Residential proxy networks may sound technical, but their impact is easy to understand: they help criminals hide in everyday internet traffic. In this post, we break down how these massive botnet-powered ecosystems enable fraud, evade detection and quickly recover after disruption—and why stopping them will take coordinated action across the security community.
Key findings
- Black Lotus Labs® tracks nearly 20 million distinct IPs per day across more than 30 malicious proxy botnet clusters, showing that the residential proxy ecosystem has grown far beyond isolated botnets.
- More than 20 malicious proxy botnet clusters regularly exceed 100,000 daily victims, with several large operators controlling or accessing millions of compromised devices worldwide.
- Residential proxy services help threat actors hide malicious activity in everyday internet traffic, enabling fraud, credential attacks, scanning, geo-evasion and other abuse.
- Major proxy providers operate as a resilient supply chain, using botnets, storefronts and resale relationships to replenish inventory and recover quickly after disruption.
- Compromised IoT, SOHO and mobile devices create a large pool of low-cost residential IPs that are difficult to attribute, monitor and dismantle one provider at a time.
- Sustained disruption will require coordinated action across botnet infrastructure, proxy storefronts, hosting providers, law enforcement, telecoms and the broader security community.
This article explains how the residential proxy ecosystem evolved, why it enables large-scale abuse, and what defenders can do to help reduce the threat.
The hidden risk behind residential proxy networks
The proliferation of residential proxies is difficult to restrict because they give attackers two major advantages: anonymity and cover. In any contested environment, offense and defense continuously evolve to overcome each other. Residential proxies largely bypass standard detections, such as reputation-based blocking and alerting, rate limits for brute-force attacks, anti-fraud defenses and geo-blocking. By routing traffic through legitimate home internet connections near the targeted entity, proxy users blend in with the volume of everyday internet traffic. We even see AI companies using proxies to circumvent geographic “fences” while scraping the web to train large language models (LLMs) from distributed points, avoiding website rules.
The increase in demand for proxies has attracted a legion of actors, many with malicious intentions, who profit at the expense of unknowing and unwitting users.
Describing what constitutes a “residential proxy” service requires some nuance. We consider a residential proxy to be any device that acts as a proxy and is not an IP belonging to a data center or a Virtual Private Server (VPS). Criminal users prefer this infrastructure that primarily uses dynamic and frequently rotated IP addresses to avoid linking their actions to an IP that ends up on a watch list.
Some services pay users to access the bandwidth they purchase from their internet service provider (ISP) to proxy traffic from others. Often, it is against an ISP’s terms of service for an end user to resell bandwidth without permission. Even if an end user agrees to the terms and conditions required to join a proxy service, they likely lack the ISP’s required awareness and approval. The problem becomes more complex when a mobile device enrolled in a proxy is involved.
If a user has a proxy service running on their phone and connects to Wi-Fi at a coffee shop, the shop’s network is now unknowingly acting as part of a residential proxy service.
A number of these residential proxy services exist and act independently. However, we have observed multiple residential proxy services collaborating to form what amounts to the largest cooperative network ever seen on the internet.
Black Lotus Labs has monitored more than 30 malicious proxy botnets over several years by developing algorithms that detect both small and large malicious botnets at scale, enabling us to monitor them as they emerge.
Malicious services and where to find them
Before diving into the details of botnets, it is essential to understand how Black Lotus Labs assesses whether a proxy service (and its underlying infrastructure) is predominantly supported by malware. We begin by analyzing global IP backbone telemetry, for which we have developed algorithms to identify clusters of unusual activity across the Lumen backbone.
These specialized methods, tailored for different types of botnets, often detect their presence as soon as a C2 server comes online. If multiple Asus routers across the internet begin communicating with the same C2 server, for example, the activity is immediately logged and investigated. For proxy services in the residential IP space, we often supplement this analysis with publicly available information to draw a more comprehensive view.
In this article, we define small botnets as those with fewer than 40,000 distinct IPs, while large botnets generally have millions of IPs.
