Resources Docs Free Blog Contact
Log in Get started

Residential proxy botnets: where ‘clean’ home IPs really come from

Residential proxy botnets run on infected TV boxes, old routers and free VPNs. What the 2024–2026 takedowns show, and what your signup form still sees.

In short
  • Some of the largest residential proxy networks run on devices whose owners never agreed: free-VPN malware, pre-infected Android TV boxes, end-of-life routers and paid SDKs.
  • Sources count differently: more than 19 million IP addresses for 911 S5 (DOJ), over 10 million devices for BadBox 2.0 (Google), over 369,000 routers and IoT devices for SocksEscort (Europol). None of the counts is small.
  • IP blocklists lose to rebrands, whitelabel reselling and churn, and the exits are real homes’ and offices’ connections.
  • A bare-IP lookup cannot see these exits. A live visit returns proxy_detected and a block only for exits already tied to a pool; network.residential: true means nothing fired, not that the visitor is safe.
  • The renter’s own machine still shows: automation, a fake browser or an emulator blocks, a time zone mismatch reviews, and counters belong on the device, not the address.
On this page
  1. Four ways a home device becomes someone else’s exit
  2. The takedowns, 2024–2026
  3. What the botnets are rented for
  4. Why an IP blocklist keeps losing
  5. What your signup or login form can still see
  6. If you ship devices or apps

A residential proxy is someone else’s home connection, rented out by the gigabyte or the month, and some of the largest networks selling them are residential proxy botnets: devices whose owners never agreed to it. The 2024–2026 takedowns describe the routes in: malware bundled with free VPNs and pirated software, Android TV boxes and projectors sold with a backdoor already installed, end-of-life routers taken over without a password, and SDKs that app developers are paid to embed. This Maskbreak explainer follows that supply chain through court filings, police statements and threat-intelligence reports, then shows what a signup or login form can still see when the address belongs to a real household.

The takedowns put numbers on it, each counted a different way. The US Justice Department said the infected computers behind the 911 S5 botnet were associated with more than 19 million unique IP addresses (May 2024). Google said the BadBox 2.0 botnet compromised over 10 million uncertified Android devices (July 2025). Europol said the SocksEscort service allegedly compromised over 369,000 routers and IoT devices (March 2026). Dutch police and the national cyber security centre, NCSC, took a botnet of at least 17 million infected devices offline in May 2026; their statement says it was used for cyberattacks and does not say it sold proxy access, but it warns that poorly secured routers and IoT devices can be used as “residential proxies”. And Google’s Threat Intelligence Group estimated that the NetNut network numbered at least 2 million devices (July 2026). All sources in this post were checked on 2026-09-27.

Four ways a home device becomes someone else’s exit

Some residential supply is paid and opt-in: bandwidth-sharing apps give the people who install them credits that convert into money, and sell that bandwidth as residential proxies (Trend Micro, February 2023, checked 2026-09-27; proxy SDKs and proxyware covers that side, and what a residential proxy is covers the basics). The enforcement record describes four other channels, and in each the person whose line carries the traffic is not the person being paid.

