The Phantoms of the Fraudpera: An Overview of Anti-Detection Tooling

Bobbie Chen (Product Manager · Stitch by Twilio)

BSidesSF 2026 · Day 1 · AMC Theatre 04

Overview

In "The Phantoms of the Fraudpera," Bobbie Chen, a Product Manager specializing in bot detection and fraud prevention at Stitch by Twilio, unveils the sophisticated and often underappreciated landscape of anti-detection tooling employed by fraudsters. Chen argues that fraud is not merely an underworld activity but a highly organized, profit-driven business, mirroring legitimate B2B SaaS operations in its structure, tooling, and pursuit of return on investment (ROI). The talk aims to strip away the blindfold from defenders, revealing the commercial-grade evasion tools readily available to attackers.

Watch on YouTube

Visual summary for The Phantoms of the Fraudpera: An Overview of Anti-Detection Tooling by Bobbie Chen
Visual summary for The Phantoms of the Fraudpera: An Overview of Anti-Detection Tooling by Bobbie Chen

Key moments

  1. 0:00 Introduction to Phantom of the Fraudpera
  2. 2:00 Fraud as a Professional Business Operation
  3. 2:40 Visualizing Fraud Centers: Whiteboards and Gongs
  4. 4:30 Professional B2B SaaS-like Tools for Fraudsters
  5. 6:00 Demonstrating a CAPTCHA Solving Marketplace
  6. 7:45 Why Defenders Often Overlook Attacker Tooling

The Phantoms of the Fraudpera: An Overview of Anti-Detection Tooling

Speakers: Bobbie Chen, Product Manager, Stitch by Twilio

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=AfqwKgnVuc8

Overview

In "The Phantoms of the Fraudpera," Bobbie Chen, a Product Manager specializing in bot detection and fraud prevention at Stitch by Twilio, unveils the sophisticated and often underappreciated landscape of anti-detection tooling employed by fraudsters. Chen argues that fraud is not merely an underworld activity but a highly organized, profit-driven business, mirroring legitimate B2B SaaS operations in its structure, tooling, and pursuit of return on investment (ROI). The talk aims to strip away the blindfold from defenders, revealing the commercial-grade evasion tools readily available to attackers.

This presentation is critical for anyone involved in online security, fraud prevention, or product management, particularly those managing services with free trials or valuable offerings. Chen highlights that many defenders are unaware of the extent and commoditization of these anti-detection services, putting them at a significant disadvantage. By understanding the attacker's motivations, tools, and business model, defenders can shift their strategy from reactive blocking to proactively eroding the attacker's ROI, ultimately making their services less attractive targets.

Background

▶ Watch: Introduction to Phantom of the Fraudpera (0:00)

Chen begins by challenging the popular perception of fraud as a shadowy, individualistic endeavor. Instead, he asserts that fraud operates as a sophisticated business, complete with organizational structures, Standard Operating Procedures (SOPs), runbooks, and continuous iteration for improvement. Drawing parallels to legitimate B2B SaaS companies, Chen illustrates how fraudulent enterprises leverage specialized commercial tools to achieve their objectives. He presents screenshots of actual "bad actor to bad actor" (B2B2B) SaaS platforms offering services like unlimited social account management, CAPTCHA solving, and multi-profile browsing, all complete with professional landing pages, pricing tiers, and comprehensive documentation.

The motivating scenario presented is common: a SaaS company offering a free trial experiences a sudden "hockey stick" growth in sign-ups, only to discover that a significant portion of this activity is fraudulent. This abuse arises because, whenever something valuable is given away for free, there's an inherent incentive for attackers to exploit it at scale, either for direct profit, resale, or as a component of larger schemes. Chen emphasizes that many defenders, while familiar with open-source hacking tools like Mimikatz, remain largely ignorant of the commercial, off-the-shelf anti-detection solutions that fraudsters purchase and deploy, akin to playing chess blindfolded against an opponent with full vision.

Key Findings

▶ Watch: Visualizing Fraud Centers: Whiteboards and Gongs (2:40)

The central finding of Chen's talk is the pervasive existence and accessibility of commercial anti-detection tooling, which enables fraudsters to bypass common security measures with surprising ease and low cost. These tools are designed to make automated, large-scale attacks appear legitimate, directly challenging traditional detection methods. Chen categorizes these evasion tools into four primary types:

  1. Residential Proxies: Services that route attacker traffic through legitimate residential IP addresses, making it difficult to distinguish from genuine user activity.
  2. CAPTCHA Solvers: Automated or human-powered services that defeat CAPTCHA challenges at scale and for minimal cost.
  3. Anti-Detect Browsers: Customized browser environments designed to spoof device fingerprints and browser attributes, preventing tracking and correlation across multiple fraudulent accounts.
  4. Device Farms: Physical racks of real mobile devices or other hardware used to generate authentic-looking traffic and interactions at scale.

Chen stresses that the impact of these tools is amplified by the fact that fraud is a business driven by Return on Investment (ROI). Attackers, like any business, seek to maximize their payout while minimizing time and cost. Therefore, the most effective defensive strategy is not to achieve perfect, unbreachable security, but to strategically increase the attacker's time, cost, or decrease their potential payout, thereby breaking their ROI and motivating them to seek easier targets.

