Skip to content
Inside The Mobile Farm The Oem Stack Powering Us 4g 5g Proxy Networks

Inside The Mobile Farm The Oem Stack Powering Us 4g 5g Proxy Networks

infrawatch.com April 22, 2026

We identify 87 physical SIM farms across 17 countries, link downstream proxy providers, and describe the technical capabilities that enable large-scale fraud and abusive automation.

In February 2026, Infrawatch investigated several self-proclaimed “SIM Farm as a Service” offerings, identifying the underlying physical infrastructure: racks of real phones and 4G/5G modems connected to carrier networks.

Infrawatch identified 87 exposed instances of the ProxySmart control panel across 17 countries, linked to at least 24 commercial proxy providers and 35 cellular providers. The observed footprint includes at least 94 physical phone-farm locations across North America, Europe, and South America, including a distributed presence across 19 U.S. states.

SIM farms enable a range of illicit and abusive activity at industrial scale and are supported by a broader downstream ecosystem of software, infrastructure, and commercial evasion services.

In September 2025, the U.S. Secret Service dismantled a telecommunications threat in New York involving more than 300 co-located SIM servers and 100,000 SIM cards. In October 2025, a Europol-supported operation in Latvia targeted a cybercrime-as-a-service network that relied on SIM-box infrastructure, leading to seven arrests and the seizure of 1,200 SIM-box devices and 40,000 active SIM cards.

Infrawatch assesses that a large portion of the mobile proxy ecosystem is enabled by a shared SIM Farm as a Service control plane called ProxySmart.

Some ProxySmart-powered providers market directly to Russian-speaking audiences as a means of obtaining U.S.-located mobile connectivity and accessing geo-restricted platforms.

Across providers reviewed, meaningful KYC was uncommon, and some explicitly advertised that no KYC was required, making mobile carriers across the world broadly accessible to any buyer.

ProxySmart is publicly associated with a Belarus-based vendor footprint and offers an end-to-end stack for operating and monetising a physical farm, including device management, automated IP rotation, customer provisioning, plan enforcement, and anti-bot countermeasures. Technical analysis indicates operator capabilities consistent with large-scale evasion enablement, including automated IP rotation, remote device control, and network fingerprint spoofing.

ProxySmart appears to function as OEM software used by multiple SIM farm operators. The platform explicitly positions itself as the stack for operators seeking to run a “Professional 4G/5G Mobile Proxy Farm,” and is supported by extensive installation, deployment, and operational documentation.

Figure 1 - Example of SIM Farm Deployment

ProxySmart is sold to farm operators on a SIM-count pricing model and provides an end-to-end stack for operating and monetising mobile proxy infrastructure. Its functionality spans farm management, device control, customer provisioning, retail proxy sales, and payment handling. In effect, it offers a fully fledged SIM farm as a Service platform.

The platform is marketed as a turnkey solution rather than a tool intended only for highly technical operators. Its public-facing materials advertise a web interface, API, remote access, documentation, and support, presenting SIM farm deployment as a productised commercial setup rather than a specialist engineering effort. This likely lowers the technical barrier to establishing and operating mobile proxy infrastructure.

Mobile proxies are attractive to users because they typically sit behind carrier-grade NAT, meaning a single IP address may be shared by multiple clients at the same time. This makes IP-based blocking less effective and also enables rapid IP rotation, since addresses can often be changed simply by forcing a reconnection to the carrier network.

Infrawatch identified 87 distinct instances of the ProxySmart control panel across 17 countries, linked to at least 24 commercial proxy providers. These providers rely on phone- or modem-based farms, hosted either directly by the provider or by third parties.

Taken together, these deployments underpin a global phone-farm network spanning at least 94 locations across North America, Europe, and South America.

Figure 2 - SIM cards installed in 4G dongles within a ProxySmart deployment

Separately, Infrawatch identified the location of a U.S.-based operator who openly a phone farm online while inadvertently exposing EXIF metadata in published images. That operator was assessed to be based in New York.

Within a single farm, more established operators often distribute SIM cards across multiple carrier networks in order to increase the value of their infrastructure to downstream proxy providers.

This expands the available IP address pools, improving the likelihood of bypassing IP-based restrictions. The SIM cards are typically acquired on unlimited data plans, with operators openly discussing which carriers are best suited to this model.

