Skip to content
New Report from GreyNoise Intelligence Points to a Significant Number of Compromised ...

New Report from GreyNoise Intelligence Points to a Significant Number of Compromised ...

Greynoise • April 2, 2026

‍ Washington, DC – April 2, 2026 – GreyNoise Intelligence, the cybersecurity company providing real-time intelligence network-based attacks, today released a new report entitled " The Invisible Army: Residential Proxy Abuse in Internet-Scale Attack Traffic ,” based on 4 billion malicious sessions observed targeting edge devices over 90 days. The data reveals a disturbing pattern of attackers using compromised internet connections as a disguise to route malicious traffic.

“Much of the security industry built defenses around the idea that you can determine intent from an IP address,” said Ash Devata, CEO, GreyNoise Intelligence. “This research proves that assumption is now broken at scale. Nearly 4 in 10 IPs hitting our sensors are residential IPs, indicating the scale with which internet gear has been compromised. Attackers have weaponized the infrastructure we trust most, and every organization that relies on IP reputation as a primary defensive layer is exposed right now.”

In January 2026, Google Threat Intelligence Group disrupted IPIDEA , one of the world’s largest residential proxy networks, with 9 to 11 million daily active proxies used by over 550 distinct threat groups, including state- actors from China, DPRK, Iran, and Russia. In May 2024, the US Department of Justice dismantled 911 S5 , consisting of 19 million IPs across 190 countries. Mandiant’s M-Trends 2025 also documented state threat actors routing operations through residential infrastructure.

For this research, GreyNoise leveraged its Global Observation Grid (GOG), with coverage across 80+ countries to observe unsolicited internet traffic for 90 days, between November 29, 2025-February 27, 2026. The dataset encompasses 4,020,000,000 sessions from 5,720,000 unique source IPs targeting internet-facing infrastructure, excluding known benign scanners and spoofable traffic. GreyNoise’s network observes scanning and probing attempts that also reach internet-facing infrastructure. The company observes techniques and scale; it cannot confirm compromise of production systems.

Key findings from the report include:

"Residential proxies are nightmare fuel for defenders,” said Andrew Morris, Founder and Chief Architect at GreyNoise. “They flip every IP and geolocation-based defense on its head. AI content scrapers have massively driven up demand for these networks, and the businesses behind them are not thinking security or abuse — the incentives are misaligned in a perfect storm. Nation-states are tunneling attack and C2 traffic through regular people's phones during active conflict, and this is only going to get worse."

Security teams need to shift their focus from IP reputation and develop a deeper understanding of the behavioral patterns around internet traffic. This report outlines the full scale of this problem and provides actionable recommendations for better defense against residential proxy abuse.

To download the full GreyNoise Intelligence report "The Invisible Army: Residential Proxy Abuse in Internet-Scale Attack Traffic," please visit: .

GreyNoise Intelligence

Extracted Entities