Small vs. large and how they are built
Black Lotus Labs generally assesses that most smaller proxy services, especially those that sell access to a specific IP address of a user’s choice, are primarily composed of infected IoT devices (routers). The operators of smaller botnets tend to focus on end-of-life devices and the use of more recent CVEs against unpatched equipment. Examples include KadNap, which powered Doppelganger, or Ngioweb, which powered NSOCKS. These services often lack sufficient proxies to operate competitively, so they take shortcuts on security and oversight that cut costs. Those decisions foster an environment of illicit utility.
Take a service like Doppelganger which had no public marketing on any legitimate forums and even advertised on their own website, “We do not require registration and do not monitor your actions.” This means a user is free to use an IP address however they see fit, whether for mass scanning the internet or trying to exploit an organization.
For small botnets, the maximum number of bots the operators can acquire is generally not their top priority. The small botnet operator is like a real estate agent: the quality and location of a bot creates its value. Experienced criminal operators are drawn by the selection offered by these networks, such as the ability to choose from multiple devices in a specific city.
This is contrary to large proxy service operators, who have one goal above all else: How many proxies can I acquire that can be used reliably? They need to be able to compete with many other “reputable” services that offer millions of proxies.
By gathering as many proxies as possible, large providers can offer gigabytes of traffic at extremely low prices. Most services offer discounts to clients who purchase access to large amounts of bandwidth, bringing prices down even further and increasing competition among providers. While this by itself is a normal business practice, so too is the fact that for these malware-oriented “volume discount” proxy services, there is usually little to no monitoring of usage. As one might imagine, these are favorable conditions for criminal activity and abuse to take place on an unprecedented scale.
Large proxy services that operate malicious botnets behind the scenes often hide in plain sight. When looking at a service’s storefront, it becomes very challenging to recognize embellishment from outright deception.
Many services advertise having millions, to hundreds of millions, of IPs. One key piece of information we search for is an explanation of how they source their IPs. Malware-backed services, for instance, will frequently use terms such as “ethical proxies” with next to no description of how those proxies are obtained, hoping that a visitor to the website blindly trusts their motives.
One example is the proxy provider reported to be using the same malware packaged in Kimwolf installations. The word “ethical” appears, at the time of writing, on their website six times. This is despite the provider’s prior use of Kimwolf to grow its proxy numbers and its more recent association with the Titan botnet. Titan is commonly found in backdoored Android Package Kits (APKs) to enlist unknowing users and has amassed close to 500,000 daily victims.
In contrast to smaller botnets, many large providers expand their networks by using Software Development Kits (SDKs) bundled with legitimate applications, enabling their software to be installed across many device types. An SDK is a package of tools, libraries and code used to support legitimate applications, such as when you download a new app on your phone. In this manner, they can scale quickly while avoiding the issue of user awareness or consent, much like widescale vulnerability exploitation but without the mess.
The subterfuge does not end there. Many proxy providers have a public-facing website on which they claim to always ask for user consent before using their bandwidth. A quick search on VirusTotal or any other public repository of malicious content often proves these statements false when IPs are found to be part of malicious campaigns.
When considering what constitutes a malicious service, all of these elements need to be understood: the use of SDKs or malware to acquire IPs, the veneer of legitimacy, massive scale alongside claims of ethics, accepting only cryptocurrency and offering to proxy traffic for anonymous users.
Black Lotus Labs focuses on botnets built through practices that are, at best, deceitful and, at worst, compromised devices with damaging malware.
Residential proxy service enabling fraud: a use case
Over the years, we have consistently emphasized how critical these residential proxy services are to enabling fraudulent activity. For this report, we wanted to show a real-world example step by step.
Months ago, we came across an open directory that was full of credit card data, including CVV codes, the 3- or 4-digit codes used to prevent credit card fraud in off-premises transactions. The directory had over 2,000 rows of fresh credit card details and was regularly updated with new data. We alerted financial institutions and law enforcement of this activity as we continued to monitor it.