Technical Deep Dive

▶ Watch: Professional B2B SaaS-like Tools for Fraudsters (4:30)

Chen provides a detailed breakdown of each anti-detection tooling category, explaining their mechanisms, pricing models, and the specific challenges they pose to defenders.

Residential Proxies

Residential proxies are a cornerstone of modern bot attacks and scraping operations. Unlike traditional data center proxies or VPNs, which are often easily flagged, residential proxies route attacker traffic through IP addresses assigned to individual internet service provider (ISP) subscribers. This makes the traffic appear as if it originates from a legitimate home user, granting it a higher trust score in many detection systems.

Providers advertise vast networks, with one example boasting "150 million+ rotating residential IPs in 195 countries," offering geo-targeting down to the country, state, city, or zip code level. The pricing is remarkably low, starting "as low as $2.50 per gigabyte of traffic." These proxies are sourced either consensually—through apps that pay users a small monthly fee ($5-10) to route traffic through their home connection—or, more maliciously, through malware networks or botnets.

The critical challenge posed by residential proxies is their interaction with Carrier-Grade Network Address Translation (CGNAT). As illustrated by a Cloudflare diagram in the talk, CGNAT allows thousands of users to share a single public IP address. Consequently, if a defender bans a residential IP address associated with malicious activity, they risk inadvertently blocking thousands of legitimate users sharing that same IP. This "blast radius" makes IP banning, a common early-stage defense, highly imprecise and potentially damaging to user experience, often without the defender even realizing the full impact.

CAPTCHA Solvers

CAPTCHAs (Completely Automated Public Turing test to tell Computers and Humans Apart) were originally designed to present tasks easy for humans but difficult for computers. However, their effectiveness has been severely eroded by specialized CAPTCHA solving services. These services operate in two main ways: as two-sided marketplaces (similar to Amazon Mechanical Turk), where humans are paid small sums to solve CAPTCHAs, or increasingly, as dedicated custom tooling leveraging advanced AI and machine learning models for automated solving.

The pricing for these services highlights their commoditization: "For $1 you can solve 1,000 CAPTCHAs. For $3 you can solve 1,000 CAPTCHAs of certain kinds." These prices are highly competitive across multiple providers, converging to "one to two dollars per thousand CAPTCHA solves." This means that for a minimal investment, attackers can bypass CAPTCHAs at massive scale without requiring any specialized skills or coding ability.

Defenders can sometimes detect CAPTCHA solvers by comparing device attributes collected during the CAPTCHA challenge (e.g., browser fingerprint, device characteristics) against those collected when the CAPTCHA token is submitted. Discrepancies can indicate that a different device or environment solved the CAPTCHA than the one submitting it. However, this method requires robust device fingerprinting and continuous adaptation as solver technologies evolve.

Anti-Detect Browsers

Anti-detect browsers are specialized, modified web browsers (often forks of Chromium) designed to manipulate or spoof browser and device fingerprints. Their primary goal is to make automated traffic appear as if it originates from a unique, legitimate user, thereby evading detection systems that rely on device fingerprinting to identify bots or correlate multiple accounts.

These browsers offer features that allow attackers to:

  • Fake device attributes: Consistently mimic specific mobile devices or operating systems for different accounts.
  • Evade correlation: Prevent linking traffic from various fraudulent accounts, crucial for multi-accounting and free trial abuse.
  • Quick cloning and bulk operations: Rapidly create and manage numerous browser profiles, each with a distinct, believable fingerprint.
  • Built-in automation (RPA): Often include robotic process automation capabilities to scale up fraud behavior.

Pricing for anti-detect browsers is also accessible, with one example showing access to 10, 50, or 100 different profiles for as little as "5.85 euros per month." Chen notes a surprising finding from researchers: "some of the most well-known and highest price solutions performed among the worst. Price has almost no correlation with stealth quality," mirroring inconsistencies found in legitimate B2B software markets.

Device Farms

Device farms represent one of the most challenging evasion techniques to combat. These are physical racks of real devices, such as mobile phones, operated remotely. One example cited is an A16Z-backed startup building phone farms for marketers to create "fake content on TikTok."

The core challenge with device farms is that they generate traffic from real devices. This makes them extremely difficult to detect using traditional bot detection methods that look for virtual machines, emulators, or synthetic browser environments. Attackers can rent access to these "real phones that are running on their devices" for "a few thousand dollars per month," allowing them to create vast amounts of authentic-looking content and interactions at scale. This poses a significant threat as the distinction between a real user and an automated, fraudulent operation becomes almost imperceptible at the device level.

Demo / Proof of Concept

▶ Watch: Demonstrating a CAPTCHA Solving Marketplace (6:00)

While the talk did not feature a live technical demonstration or proof of concept in the traditional sense, Bobbie Chen effectively illustrated the operational reality of anti-detection tooling by showcasing numerous screenshots of actual B2B-style SaaS platforms used by fraudsters. These images displayed professional landing pages, detailed feature lists, tiered pricing models, and comprehensive documentation, serving as a powerful visual "proof of concept" for the commercial availability and sophistication of these evasion services.