Where involuntary residential exits come from (sources checked 2026-09-27)
ChannelHow it gets on the deviceDocumented exampleWho gets paid
Free VPNs and pirated softwareProxy malware packaged inside a free VPN, a pirated game or a pay-per-install bundle on a Windows PC911 S5, through MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN and ShineVPN (FBI) and pay-per-install bundles of pirated software (DOJ)The botnet operator: the indictment alleges its administrator received approximately $99 million from 2018 to July 2022
Pre-infected Android devicesA backdoor installed before sale, or loaded by an app, on off-brand, uncertified Android TV boxes, projectors, tablets, picture frames and car infotainment unitsBADBOX: in every case known to Germany’s BSI, the malware was already installed at purchase. BADBOX 2.0: HUMAN found the devices are not Play Protect certifiedProxy sellers on top of the backdoor: HUMAN saw one group offering residential proxy access at $13.64 per 5 GB routed through BADBOX 2.0 devices
Exploited routers and IoTKnown vulnerabilities in routers that no longer get patches; TheMoon malware “does not require a password”, per the FBIAnyproxy and 5socks (DOJ); SocksEscort, via a vulnerability in one brand’s residential modems (Europol); a password-spraying network made mostly of TP-Link routers (Microsoft)Subscription sellers: 5socks charged $9.95 to $110 a month under the slogan “Working since 2004!”, and its defendants are believed to have amassed more than $46 million
SDKs in apps, TV apps and extensionsA developer adds a monetisation SDK; the device joins the pool when the app runsIPIDEA’s Castar, Earn, Hex and Packet SDKs; over 600 apps and 3,075 Windows files seen contacting IPIDEA’s command domains (Google, January 2026); NetNut SDKs for smart TVs and streaming boxes (Google, July 2026)The app developer, “usually on a per-download basis” for IPIDEA, according to Google; then the network, which sells the exits

The SDK channel comes with a consent story, which is why it has its own post on proxyware SDKs. In short: HUMAN found free VPN apps on Google Play that turned phones into proxy nodes “without their knowledge”; the LumiApps SDK behind a later version shipped a sample consent screen, but HUMAN did not observe it in any app it found in the wild (HUMAN, March 2024, checked 2026-09-27). Secure Annex found the same model in browser extensions: a library that turns them into a web-scraping network, in extensions used by nearly 1,000,000 people (Secure Annex, July 2025, checked 2026-09-27).

The channels also feed each other. Google says IPIDEA’s SDKs “played a key role in adding devices” to the BadBox 2.0, Aisuru and Kimwolf botnets. Synthient bought devices of the models it saw most often and found them already running a malicious proxy SDK. It also reported that Kimwolf reached Android devices with an exposed debugging service through the residential proxy networks themselves: once a device joined a pool, Kimwolf “will have scanned and exploited the device within minutes” (Synthient, January 2026, checked 2026-09-27). Synthient adds that the Kimwolf actors named a binary to implicate IPIDEA, “which has no involvement with the Kimwolf actors”: one ecosystem, not one operator.

The takedowns, 2024–2026

Each row gives scale the way its source states it: IP addresses, devices or proxies for sale, on different dates, so the rows do not add up to one total.

Takedowns and reports on botnets behind residential proxies (sources checked 2026-09-27)
DateOperationScale, as the source states itSource
May 2024911 S5 dismantled, administrator arrested“More than 19 million unique IP addresses”, 613,841 of them in the US; “over 190 countries”DOJ; FBI IC3
Dec 2024BSI sinkholes BADBOX in GermanyCommunication cut on up to 30,000 devices in GermanyBSI
Mar 2025BADBOX 2.0 partially disrupted“More than 1 million devices” as of January 2025; traffic from 222 countries and territoriesHUMAN
May 2025Anyproxy and 5socks domains seized, four defendants charged“More than 7,000 proxies” for sale; the FBI later remediated 547 infected US routersDOJ; FBI IC3
Jun 2025FBI warning on BADBOX 2.0“Millions of infected devices”FBI IC3
Jul 2025Google sues the BadBox 2.0 operators in New York federal court“Over 10 million uncertified devices”Google
Jan 2026Kimwolf reportInfected devices “surpassed 2 million”; around 12 million unique IP addresses a weekSynthient
Jan 2026Google disrupts IPIDEAAvailable device pool reduced “by millions”Google (GTIG)
Mar 2026Aisuru, KimWolf, JackSkid and Mossad command-and-control infrastructure disrupted (DDoS botnets; Synthient reported that Kimwolf’s operators also sold residential proxy bandwidth)“Millions of devices”; more than three million as of March 2026DOJ
Mar 2026SocksEscort (Operation Lightning)“Over 369 000 routers and Internet of Things devices in 163 countries”; “over 35 000 proxies” offeredEuropol
May 2026KimWolf’s alleged administrator arrested in Canada“Over a million devices”DOJ
May 2026Dutch police and NCSC take a botnet offlineAt least 17 million infected devices, controlled from 200 servers in the Netherlands and used for cyberattacks (the statement does not say the botnet sold proxy access)Politie; NCSC
Jul 2026Google, with the FBI and others, acts against NetNut (“Popa”)“At least 2 million devices”Google (GTIG)