The fraud actor was based in Vietnam and had compiled the essential Personally Identifiable Information (PII) for each victim, increasing the effectiveness of the card information sold to their malicious customers. The actor added a value to each PII entry indicating whether the card was currently “Live,” with information from a site known as cococheck[.]co. One day, we saw that approximately 90% of their data had a “Live” entry, indicating their stolen data was extremely fresh.
Unfortunately for this operator, they left their entire working directory open as well, allowing anyone who navigated to the server’s address to browse as if it were the homepage of a business. What was most fascinating about this open directory was that it had folders for popular residential proxy services such as “ipcola” and “kookeey,” among others. In each service’s folder, scripts were present to assess proxies across multiple aspects and evaluate proxy nodes for key attributes necessary for successful attacks.
The first part of the script checked their IPQualityScore (IPQS) keys, removing any that were currently or would become blacklisted to avoid reuse after the fact. IPQS assigns a score indicating the likelihood that an IP has been associated with fraudulent activity. For a malicious user, this helps ensure that before they abuse the card, the IPs are clean and undetectable by fraud-scoring systems. The operators regularly rotated these keys in case any of them were banned or suspended. Next, since the majority of the stolen PII was for cards based in the U.S., the actors ensured the IPs they would be using were in the country.
Finally, they took bot location one step further to ensure the proxies they ultimately used were located in specific states of interest. For example, if the actors attempted fraud in Texas, they preferred IPs geo-located in Texas. From Figure 6, we know they track proxy data down to the city level as well, so their fraudulent activity can be extremely targeted.
Among the proxy services used in this case, four operated their own very large botnets, including IPIDEA.
Notable malware-powered proxy botnets
Thanks to our detection algorithms, Black Lotus Labs has years of tracking data for many named and yet-unnamed malicious proxy botnet architectures. We track close to 20 million distinct IPs per day across more than 30 distinct clusters that are directly attributed to malicious botnet infrastructure. In almost all of these cases, we can confidently assess that those 20 million IPs did not willingly become victims of their respective botnet(s).
The following examples highlight several well-known proxy botnets that demonstrate the scale, resilience and interconnected nature of this ecosystem.
IPIDEA
In late January of 2026, Google disrupted one of the largest, if not the largest, malware-backed proxy services on the market, known as IPIDEA. While IPIDEA would recover within hours, the disruption resulted in the loss of many of its public storefronts, an approximate 33% decrease in overall traffic volumes and a 25% reduction in victim population that persisted for months.
IPIDEA continued to regenerate, test and deploy new infrastructure for victim communications in late March. By mid-May, they migrated their bot population to these new servers. Currently, only 15% still use the old infrastructure, which helped hide their system after exposure. After almost five months, IPIDEA surpassed its pre-January 2026 disruption botnet size in early July 2026.
Jaguar
Jaguar follows a trajectory similar to IPIDEA, a network first exposed by Xlab and operated by a Chinese company, which uses two architectures. The first, Jaguar, has about 600,000 IPs daily. It suffered significant losses from February to May, likely due to disruptions targeting IPIDEA, which affected its malware distribution, causing a decline in Jaguar’s bot population. Interestingly, Jaguar sees a surge in victim connections right around the time IPIDEA migrated to new infrastructure.
Jaguar maintains at least one other botnet with a daily average of 1.5 million devices, bringing their total distinct victims to around 2 million per day in our visibility. The victims in this network are spread across the globe in almost any location a user could want. To put this in perspective, this botnet maintains over 1,000 distinct IPs per day across more than half of the world's countries. Despite worldwide victimization, we can see that very few of these victims exist within China.
Jaguar uses a myriad of Chinese hosting services for its infrastructure, which consists of several hundred C2 servers and primarily gains users through pre-installed backdoored Android devices, among other methods. It operates multiple named proxy services to sell its botnet, with some focused on English speakers and others dedicated to Chinese speakers.
Kookeey
Kookeey is another Chinese-based proxy service, our actor who was committing credit card fraud was using this through the gateway gate-hk.kookeey[.]info. They currently operate a botnet of around 1.5 to 2 million distinct daily IPs and primarily gain victims through silent APK installations. Compared to IPIDEA or Jaguar, it did not suffer a loss of stock during the disruption.
In terms of victim distribution, their botnet is very similar to Jaguar’s, suggesting they are likely using similar channels and methods to acquire proxies. Kookeey operates under multiple brands and has around 300 daily active servers across its proxy and malware distribution infrastructure. The botnet they operate has previously been reported for use in brute-forcing Microsoft logins, among other malicious activity observed emanating from this network.
NetNut
Recently disrupted by the U.S. Department of Justice alongside Lumen and other private industry partners such as Google and Shadowserver, NetNut operated one of the largest malicious proxy botnets known as Popa which, unlike the botnets we have discussed so far, was not operated by Chinese actors. Popa was commonly found in silent installs on Android devices and averaged nearly 1.5 million daily unique IPs in our visibility. One interesting aspect to note is that when IPIDEA was disrupted, Popa’s population fell by around 15% and never made a full recovery.
In our post on the NetNut disruption, we noted that NetNut controls over 1,000 servers in its architecture. Around 250 of them are for Popa, and another 400 are gateways for users to interact with the service. When analyzing the NetNut gateway servers, we observed traffic flowing to two upstream locations: Popa C2s or a layer of 400 servers that help operate and run a botnet of close to 400,000 daily IPs, many of which resolve to subdomains of liveproxies[.]io.
While tracking this architecture, we observed one of NetNut’s IPs using SSH to connect directly to IPs that resolved to cyberprotector[.]online domains. Those domains were seized as part of the NetNut operation, further linking the related infrastructure. As we investigated this IP, we found it had an open directory containing files that held Claude configurations and scripts suggesting the use of AI models to create applications and help manage their pipelines.
G3Proxy
In 2025, G3Proxy grew to a concerning size. For most of the year, it operated primarily on Android TV boxes via preinstalled malware that was loaded onto the devices before they ever reached the victim. Their methods changed in 2026 as the actors became more aggressive, distributing APKs to backdoor Android devices. This malware was commonly found installed alongside other malware, such as Popa, on Android devices. In 2026, G3Proxy peaked at over 1 million distinct IPs in a single day in our visibility.
The actors who operate G3Proxy likely took note of the IPIDEA disruption, as nearly one month to the day after IPIDEA went down, G3Proxy overhauled most of its architecture to be more resilient. They went from basing the majority of their C2 architecture in the U.S. to hosting it entirely in Chinese IP space to avoid the complications of another disruption.
Based on analysis of the botnet’s architecture, we can assess with high confidence that the operators are Chinese and operate from a single storefront, which they use to resell their botnet to others.
The symbiotic ecosystem
The botnets mentioned above are just the tip of the iceberg. Black Lotus Labs tracks many other known and novel proxy botnets, several of which maintain populations in the millions. Of the more than 30 distinct malicious proxy botnet clusters we track, over 20 regularly consist of more than 100,000 daily victims.
For those taking their first look at this ecosystem, it may seem complex. And it is, by design. The botnets we briefly described and the different proxy services that make up this space may seem entirely distinct and unrelated at first glance. Bitsight has done extensive research highlighting significant overlap among these proxy services. However, we would like to take this one step further and characterize it as the largest symbiotic ecosystem on the internet.
Our research has shown that most large providers develop their own botnets, while reselling bots from other providers to bolster their numbers. Combining their efforts with others’ stock gives access to millions of IPs across the landscape. Building a sufficiently large pool of their own bots helps them avoid being seen as just a reseller of others’ bots, thereby adding more value. Even if an operator resells ten times as many bots as they capture, there is still significant profit. This is how a provider goes from a botnet of 500,000 devices to a proxy service of five million devices.
To better understand this ecosystem, consider the graph above, derived from a hybrid of our global telemetry and publicly available sources. Each icon represents the C2 infrastructure of a botnet and the number of distinct IPs it controls. Botnet names in red represent Chinese-operated proxies, which make up around 50% of the malicious proxy botnets we track. Red lines indicate connections between the infrastructures of two distinct proxy botnets, at least one of which is Chinese. In this graph, IPIDEA is labeled as a reference point.
Several important points can be drawn from this diagram. The first is that no single botnet (aside from IPIDEA) directly controls tens of millions of unique IPs. But as we show, it becomes trivial for other botnets to gain and offer access to a population of 10 million by sharing with other large populations. The next and most critical point is that most botnets can reach out to any other botnet.
Two more factors are concerning: first, when looking at a specific proxy service, it can be difficult to determine where a given bot originated. Making matters worse, we also have the growing problem of cohabitation: in many cases, a victim device may harbor multiple infections. This further obscures which botnet is responsible for the proxies’ abuse at any given time. Unfortunately, all these elements result in an environment that is as persistent as it is invasive. If a particular botnet’s architecture is taken offline, other botnets are available to take its place. Operators have sources for reselling other bots, and there is a staggering pool of devices worldwide that are vulnerable to infection. That resilience is best illustrated in the following examples.
Example 1: IPIDEA
IPIDEA does not operate in isolation. Our analysis of its backend history shows many proxy services connecting to it, likely to resell its extensive IP pool. Since many of these services persisted after the IPIDEA disruption, it is reasonable to conclude that some effectively switched to reselling from other large proxy providers, in addition to what remained of IPIDEA’s network.
IPIDEA also maintained connections to other major services for access to their bot pools. Direct connections into many Popa C2s and IPs resolving to subdomains of netnut[.]io such as zabbix.netnut[.]io, indicated a working relationship with NetNut. In fact, at least four large proxy services, including Kookeey, were linked to IPIDEA in 2025 and 2026. These connections were unaffected by the disruption and likely helped IPIDEA recover quickly by providing access to new IP pools. According to our telemetry, IPIDEA has rebuilt to close to ten million daily distinct IPs, roughly six million more than immediately after the disruption, now representing more victims than its original botnet size.
Example 2: G3Proxy
G3Proxy has connections to only one other malicious proxy botnet we can see. However, when reviewing the bot victim counts in Spur, we find that nearly 75% of the victims are listed as NetNut. This does not imply that NetNut controls G3Proxy. However, it does imply that, based on Spur data, NetNut is most likely either directly reselling G3Proxy or reselling it through another service.
Example 3: Botnet S
Botnet S is run by a large Chinese marketing company publicly traded on the Chinese stock exchange. This company has almost all its proxy architecture based in the U.S. and operates under many different service names. On average, it maintains around 650,000 distinct IPs per day, with peaks near 900,000 devices, primarily compromised through backdoored Android samples.
The sheer size of this botnet is concerning, especially given what it connects with. This service has direct connections to at least NetNut, IPIDEA and IpMoYu. This suggests that if this botnet or proxy service is disrupted, it has multiple paths to avoid a complete shutdown. In turn, they can help restore any of these other services if they are disrupted.
Example 4: NSOCKS
Operators of smaller botnets, those holding tens to hundreds of thousands of proxies, also take advantage of the ecosystem.
Lumen disrupted NSOCKS and the Ngioweb back in 2024. Over the next six months, the NSOCKS service struggled to regain its footing as the Ngioweb tried to rebuild. During that time, NSOCKS found a way to survive. Just as the aforementioned Shopsocks5 and VN5Socks were likely reselling NSOCKS, they began reselling other proxy services such as NetNut and IPIDEA. In the months following our disruption, we noticed that the backconnect servers were contacting other proxy services and soon listed more proxies than before.
They even hinted at this in a notification on their page, advising of a “new type of proxy” and that their IPs may be of “worse quality.”
At the time of our report, the Ngioweb is up and running using a new Domain Generation Algorithm (DGA) to manage its C2 infrastructure.
Example 5: ASOCKS
Recently, Dutch Law Enforcement disrupted the ASOCKS proxy service, which goes by several other names, including Nexusnet. The Dutch claimed this service hosted 17 million IPs. However, Lumen tracked the botnet for some time and found it averaged 100,000-200,000 victims. After the interdiction, the botnet went down and has yet to be rebuilt, which is a fantastic win, but their reselling partnerships were not disrupted. Immediately after the event, we saw a large volume of traffic from their backend servers going to two different proxy service entry gateways as they prepared to restock with new bots. Without simultaneously disrupting the storefronts and other botnets they relied on, ASOCKS was able to maintain normal operations very shortly after the disruption, with almost no downtime.
History on repeat
What does all this information tell us? First, there are many actors in this malicious proxy botnet space, ranging from individuals like “Dort,” who ran a proxy network in addition to the Kimwolf botnet, to networks owned by publicly traded companies. Next, most major proxy services allow reselling of their IPs and have dedicated programs for exactly that. Our understanding of the various botnets in this space, along with experience in multiple disruptions, leads us to a very important conclusion: taking down a single malicious proxy provider or their botnet in isolation is likely to result in a short-lived solution.
The botnet ecosystem has evolved to create reinforcing pathways between actors, essentially forming a global supply chain. As defenders target only a single botnet or service at a time, the operators of those networks can acquire and resell other providers’ IPs for as long as it takes to rebuild their own network.
Millions of devices worldwide are poorly defended at best and unsupported at worst, so many in fact, that we often see victims hosting multiple proxies’ malware files. This means an actor with the knowledge to build in the first place will get back to work, just as a farmer replaces a barn after a storm. Once they rebuild and control their own stock, they reduce their reliance on reselling others’ bots, returning to a more profitable model. If the global supply chains that supply victims to botnets are not disrupted regularly, botnet operators will always rebuild to their previous form.
In recent years, the malicious proxy environment has essentially created the largest collective botnet currently active on the internet, capable of moving millions of IPs within hours to wherever they are needed. Botnet operators sell proxies to each other for several reasons. First, acquiring bots is not much of a challenge, as we have pointed out, and operators generally do not care what the proxies are used for. Reselling to each other at scale not only generates profit but also creates a safety net for the community. The demand for proxies is high enough that while buyers may have preferred networks, they will buy proxies from whoever sells them.
The Kimwolf operators recently introduced a wrinkle in this mutually beneficial sharing. An individual actor (Dort) changed the environment not simply by exploiting devices downstream of the proxy, but by doing it at scale. In other words, instead of renting proxies, Kimwolf stole access to massive proxy botnets, reaching past their gateways and turning their pool of proxies into a new generation of lethal DDoS botnets. Since there is no honor among thieves, this “local exploitation” vulnerability is a serious problem for defenders and the proxy industry alike.
Even if a few large proxy providers prevent LAN exploitation on their services, given the number of distinct botnets in this space and the number of different reselling services, there will always be some who have failed to properly secure their environments. We have entered a stage where actors are building malicious botnets with very little oversight to prevent criminal activity by their users, simultaneously leaving millions of infected devices open to further exploitation. This is a recipe for disaster.
Consider a device that hosts a proxy and also connects to a corporate network. It creates a route into and out of that network, allowing both inbound internet traffic and access to internal systems. If malicious actors control the proxy, they can enable scanning, lateral movement and other malicious activity.
These massive networks have drawn increased attention: Google’s action against the world’s largest residential proxy service, the help Lumen provided in disrupting Popa, and the Department of Justice’s disruption of the world’s largest DDoS botnet are newsworthy examples. The momentum from these events should be carried forward and expanded. Otherwise, the results appear to be temporary. Until the malicious proxy landscape is properly addressed and regulated on both the private industry and law enforcement sides, this issue will grow and, along with the DDoS botnet landscape, will most likely become a greater problem in the long term.
