Despite multiple takedowns, botnets continue to grow

Botnets Powered by Residential Proxies Continue to Grow, Evade Detection

A staggering 60 million victim IP addresses are currently being exploited by botnets worldwide, with a significant proportion of these compromised devices located in the United States. These malicious networks are powered by residential proxy networks, which allow cybercriminals to blend in with legitimate traffic and evade detection.

At its core, a residential proxy network is essentially a botnet that uses unsuspecting users’ internet connections to carry out malicious activities. Cybercriminals take control of these devices, turning them into “zombies” that can be used for a variety of nefarious purposes, from launching massive denial-of-service (DDoS) attacks to distributing malware and other forms of cyber threats.

According to Chris Formosa, senior lead information security engineer at Black Lotus Labs, the demand for botnets is driving their growth. “There’s clearly a market for these botnets,” he explained in an interview with CyberScoop. “Aside from criminal activity, who wants access to millions of IPs regularly?” This demand not only fuels opportunities for cybercriminals but also provides them with a constant supply of new victims.

One notable example is IPIDEA, one of the largest residential proxy networks, which was disrupted by coordinated strikes in January. However, as researchers at Black Lotus Labs observed, the botnet quickly rebounded and even surpassed its pre-disruption size, boasting a current population of approximately 10 million IPs. “Their rebuild was eye-opening,” said Ryan English, information security engineer at Black Lotus Labs. “Even for how quickly some botnets can rebound, theirs was surprising.”

The challenge facing defenders is significant, as the growth of these botnets seems almost insatiable. More than 1 billion devices are currently vulnerable and available to be unknowingly sucked up into botnets, providing cybercriminals with a seemingly endless supply of new victims.

To make matters worse, researchers at Black Lotus Labs have observed multiple residential proxy services collaborating to form what amounts to the largest cooperative network ever seen on the internet. “Our understanding of the various botnets in this space, along with experience in multiple disruptions, leads us to a very important conclusion,” they wrote in their report. “Taking down a single malicious proxy provider or their botnet in isolation is likely to result in a short-lived solution.”

In other words, disrupting one botnet may only lead to its replacement by another, as the underlying problem remains unsolved. Until the malicious proxy landscape is properly addressed and regulated on both the private industry and law enforcement sides, this issue will continue to grow and pose a significant threat to online security.

So what can individuals do to protect themselves? For starters, it’s essential to ensure that all devices are kept up-to-date with the latest security patches. This may seem like a simple step, but many people neglect to do so, leaving their devices vulnerable to exploitation by cybercriminals. Additionally, being cautious when clicking on links or downloading attachments from unknown sources can go a long way in preventing infections. By taking these basic precautions and staying informed about emerging threats, individuals can significantly reduce their risk of falling victim to botnet attacks.


Source: CyberScoop — 2026-07-24