The same botnet gets different numbers because sources count at different moments and from different vantage points: BADBOX 2.0 was more than 1 million devices to HUMAN as of January 2025, “millions” to the FBI in June and over 10 million to Google in July. Addresses and devices are different units too. The DOJ counted 911 S5 in IP addresses associated with “millions of residential Windows computers”; Synthient saw about 2 million Kimwolf devices produce around 12 million unique addresses a week; Europol counted 369,000 compromised devices behind 35,000 proxies for sale. None of the counts is small.

NetNut’s parent company, Alarum Technologies, said in a press release filed with the SEC on 3 July 2026 (checked 2026-09-27) that certain NetNut domains had been seized by the FBI, that neither it nor NetNut had been formally contacted by the FBI or any other authority at that time, that part of its services was disrupted, and that it was investigating whether its network had been used for malicious purposes by third parties.

Try it

Put your own browser on the bench: the free scanner on the homepage returns the verdict the API returns, with every reason listed.

Open the scanner

What the botnets are rented for

The documented uses land on the forms most software companies run: signup, login and checkout.

  • Government benefit fraud. The US estimates that 560,000 fraudulent unemployment insurance claims came from IP addresses compromised by 911 S5, with a confirmed fraudulent loss above $5.9 billion, and that more than 47,000 Economic Injury Disaster Loan applications did too (DOJ, May 2024).
  • Checkout with stolen cards. The 911 S5 case started with about 2,525 fraudulent orders worth $5.5 million placed on the US military exchange’s online store, ShopMyExchange, through hijacked residential addresses. Card fraud detection and federal investigators stopped the bulk of them, and the actual loss came to about $254,000 (same DOJ release). The addresses looked like households; what held was everything else that was checked.
  • Credential stuffing. In April 2024 Okta reported a rise in the frequency and scale of credential stuffing attacks “facilitated by the broad availability of residential proxy services”; most of that traffic appeared “to originate from the mobile devices and browsers of everyday users, rather than from the IP space of VPS providers.”
  • Password spraying below every threshold. Microsoft reported in October 2024 that a network of compromised routers, mostly TP-Link, made only one sign-in attempt per account per day in about 80 percent of cases, with an average of 8,000 devices active at any given time. At that pace a per-account lockout rarely trips, and the attempts are spread thin across addresses.
  • Account creation and takeover. The BSI says BadBox can create email and messenger accounts without the owner noticing. HUMAN reports that Trend Micro researchers saw one BADBOX 2.0 group deploy payloads “to programmatically create accounts in online services”, and that an infected device in HUMAN’s own lab attempted an account takeover.
  • Everything else. Europol lists ransomware, DDoS attacks and child sexual abuse material among SocksEscort’s uses; the FBI lists bomb threats, identity theft and initial access brokering for 911 S5. Google saw over 550 threat groups use IPIDEA exits in one week of January 2026, password spraying included, and 316 threat clusters use suspected NetNut exits in one week of June 2026.

The login playbook is in credential stuffing through residential proxies.

Why an IP blocklist keeps losing

A list of bad addresses is the first thing most teams reach for. Four properties of these networks make it decay faster than it grows.

