Despite multiple takedowns, botnets continue to grow

A Resilient Threat: Botnets Continue to Grow Despite Disruptions

A staggering 60 million victim IP addresses are currently being controlled by botnets powered by residential proxy networks, according to a recent report from Lumen Technology’s Black Lotus Labs. These malicious networks are enabling cybercriminals of all types to evade detection by blending in with seemingly legitimate traffic, making it increasingly difficult for defenders to keep up.

At the heart of this problem is the ease with which botnets can rebuild and recover after being disrupted. The IPIDEA residential proxy network, one of the largest in operation, was severely impacted by coordinated strikes in January. However, within hours, it had recovered at nearly half-strength, and has since surpassed its pre-disruption size, controlling approximately 10 million IPs.

This resilience is fueled by a thriving market for botnets, which provides opportunities for growth, reselling, collaboration, and quick rebounds following disruptions. Cybercriminals are constantly seeking out the cover that botnets provide, while more devices become vulnerable due to poor security updates or vendors abandoning support for older products. As a result, the available pool of proxy hunters grows every year.

The challenge for defenders is significant, with multiple residential proxy services collaborating to form what amounts to the largest cooperative network ever seen on the internet. Black Lotus Labs currently tracks over 30 distinct malicious proxy botnet clusters, each boasting more than 100,000 daily victims. The report’s authors warn that taking down a single malicious proxy provider or their botnet in isolation is unlikely to result in a long-term solution.

In fact, the researchers conclude that the malicious proxy environment has essentially created the largest collective botnet currently active on the internet. This collective botnet can move millions of IPs within hours to wherever they are needed, making it an increasingly formidable threat. Until the malicious proxy landscape is properly addressed and regulated, this issue will continue to grow.

So what does this mean for individuals and organizations looking to protect themselves from these threats? The first step is to ensure that all devices, including older ones, have up-to-date security patches and are running the latest software versions. Additionally, implementing robust security measures such as network segmentation and intrusion detection can help mitigate the risk of botnet infection.

Ultimately, the growth of botnets highlights the need for a more coordinated effort between industry leaders, law enforcement, and regulatory bodies to address this issue. Until then, individuals and organizations must remain vigilant and proactive in their cybersecurity efforts, recognizing that even with disruptions, these resilient threats will continue to evolve and adapt.


Source: CyberScoop — 2026-07-24