Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks
Bad Sushi: China-Nexus Phishing Operation Shifts to (TL-2026-2471), also tracked as Bad Sushi, is a high-severity phishing campaign, first published 2026-09-12. It is linked to a China-nexus actor with low confidence, affects SBI SBI online banking customers (brand impersonation, not a software, maps to 10 MITRE ATT&CK techniques (T1090.002, T1204.001, T1566.002), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-2471
- Threat ID
- TL-2026-2471
- Also known as
- Bad Sushi
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-12
- Last reviewed
- 2026-09-12
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, payment card services
- Target regions
- japan, taiwan
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Bad Sushi: China-Nexus Phishing Operation Shifts to
Malware and tooling: BadBox, Badbox / Badbox 2.0, Mobdro, Popa botnet, SystemBC - S9001, Tofsee, aisuru, kimwolf, vo1d, IPIDEA, Luna Proxy (lunaproxy.com), NetNut
A China-nexus phishing operation ('Bad Sushi') abandoned its dedicated China Telecom/China Unicom spam-sending subnets in April 2025 for rented residential-proxy infrastructure, jumping from single-country (Japan) targeting to 173 countries and 1.3M+ distinct source IPs within a month while impersonating Japanese financial brands SBI, JCB, and Hodaka.
How Bad Sushi: China-Nexus Phishing Operation Shifts to works
Since at least February 2023, Spamhaus has tracked a China-nexus phishing operation running dedicated spam cannons out of China Telecom (Fujian branch) and China Unicom subnets, primarily targeting Japanese internet users with phishing emails impersonating financial brands SBI, JCB, and Hodaka. Listing of those subnets in the Spamhaus Blocklist (SBL) suppressed deliverability, and in early April 2025 the operator pivoted its sending infrastructure to residential proxy networks built on insecure or pre-compromised consumer/IoT devices (the same abuse model documented in Spamhaus's earlier reporting on malicious proxy SDKs bundled with apps such as Mobdro and on compromised smart doorbells).
The pivot produced an immediate and dramatic scale increase: within the same month the operation was observed churning 3.5-4 million residential-proxy IPs at a rate of roughly 250,000 IPs per day, with Spamhaus noting that source-IP geography (Latin America in particular) 'lit up in Spamhaus's systems like a Christmas tree.' By May 2025 the campaign's source geography had expanded from a single country to 173 countries, with distinct source IPs growing from approximately 4,600 to over 1.3 million spread across 8,893 distinct Autonomous Systems. Alongside the infrastructure shift, the operator changed its email tradecraft: pre-shift messages used brand-impersonating HELO strings tied to the targeted financial institutions, while post-shift traffic consistently uses generic, non-existent HELOs — a reliable discriminator for defenders. Spamhaus additionally observed the operator (and adjacent spam senders) routing messages through legitimate email-forwarding services to 'wash' phishing mail and inherit better sender reputation for deliverability. Phishing landing pages moved from shared file-hosting networks to dedicated VPS instances on Alibaba Cloud and Tencent Cloud, fronted by .top-TLD redirector domains.
The operation demonstrates active, systematic evasion: proxy IPs are discarded within minutes of being added to Spamhaus datasets, and emissions have begun shifting from IPv4 to IPv6 address space, driving a corresponding surge in IPv6 listings. As of the October 2025 Spamhaus report, residential-proxy activity attributable to this and related campaigns accounted for roughly 66% of all Exploits Blocklist (XBL) listings (3.34 million) and 37% of Combined Spam Sources (CSS) listings (1.73 million). Spamhaus separately observed a similar Brazil-nexus campaign abusing ~500,000 residential-proxy IPs for brute-force login attempts in the weeks preceding the China-nexus pivot, and noted comparable phishing activity against Taiwanese internet users, suggesting a broader trend of China-nexus and adjacent actors adopting rented residential-proxy infrastructure as a blocklist-evasion primitive. Bitsight traces the underlying malware lineage to 'backconnect' residential-proxy malware active since at least 2016.