  1. The brand changes, the network does not. 911 S5 was taken offline by its administrator in July 2022 and rebranded as Cloudrouter in October 2023, according to the FBI. HUMAN found BADBOX 2.0 while watching what was left of the first BADBOX. Google names thirteen “ostensibly independent proxy and VPN brands” it says are controlled by the actors behind IPIDEA.
  2. Whitelabelling and reselling. Google says it has “high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet”, and that operators whose own botnet degrades “begin buying capacity from their competitors, effectively becoming a reseller.” The brand on the invoice says little about where an exit came from.
  3. Churn. Microsoft put the average uptime of a node in the router network it tracked at about 90 days. Synthient saw Kimwolf produce around 12 million unique addresses a week from about 2 million devices. A list of yesterday’s addresses describes yesterday.
  4. The exit is someone’s real connection. The owners of SocksEscort’s modems “would not be aware that their IP addresses were used for illegitimate activities”, Europol says. The same line carries its owners’ own traffic, possibly including your customer’s. Block the address and you block them, and keep blocking them after the device is cleaned (the FBI remediated 547 routers in the 5socks case alone).

What your signup or login form can still see

None of this makes the visit invisible; it makes the address the weakest thing to judge it by. What Maskbreak can tell you depends first on what you send it.

A bare IP lookup cannot see these exits. GET /v1/lookup checks an address against the Tor exit list and published cloud ranges. A botnet exit on a home broadband line is neither, so a lookup answers known: false and allow for it, which means neither list matched, not that the address is safe. VPN and proxy verdicts, and the operator name, come from a live visit: POST /v1/evaluate with the token the browser SDK collects on your page.

An exit already tied to a known pool returns network.proxy: true, the reason proxy_detected and decision: block by default, and network.service names the pool when known.

Computed with Maskbreak’s own response builder for a home-line exit already tied to a pool: 50 for the proxy and nothing for a datacenter, so a risk score of 50 and a block; residential reads false because the proxy flag fired. The address is a documentation range, EXAMPLE_POOL stands in for the pool name (null when unknown), and legacy fields, evaluated_in_ms and the device result are omitted.

An exit nobody has tied to a pool yet comes back as network.residential: true with empty reasons and decision: allow. That means nothing fired on the network side, not that the visitor is safe; it is what the renter paid for. The evidence then comes from the renter’s own machine, which the pool does not change:

  • Automation, a fake browser or an emulator block: automation_detected, antidetect_browser, emulator_detected. These come from the device half of the check, so send fingerprintEventId with every call.
  • A device clock that contradicts the exit’s country on an otherwise ordinary connection (send tz) adds timezone_mismatch and moves allow to review, never to block, because travellers produce it too.
  • The same device across accounts shows in device.linked_accounts (and the reason multi_account_device once it exceeds one) when you send your own server-side accountId. The pool gives each attempt a fresh address, never a fresh machine; a script that skips the browser arrives with no device evidence at all, which the example below holds.
  • A VPN alone is review, never block: an ordinary commercial VPN is not a botnet exit, and many customers use one.

Maskbreak is free during open beta, with no credit card and a standard allowance of 1,000 visitor checks per hour. The server side of a signup check looks like this; the browser SDK adds the monocle, sentinel_fp and sentinel_tz fields to your form, and the integration guide has the full watch-then-enforce version.

Node.js, server only
// Enforce path. Start in watch mode (log v.decision, always call next())
// for a few days, then switch.
app.post('/signup', async (req, res, next) => {
  const accountId = newUserId();            // your server-side id, never client input
  try {
    const r = await fetch('https://maskbreak.com/v1/evaluate', {
      method: 'POST',
      signal: AbortSignal.timeout(3000),
      headers: {
        'Authorization': 'Bearer ' + process.env.MASKBREAK_API_KEY,
        'Content-Type': 'application/json'
      },
      body: JSON.stringify({
        token: req.body.monocle,                  // the live visit, not a bare IP
        fingerprintEventId: req.body.sentinel_fp, // the device half
        accountId,                                // unlocks device.linked_accounts
        tz: req.body.sentinel_tz                  // device clock vs exit country
      })
    });
    if (!r.ok) throw new Error('Visitor check unavailable');
    const v = await r.json();
    if (v.test || v.sandbox || v.sample) throw new Error('No production verdict');
    if (v.decision === 'block') {
      return res.status(403).json({ error: 'Signup unavailable.' });
    }
    if (v.decision === 'review' || v.degraded || !v.device) {
      return res.status(409).json({ next: 'verify_email' }); // a step you can verify
    }
    // Count signups per device, never per IP: the exit rotates, the machine does not.
    await recordSignup(v.device.visitor_id, accountId);
    return next();
  } catch {
    return res.status(503).json({ error: 'Please try again shortly.' });
  }
});

