

Timeline of Bad Sushi: China-Nexus Phishing Operation Shifts to

  • Bitsight documents 'backconnect' residential-proxy malware active since at least 2016, establishing the technical lineage for today's residential-proxy-as-a-service platforms.
  • Spamhaus documents smart doorbells and other IoT devices being compromised via malicious proxy SDKs bundled in apps such as Mobdro, seeding the residential-proxy ecosystem later abused for phishing distribution.
  • Spamhaus publishes a primer on the dangers of residential proxy networks, describing SDK-based device recruitment and its abuse for spam and network-penetration.
  • Spamhaus begins listing China Telecom (Fujian branch) and China Unicom subnets dedicated to phishing emissions in the Spamhaus Blocklist (SBL).
  • The China-nexus phishing operation ('Bad Sushi') shifts its distribution infrastructure from dedicated China Telecom/Unicom subnets to residential proxy networks, deploying 3.5-4 million IPs with roughly 250,000 IPs churned daily; source-IP geography including Latin America surges.
  • A separate Brazil-nexus campaign is observed abusing roughly 500,000 residential-proxy IPs for widespread brute-force login attempts, shortly before the China-nexus pivot.
  • Campaign source geography expands from a single country (Japan) to 173 countries; distinct source IPs grow from approximately 4,600 to over 1.3 million across 8,893 distinct Autonomous Systems.
  • Badbox/Badbox 2.0, Android supply-chain malware that fed residential-proxy device pools, is disrupted.
  • Spamhaus publishes 'Bad sushi: China-nexus phishers shift to residential proxies,' documenting the campaign; residential-proxy activity by this point accounts for roughly 66% of XBL listings (3.34M) and 37% of CSS listings (1.73M).
  • The Kimwolf botnet is documented infecting more than two million Android TV streaming devices via bundled residential-proxy software, expanding the pool of abusable proxy infrastructure.
  • Google Threat Intelligence Group (GTIG) publishes a disruption report on the IPIDEA conglomerate (Luna Proxy/922Proxy/IP2World/ABC Proxy and 9 other brands): over 550 distinct threat groups from China, DPRK, Iran, and Russia used IPIDEA exit nodes in a single 7-day window; GTIG identifies ~7,400 Tier Two C2 servers, 3,075 malicious Windows PE hashes, and 600+ compromised Android apps carrying PacketSDK/CastarSDK/HexSDK/EarnSDK; Cloudflare disrupts domain resolution and Google Play Protect blocks the malicious SDK-bearing apps, reducing IPIDEA's device pool by millions.
  • The FBI and IC3 publish a public service announcement warning device owners about residential-proxy network recruitment and abuse.
  • In a single week during June 2026, GTIG observes 316 distinct threat clusters, including cybercriminal and espionage groups, using suspected NetNut exit nodes; NetNut's network is estimated at 2 million-plus devices with botnet-plugin components shared with Badbox 2.0.
  • FBI, Google, Lumen, Shadowserver, and IRS Criminal Investigation seize the NetNut residential-proxy platform, built on the roughly two-million-device Popa botnet; Google separately disables Google accounts/services used for NetNut C2 and Play Protect disables apps carrying NetNut SDKs.

Sources cited for Bad Sushi: China-Nexus Phishing Operation Shifts to

More in phishing

Detection coverage for TL-2026-2471

As of 2026-09-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2471 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats