VYPR
trendPublished Jul 24, 2026· 1 source

Residential Proxy Botnets Explode in Size, Evading Takedowns

Lumen's Black Lotus Labs reports residential proxy botnets are rapidly expanding, nearing 60 million victim IPs globally, with some quickly rebounding after takedowns.

Residential proxy botnets are experiencing a significant surge in growth, enabling a wide array of cybercriminals to mask their malicious activities by blending in with legitimate internet traffic. According to a recent report from Lumen Technology's Black Lotus Labs, the global scale of these compromised networks is rapidly approaching 60 million victim IP addresses. A substantial portion, roughly one in four of these compromised IPs, are located in the United States. However, the true number of infected devices is likely much higher, as the report acknowledges limitations in visibility into all existing networks and the common occurrence of multiple devices sharing a single IP address unknowingly running malicious proxy software.

Super-sized botnets are becoming increasingly prevalent, with Lumen researchers observing an average of 10 distinct botnets each controlling populations of approximately one million active victims daily. This sustained growth is directly fueled by a robust market for compromised IP addresses. "The only reason these botnets keep getting more and more victims is because there is clearly a market. Aside from criminal activity, who wants access to millions of IPs regularly?" Chris Formosa, senior lead information security engineer at Black Lotus Labs, stated in an interview.

This demand creates a fertile ground for growth, resale, collaboration, and crucially, rapid recovery following disruptive law enforcement actions. A prime example of this resilience is the IPIDEA network, once one of the largest residential proxy services. Despite infrastructure disruptions from coordinated strikes in January, IPIDEA reportedly recovered to nearly half its strength within hours and has since surpassed its pre-disruption size, now boasting a botnet population of about 10 million IPs. "Their rebuild was eye-opening as they began to rebound from that interdiction," noted Ryan English, another information security engineer at Black Lotus Labs. "Even for how quickly some botnets can rebound, theirs was surprising. We've seen them all rebuild, but we haven't seen anybody do it that fast."

The continuous expansion of botnets is driven by several factors. Cybercriminals actively seek the anonymity these networks provide, while a steady supply of cheap, poorly defended devices enters the market. Furthermore, the lifecycle of older, yet still functional, products is extended as vendors cease providing security updates, leaving them vulnerable to exploitation.

"Your available pool for those proxy hunters grows every year, and it will continue to grow every year," English added, estimating that over one billion devices are currently vulnerable and susceptible to being unknowingly absorbed into botnets. The challenge for defenders is significant, as the operators of these botnets have established a complex global supply chain that is difficult to dismantle effectively.

Researchers highlighted a concerning trend of collaboration among multiple residential proxy services, forming what appears to be the largest cooperative network ever observed on the internet. Black Lotus Labs currently monitors over 30 distinct malicious proxy botnet clusters, most of which consistently report more than 100,000 daily victims.

"Our understanding of the various botnets in this space, along with experience in multiple disruptions, leads us to a very important conclusion: taking down a single malicious proxy provider or their botnet in isolation is likely to result in a short-lived solution," the report states. The malicious proxy environment has effectively coalesced into the largest collective botnet active today, capable of shifting millions of IPs rapidly to wherever they are needed.

Lumen concludes that until the malicious proxy landscape is adequately addressed and regulated by both private industry and law enforcement, the problem will continue to escalate. This growing issue, coupled with the persistent threat of DDoS botnets, is projected to become a more significant problem in the long term.

Synthesized by Vypr AI