Infrawatch identified 24 commercial proxy providers assessed to be downstream of ProxySmart-backed farm infrastructure. Some appear to be direct farm operators, while others present as resellers packaging third-party farm capacity into retail proxy plans.

In many cases, the operators of the physical farms also appear to be the commercial proxy providers marketing the service. Where a provider appears linked to multiple physical locations, Infrawatch assesses that a compensation structure may exist for third parties hosting the hardware, although this could not be independently corroborated at the time of writing.

Some providers appear highly geographically specific, targeting only individual countries or narrow regional markets. These are likely smaller-scale operators hosting their own hardware. Several also appear to focus on specific use cases, including account creation, account management, posting, engagement, and general botting activity on major social platforms.

One Russia-based service linked to U.S.-hosted SIM farms openly advertised its offering on Telegram as a means of circumventing Russian state censorship. In the post shown in Figure 3, the operator claimed the service relied on “real phones” located in the United States and access to services ranging from advanced AI models to graphics cards.

ProxySmart appears to impose limited gatekeeping on who can operate the stack.

Based on Infrawatch’s review of downstream services, there is no clear indication that customers are required to be incorporated entities, accredited businesses, or otherwise subject to meaningful eligibility checks before purchasing access.

Infrawatch identified at least 94 physical SIM farm locations across 17 countries spanning North America, Europe, and South America. These locations host racks of phones and/or 4G/5G modems connected to local mobile carriers and are marketed as commercially rentable proxy infrastructure.

The observed country footprint includes the United States, Canada, the United Kingdom, Germany, Spain, Portugal, Ukraine, Latvia, France, Romania, Brazil, Ireland, the Netherlands, Australia, Italy, Poland, and Georgia (Figure 4). While ProxySmart-backed infrastructure is present across multiple regions, Infrawatch observed a pronounced concentration of deployments in the United States, with additional coverage across Europe and smaller representation in South America and Australia.

Figure 4 - Global distribution of identified SIM farm locations

Within the United States, Infrawatch observed farms spanning 19 states, ranging from California and Texas to Maine and Delaware (Figure 5). Identified locations are predominantly in major metropolitan areas with strong 4G/5G coverage.

Figure 5 - Distribution of identified SIM farm locations across the United States

In some identified U.S. deployments, operators make use of external antennas to improve signal quality, positioning them adjacent to device racks or modems to increase signal stability.

Across ProxySmart-powered farms, operators advertise access to SIMs and carrier connectivity from a wide range of mobile networks, including: AT&T, Verizon, T-Mobile, Telcel, Rogers, EE, O2, Three, Vodafone, Orange, SFR, Free, Bouygues, Deutsche Telekom, KPN, Movistar, MEO, NOS, TIM, Wind Tre, Play, Telstra, Optus, Kyivstar, Lifecell, Vivo, Claro, Digi Mobil, MásMóvil, Yoigo, Lobster, Magti, Silknet, and Geocell.

A single farm operation may use several local carriers at a time. Multi-carrier availability may allow operators to offer location-specific mobile egress, manage capacity constraints, and rotate traffic across networks in response to platform controls or carrier-level enforcement.

Infrawatch identified 87 exposed instances of the ProxySmart control panel across the public internet. These panels (Figure 6) shared an initial HTTP response fingerprint with SHA-256: 739f22524fb0fbb64d9bd8bd9e54df73e17abbe8807ca6df350f69078e4bf164.

Figure 6 - ProxySmart Control Panel Login

A subset of panels associated with larger operators appeared rebranded to remove explicit ProxySmart references while retaining the same underlying fingerprint.

Infrawatch Scope users can use the following pivot: http.response.body.hash.sha256:"739f22524fb0fbb64d9bd8bd9e54df73e17abbe8807ca6df350f69078e4bf164"

ProxySmart’s model provides a web-based control panel for managing farm operations, typically self-hosted by the operator. ProxySmart documentation recommends deploying a reverse proxy in front of the panel to obscure the panel’s underlying hosting and reduce direct attribution, including use of common cloud hosting providers such as DigitalOcean or Hetzner.

As shown in Figure 7, the panel provides centralized management of proxy endpoints, devices, and carrier configuration for a farm.