No specific actor group or malware family is named by Spamhaus for this operation; the 'Bad Sushi' designation is the vendor's campaign label, not a confirmed threat-actor identity. The residential-proxy pools abused for delivery are themselves built and monetized by a distinct criminal ecosystem that Spamhaus, Bitsight, and Google's Threat Intelligence Group (GTIG) have separately documented as the supply chain enabling this and comparable phishing/fraud campaigns. GTIG's January 2026 disruption of the IPIDEA conglomerate (operating 13 proxy/VPN storefront brands including Luna Proxy, 922 Proxy, ABC Proxy, and IPIDEA itself, all signed with Hong Kong shell-company code-signing certificates) found over 550 distinct threat groups — including China-, DPRK-, Iran-, and Russia-nexus clusters — using IPIDEA exit nodes in a single 7-day window for SaaS access, on-premises intrusions, and password-spray attacks, backed by roughly 7,400 Tier Two C2 servers, 3,075 malicious Windows PE hashes, and 600+ compromised Android apps (PacketSDK, CastarSDK, HexSDK, EarnSDK — the last a rebrand of prior Badbox 2.0 botnet infrastructure); Google, Cloudflare, and Lumen/Black Lotus Labs jointly disrupted the Tier One C2 domains and Google Play Protect blocked the malicious SDK-bearing apps. GTIG's July 2026 follow-up disruption of the separate NetNut platform (built on the ~2-million-device Popa botnet, seized with FBI and IRS-CI involvement) found 316 distinct threat clusters using suspected NetNut exit nodes in a single week and identified NetNut botnet-plugin components shared with Badbox 2.0 — evidence that the same underlying device-compromise supply chain feeds multiple competing residential-proxy storefronts. Those entities are recorded here as sourced infrastructure context establishing the delivery mechanism's provenance, not as confirmed operators of the Bad Sushi campaign itself.
MITRE ATT&CK techniques used in TL-2026-2471
Command and Control
Execution
Initial Access
Resource Development
T1583.001 Domains; T1583.003 Virtual Private Server; T1583.005 Botnet; T1585.002 Email Accounts; T1585.003 Cloud Accounts
command-and-control
Defense Evasion
Affected products and versions in Bad Sushi: China-Nexus Phishing Operation Shifts to
- SBI — SBI online banking customers (brand impersonation, not a software vulnerability)
- JCB — JCB payment-card customers (brand impersonation, not a software vulnerability)
- Hodaka — Hodaka customers (brand impersonation, not a software vulnerability)
Remediation for Bad Sushi: China-Nexus Phishing Operation Shifts to
Immediate actions
- Block or flag inbound SMTP sessions presenting generic, non-existent, or non-resolvable HELO/EHLO strings
- Enforce SPF, DKIM, and DMARC on inbound mail flows to catch spoofed financial-brand senders
- Disable or restrict automatic forwarding rules that accept unauthenticated inbound messages
- Monitor for and block known IPIDEA/NetNut Tier One C2 domain patterns (e.g. *.packetsdk.xyz/.net/.io, holadns.com, *.hexsdk.com) as a proxy-supply-chain compromise indicator on managed endpoints
Workarounds
- Identify and disconnect residential IoT devices (smart doorbells, streaming boxes, routers) exhibiting proxy-like outbound connection patterns
- Rate-limit or geofence unexpected authentication/login traffic sourced from residential ASN space when it does not match customer geography
Longer-term hardening
- Subscribe to and act on Spamhaus XBL/CSS/SBL and ZEN (not SBL alone) feeds, since PBL/ZEN coverage catches residential-proxy-sourced traffic that SBL-only filtering misses
- Deploy egress monitoring for residential-proxy SDK / proxyware traffic patterns on managed endpoints and IoT device fleets
- Educate Japanese financial-brand customers (SBI, JCB, Hodaka) on current lure patterns and .top-domain redirector abuse
- Audit mobile fleets for applications bundling known proxy SDKs (PacketSDK, CastarSDK, HexSDK, EarnSDK) and rely on Google Play Protect enforcement signals
Timeline of Bad Sushi: China-Nexus Phishing Operation Shifts to
- Bitsight documents 'backconnect' residential-proxy malware active since at least 2016, establishing the technical lineage for today's residential-proxy-as-a-service platforms.