Defensive Implications

▶ Watch: Why Defenders Often Overlook Attacker Tooling (7:45)

The overarching defensive strategy proposed by Chen is to break the attacker's Return on Investment (ROI). Since fraud is a business, attackers will always prioritize targets that offer the highest payout for the lowest time and cost investment. Defenders must therefore focus on strategies that either decrease the attacker's potential payout, increase the time required for a successful attack, or increase the financial and operational cost of executing it.

Chen emphasizes a layered defense approach, often referred to as the "Swiss cheese model." No single layer of defense is perfect or unbypassable. Instead, effective security relies on multiple overlapping layers, each adding friction and cost. These layers should ideally not be bypassed by the same methods, creating a cumulative deterrent effect. Even if a defense is cheap for an attacker to bypass (e.g., $1-2 per 1,000 CAPTCHAs), it's not free, and these marginal costs add up, impacting their overall ROI.

Specific defensive actions include:

  • Re-evaluating IP Banning: While effective against simple, single-IP attacks, it's highly ineffective and risky against residential proxies due to CGNAT, which can block thousands of legitimate users. Defenders need more nuanced IP reputation systems that can differentiate between residential and data center IPs, and consider the context of the IP's usage rather than blanket bans.
  • Advanced CAPTCHA Strategies: Simply implementing a CAPTCHA is no longer sufficient. Defenders must also deploy mechanisms to detect discrepancies between the device solving the CAPTCHA and the device submitting the token, and continuously update these detection methods to counter evolving CAPTCHA solver techniques.
  • Robust Device Fingerprinting: While anti-detect browsers aim to defeat this, sophisticated device fingerprinting, combined with behavioral analytics, remains crucial for identifying anomalies. Defenders must continuously research and implement new fingerprinting techniques that are harder to spoof.
  • Reducing Payout Value: A direct way to impact ROI is to make the target less lucrative. This can involve "slashing the value of their free trial" or significantly limiting features for new accounts until they've established trust. This shifts attacker attention to more profitable targets.
  • Slowing Time to Value: Introducing delays in the attacker's workflow increases their operational time and reduces their daily yield. Common in fintech, this involves "delaying payouts," implementing mandatory waiting periods, or requiring additional Know Your Customer (KYC) checks before funds can be accessed.
  • Continuous Awareness and Intelligence: Defenders must actively research and understand the latest anti-detection tools and techniques. Chen's core message is that "if you're a defender and you're not even aware of this kind of tooling, that puts you at a big disadvantage." Staying informed allows for proactive defense and adaptation.

Ultimately, the goal is not to achieve absolute unbreakability, but to make the cost-benefit ratio of attacking your service unfavorable enough that attackers choose to move on to easier, more profitable targets.

Key Takeaways

  • Fraud is a Business: Modern fraud operations are organized, profit-driven enterprises utilizing sophisticated business models and tools, not just individual actors.
  • Commercial Evasion is Commoditized: Advanced anti-detection tooling, including residential proxies, CAPTCHA solvers, anti-detect browsers, and device farms, is readily available and affordable as "B2B SaaS" for bad actors.
  • Traditional Defenses Are Insufficient: Common security measures like basic IP banning and simple CAPTCHAs are easily bypassed by these commercial tools, often with unintended consequences (e.g., blocking legitimate users via CGNAT).
  • Focus on Attacker ROI: The most effective defensive strategy is to break the attacker's Return on Investment by increasing their costs, extending their time-to-value, or decreasing their potential payout.
  • Layered and Adaptive Defenses: Implement multiple, overlapping layers of defense (Swiss cheese model) that each add friction and cost, and continuously adapt these defenses as attacker tools evolve.
  • Defender Awareness is Paramount: Security and fraud teams must be fully aware of the commercial anti-detection landscape to effectively design and implement countermeasures, playing "with the blindfold off."

About the Speaker(s)

Bobbie Chen is a Product Manager at Stitch by Twilio, where he specializes in bot detection and fraud prevention. His work involves understanding the evolving tactics of fraudsters and developing solutions to protect online services and users. Chen's expertise lies in bridging the gap between technical security challenges and strategic product development to combat large-scale abuse.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent threat-intel/awareness talk that does one useful thing well: frames the fraud ecosystem as a B2B SaaS market with real pricing data and product screenshots, making the commoditization argument concrete. Nothing here is novel for anyone already working in fraud or bot detection, but it's a solid on-ramp for product managers, engineers, and defenders who haven't stared at these tooling markets directly.

Heather Calloway (CISO) — SOLID

Chen does useful work demystifying the commercial fraud tooling ecosystem and framing attacker behavior through an ROI lens — that framing alone has real value for product and security teams who still think CAPTCHAs are a meaningful barrier. But this is a practitioner-level awareness talk, not a governance or program-level one, and it stops well short of telling security leaders what to own, what to escalate, or what institutional decisions need to change.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026