Real disruption will require collaboration
Malicious proxies form a web that not only enables all manners of criminal activity but are also used by nation-state threat actors. The security industry works with law enforcement wherever possible, but to achieve lasting success, we need to go further. Greater awareness and understanding of the issue, along with increased visibility, is a beginning. Defenders need help addressing this issue. This help can and should come from both law enforcement and private industry.
On the law enforcement and policy side, the conversation should include creating regulations to protect end users from these botnets. When combined with law enforcement action, policies can make it much less desirable to use or profit from residential proxy services, thereby reducing the number of malicious actors entering this space. Creating policy is not our area of responsibility; however, we feel strongly that this is a necessary element for success.
Our research also reveals strategic considerations: Chinese individuals and companies operate most large botnets, yet most of these services prohibit the use of proxies located within mainland China. In other words, “The Great Firewall” prevents the average person from visiting certain websites outside China, but malicious actors in China appear to have a free hand to operate and use residential proxies against the rest of the world.
When using Black Lotus Labs telemetry to identify who is accessing these networks as a proxy service, we often see high volumes of activity from IPs based in China. This suggests that users cannot proxy malicious (or any) traffic into mainland China due to policies instituted within the proxy service, and users are certainly proxying to the internet in every other country via these services. For example, one of IPIDEA’s new brands only allows users from a specific region to use its proxy service:
The private sector can assume a more substantial role in spreading knowledge to help other organizations enhance their network security. Lumen Defender℠ customers benefit from our research and have been shielded from most malicious botnets for over a year; however, malicious proxy services remain an internet-wide security challenge.
The residential proxy ecosystem is expanding faster than it can be contained under the status quo. To move forward, cross-industry speed, trust and multifaceted containment to disincentivize malicious proxy operators through both a reduction in the supply of bots and multiservice disruptions will be essential.
Our goal, pursued through a variety of sector-wide engagements, is to help the industry create a source of truth about the infrastructure these services use and to help all organizations, regardless of size, defend against these networks.
One of our contributions to this framework is a proprietary feed containing IOCs related to the most significant malicious proxy networks monitored by our team. We encourage telcos to begin not only blocking malicious C2 servers for proxy botnets but also, using this data, to see just how many of their users are communicating with these botnets and whether they are doing so with the telco’s permission.
Guidance for corporate network defenders
- Continue to look for attacks on weak credentials and suspicious login attempts, even when they originate from residential IP addresses, which bypass geofencing and ASN-based blocking.
- Protect cloud assets from communicating with bots attempting password-spraying attacks and begin blocking IoCs with web application firewalls.
- Ensure that device management interfaces are properly secured and not accessible via the internet. For more information on securing management interfaces, please see DHS’ CISA BoD 23-02 on securing networking equipment.
- Leverage sophisticated network perimeter countermeasures like Lumen Defender℠, which are updated continuously to proactively stop traffic from malicious points from interacting with corporate networks.
Guidance for consumers with SOHO routers and IoT devices
- Follow best practices for regularly rebooting routers and installing security updates and patches. For guidance on how to perform these actions, please see the best practices document prepared by Canadian Centre for Cybersecurity.
- Millions of “TV boxes” and TV sets of dubious origin come with proxy malware preinstalled. Avoid these. A significant number of applications for well-known brands also include SDKs that conscript TVs, so please choose wisely.
- We also recommend replacing devices once they reach their manufacturer’s end of life and are no longer supported.
If you would like to collaborate on similar research or share information on residential proxies, please contact us on LinkedIn (@BlackLotusLabs).
Analysis of the proxy ecosystem was performed by Chris Formosa with technical editing by Ryan English.
Explore how Black Lotus Labs uncovers and tracks threats like residential proxy servers to protect your organization and keep the internet clean.
This content is provided for informational purposes only and may require additional research and substantiation by the end user. In addition, the information is provided "as is" without any warranty or condition of any kind, either express or implied. Use of this information is at the end user's own risk. Lumen does not warrant that the information will meet the end user's requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This document represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. ©2026 Lumen Technologies. All Rights Reserved.