- Spamhaus documents smart doorbells and other IoT devices being compromised via malicious proxy SDKs bundled in apps such as Mobdro, seeding the residential-proxy ecosystem later abused for phishing distribution.
- Spamhaus publishes a primer on the dangers of residential proxy networks, describing SDK-based device recruitment and its abuse for spam and network-penetration.
- Spamhaus begins listing China Telecom (Fujian branch) and China Unicom subnets dedicated to phishing emissions in the Spamhaus Blocklist (SBL).
- The China-nexus phishing operation ('Bad Sushi') shifts its distribution infrastructure from dedicated China Telecom/Unicom subnets to residential proxy networks, deploying 3.5-4 million IPs with roughly 250,000 IPs churned daily; source-IP geography including Latin America surges.
- A separate Brazil-nexus campaign is observed abusing roughly 500,000 residential-proxy IPs for widespread brute-force login attempts, shortly before the China-nexus pivot.
- Campaign source geography expands from a single country (Japan) to 173 countries; distinct source IPs grow from approximately 4,600 to over 1.3 million across 8,893 distinct Autonomous Systems.
- Badbox/Badbox 2.0, Android supply-chain malware that fed residential-proxy device pools, is disrupted.
- Spamhaus publishes 'Bad sushi: China-nexus phishers shift to residential proxies,' documenting the campaign; residential-proxy activity by this point accounts for roughly 66% of XBL listings (3.34M) and 37% of CSS listings (1.73M).
- The Kimwolf botnet is documented infecting more than two million Android TV streaming devices via bundled residential-proxy software, expanding the pool of abusable proxy infrastructure.
- Google Threat Intelligence Group (GTIG) publishes a disruption report on the IPIDEA conglomerate (Luna Proxy/922Proxy/IP2World/ABC Proxy and 9 other brands): over 550 distinct threat groups from China, DPRK, Iran, and Russia used IPIDEA exit nodes in a single 7-day window; GTIG identifies ~7,400 Tier Two C2 servers, 3,075 malicious Windows PE hashes, and 600+ compromised Android apps carrying PacketSDK/CastarSDK/HexSDK/EarnSDK; Cloudflare disrupts domain resolution and Google Play Protect blocks the malicious SDK-bearing apps, reducing IPIDEA's device pool by millions.
- The FBI and IC3 publish a public service announcement warning device owners about residential-proxy network recruitment and abuse.
- In a single week during June 2026, GTIG observes 316 distinct threat clusters, including cybercriminal and espionage groups, using suspected NetNut exit nodes; NetNut's network is estimated at 2 million-plus devices with botnet-plugin components shared with Badbox 2.0.
- FBI, Google, Lumen, Shadowserver, and IRS Criminal Investigation seize the NetNut residential-proxy platform, built on the roughly two-million-device Popa botnet; Google separately disables Google accounts/services used for NetNut C2 and Play Protect disables apps carrying NetNut SDKs.
Sources cited for Bad Sushi: China-Nexus Phishing Operation Shifts to
- Bad sushi: China-nexus phishers shift to residential proxies
- Bad sushi: China-nexus phishers shift to residential proxies (syndication)
- Let's talk about the danger of residential proxy networks
- When doorbells go rogue!
- Residential Proxy Services and Malware Ecosystems
- Evading Residential Proxy Networks: Protecting Your Devices from Becoming a Tool for Criminals
- FBI Seizes NetNut Proxy Platform, Popa Botnet
- To stop crims, Google starts dismantling residential proxy network they use to hide
- Disrupting the Largest Residential Proxy Network
- Google's Continued Disruption of Malicious Residential Proxy Networks
More in phishing
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)
- Trezor, BitBox, and CoinTracking Subscribers Targeted by Phishing After Brevo SAML SSO Authorization-Boundary Breach
- Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)
Detection coverage for TL-2026-2471
As of 2026-09-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2471 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.