For the detection side in depth (the tells that survive rotation, a response ladder and a device-keyed counter table), read how to detect residential proxies. The capability overview is on the proxy detection page, the full response schema in the evaluate reference, and the vocabulary in the glossary.

If you ship devices or apps

  • At home or in the office. The FBI’s BADBOX 2.0 warning lists the signs: an Android device that is not Play Protect certified or asks you to turn Play Protect off, a generic streaming box sold as “unlocked” or offering free content, an unrecognisable brand, apps from unofficial marketplaces, and unexplained internet traffic. The FBI’s TheMoon warning adds that routers from 2010 or earlier likely get no more updates: replace them and turn remote administration off.
  • In your app. A vendor paying you for your users’ “unused bandwidth” adds a channel from the table above to your product. Some stores forbid it: the Amazon Appstore policy (checked 2026-09-27) lists “Apps that facilitate proxy services to third parties (anyone other than the device owner)” as prohibited, and notes that VPN apps are not considered proxy service apps. The business model is covered in proxyware SDKs.

Questions people ask

What is a residential proxy botnet?
It is a set of compromised home devices, such as Windows PCs, Android TV boxes and routers, whose internet connections are sold as residential proxy exits without their owners knowing. Examples named by authorities include 911 S5, which the FBI says spread through free VPN apps bundled with pirated games and software, BADBOX 2.0 on uncertified Android devices, and SocksEscort on residential modems. To a website, traffic from these exits looks like an ordinary household.
How big are residential proxy botnets?
Each source counts in its own way. The US Justice Department tied 911 S5 to more than 19 million unique IP addresses; Google said BadBox 2.0 compromised over 10 million devices; Europol said SocksEscort compromised over 369,000 routers and IoT devices; Google put the NetNut network at a minimum of 2 million devices. The figures cover different dates and units, so they do not add up to one total.
Can you block botnet proxies by IP address?
Only in part. An exit already tied to a known proxy pool can be flagged: in a Maskbreak live evaluation it returns network.proxy true, the reason proxy_detected and a block, with the pool named when known. The rest rotate quickly, are resold under other brands and belong to real households, so a blocklist goes stale and blocks real customers. Count attempts per device rather than per address, and act on device signals such as automation, a fake browser or an emulator.
How do I know if my TV box is part of a botnet?
The FBI's June 2025 warning on BADBOX 2.0 lists the signs: an Android device that is not Play Protect certified, a device that asks you to disable Play Protect, a generic streaming box advertised as unlocked or offering free content, an unrecognisable brand, apps from unofficial marketplaces, and unexplained internet traffic on your network. The FBI recommends monitoring home network traffic and reporting suspected intrusions to its Internet Crime Complaint Center at ic3.gov.
Is renting a residential proxy illegal?
This is not legal advice. The enforcement actions described in this post targeted the operators and infrastructure of services that, according to the authorities, were built on devices compromised without their owners knowing. Whether a particular purchase is lawful depends on the service, how its exits were obtained, what the traffic is used for and the jurisdiction. Google's finding that many brands whitelabel the same network means a buyer often cannot tell from the brand where the exits come from.

Run the same check on your traffic

The free scanner on the homepage returns the verdict the API returns: network and device signals in one call, with every reason listed. What each signal means: bot detection and device fingerprinting.

Get started freeRead the API docs