Figure 7 - SIM Farm Device Control

From our initial findings, it appears that proxy providers are independently running these control panels themselves. ProxySmart also provides an end customer-facing dashboard for selling the proxies managed by their farm software.

ProxySmart supports two device models: physical smartphones and USB 4G/5G modems. For phone-based deployments, devices enrol via an unsigned Android APK downloaded from the operator’s site (SHA-256: a644971c559002e70e6adef6a887f236045d9e37448ff0fe9d187767f779ac42). The application also includes functionality to send and receive SMS, enabling workflows that require phone-number verification or SMS-based automation.

For modem-based deployments, devices are managed via ModemManager, an open-source framework for controlling USB cellular modems. Observed hardware includes commonly available consumer-grade devices such as the Alcatel IK4 family, widely sold through mainstream retail marketplaces.

Both device types are orchestrated by the ProxySmart backend service, which Infrawatch observed to be implemented in Python and heavily obfuscated by PyArmor.

For phone-based farms, IP rotation is implemented by programmatically toggling airplane mode for approximately three seconds, forcing a reconnect to the cellular carrier and (often) reassignment of the egress IP.

A similar approach is taken for modem-based farms, however uses a lower-level interface to interact with the modem’s hardware.

ProxySmart supports multiple tunnelling and proxy protocols, including OpenVPN, SOCKS5, VLESS, and HTTP proxies. OpenVPN materials downloadable via the control panel contain certificate subject naming consistent with “ProxysmartVPN.”

VLESS is commonly associated with environments that perform censorship-aware filtering and traffic inspection, and is frequently used in Russia, China and Iran.

Anti-fraud and anti-bot systems commonly use TCP/IP stack fingerprinting to estimate what type of device or operating system a connection is coming from. They do this by analysing low-level TCP behaviour, such as option ordering and other stack-specific attributes. A common open-source implementation is p0f.

ProxySmart advertises OS spoofing to “simulate other OS TCP fingerprints,” with selectable profiles including macOS, iOS, Windows, and Android, configured per proxy port through the web panel. In a mobile proxy farm context, this may allow carrier egress that would normally resemble a mobile device to instead present as a different client type (for example, Windows), reducing the reliability of fingerprint-based detection and enforcement.

ProxySmart documentation and related operator materials explicitly note that OS spoofing may not function reliably on some mobile networks, citing AT&T (US) and Three (UK) as examples. These carriers likely implement guards against it.

ProxySmart is publicly associated with a Belarus-based vendor footprint. Open-source reporting and promotional materials suggest the platform is operated by individuals with long-running involvement in SIM farm and mobile proxy operations, including offers of hands-on assistance to establish 4G proxy infrastructure oriented toward social-platform use cases.

Associated promotional materials offer hands-on assistance establishing 4G mobile proxy infrastructure and explicitly reference major social platforms. For example, the material advertises support to “build your own 4G (mobile) proxy network,” framed for use on sites such as Instagram, Snapchat, , and ; platforms where anti-bot and anti-fraud controls often make mobile-origin traffic more valuable for evasion and automation.

Coronium appears to be a more established downstream user of ProxySmart and shows limited operational overlap with ProxySmart-linked tooling. In addition to software access, Coronium advertises remote assistance to support SIM farm setup.

Infrawatch observed Coronium installation materials referencing ProxySmart’s remote script update mechanism, including use of an SSH key associated with ProxySmart-linked infrastructure. Coronium also offers bundled packages that include associated farm hardware (Figure 8), alongside the software and operational support.

Figure 8 - Coronium OEM offering

Infrawatch assesses this ecosystem materially lowers the barrier to operating and reselling mobile proxy infrastructure, with limited evidence of meaningful eligibility checks across many downstream providers. The combination of carrier-grade NAT, rapid IP rotation, and multi-carrier availability reduces the effectiveness of IP-centric controls and complicates attribution at scale.

Infrawatch tracks ProxySmart-backed providers using Infrawatch Scope for discovery and Infrawatch Signal for behavioural validation beyond scanning alone. Unlike point-solution providers, Infrawatch applies a full-spectrum approach to infrastructure intelligence, combining internet-wide discovery with behavioural validation.