Detect VPN, Proxy & Bot Traffic from South Korea
Maskbreak scores every visitor's network in real time — flagging VPN exit nodes, residential proxies, datacenter ASNs, and headless browsers originating from South Korea. Free API. Under 40ms server-side. No CAPTCHAs.
The networks South Korea traffic actually arrives from
South Korea has 877 autonomous systems on the public registry. 111 of them are hosting, cloud or transit networks holding 103.2M addresses between them — the ranges a commercial VPN or datacenter proxy exits from. Residential broadband is the rest, and that is the traffic worth watching, because a residential proxy hides inside it.
| ASN | Network | IPv4 space |
|---|---|---|
| AS4766 | KIXS-AS-KR Korea Telecom | 46.4M addresses |
| AS9318 | SKB-AS SK Broadband Co Ltd | 14.6M addresses |
| AS17858 | POWERVIS-AS-KR LG POWERCOMM | 10.3M addresses |
| AS3786 | LGDACOM LG DACOM Corporation | 8.1M addresses |
| AS9644 | SKTELECOM-NET-AS SK Telecom | 7.1M addresses |
| AS6619 | SAMSUNGSDS-AS-KR SamsungSDS Inc. | 1.2M addresses |
| AS9316 | DACOM-PUBNETPLUS-AS-KR DACOM-PUBNETPLUS | 1.1M addresses |
| AS10036 | CNM-AS-KR DLIVE | 840K addresses |
Largest hosting-shaped networks registered in South Korea, by IPv4 allocation. Registry data, refreshed daily. A datacenter ASN is not evidence of fraud on its own — it is one signal, weighed alongside device and behaviour.
Why South Korea traffic needs special scrutiny
Datacenter ASN concentration
Gaming and crypto fraud are particularly active, with KT and SK Broadband ranges the most often abused.
Residential proxy resale
Consumer ISP ranges in South Korea can appear in commercial or peer-to-peer residential proxy pools. A consumer ISP label is not proof of fraud; combine it with device, session, and routing signals.
VPN exit-node clustering
The same handful of hosting providers dominate VPN exit nodes in South Korea. Maskbreak maintains live mappings of these ranges so a new IP from a known VPN ASN is flagged within seconds of going live.
Antidetect browser usage
Multi-accounting fraud against South Korean-targeted SaaS, fintech, and e-commerce increasingly uses Kameleo, GoLogin, or AdsPower to spoof device fingerprints. Maskbreak scores these at the device layer, not the IP layer.
What Maskbreak detects for South Korea traffic
- Every major VPN provider's South Korean exit nodes (NordVPN, ExpressVPN, ProtonVPN, Mullvad, Surfshark, and 40+ more)
- Commercial or peer-to-peer residential proxy pools using consumer South Korean IPs
- Datacenter ASNs commonly used for automation (AWS, GCP, Azure, OVH, Hetzner, DigitalOcean, Vultr, Linode)
- Tor exit nodes and known anonymous relays advertising South Korean geolocations
- Headless browsers (Puppeteer, Playwright, Selenium) and antidetect tooling driving sessions from South Korea
- Country-spoofing — when a session claims to be in South Korea but the network telemetry says otherwise
One API call. Bearer token. Done.
// Server-side only: an sk_live_ key must never reach the browser.
const r = await fetch('https://maskbreak.com/v1/evaluate', {
method: 'POST',
headers: {
'Authorization': 'Bearer sk_live_...',
'Content-Type': 'application/json'
},
body: JSON.stringify({ token: req.body.monocle })
});
const { decision, country, network } = await r.json();
if (country === 'KR' && network.vpn) blockOrChallenge();
Stop South Korean VPN, proxy & bot fraud today
Free tier: 1,000 requests/hour. No card, no expiry. Detects VPN, residential proxy, datacenter, and bot traffic from South Korea and 195 other countries.