Proliferation of Residential Proxy Botnets Threatens Cybersecurity

Proliferation of Residential Proxy Botnets Threatens Cybersecurity

First seen 24 Jul 2026, 21:20 UTC LumenCyberscoopsynthient.comcloud.google.comblog.xlab.qianxin.com+1 88% similarity 66.5

Article Content

Browse articles
ThreatCluster

Residential proxy networks are facilitating the growth of botnets, with Lumen's Black Lotus Labs reporting nearly 60 million compromised IP addresses worldwide. Approximately 25% of these are in the U.S., with many devices unknowingly participating in malicious proxy networks. The demand for these proxies is rising, driven by cybercriminals seeking anonymity and cover for their activities. Despite recent takedowns, botnets are rebounding quickly, with some recovering to pre-disruption sizes within hours. Lumen tracks over 30 distinct malicious proxy botnet clusters, each with over 100,000 daily victims. The challenge for defenders is significant, as the supply of vulnerable devices continues to grow. The report emphasizes the urgent need for coordinated action across the security community to combat this evolving threat.

Key Points: • Lumen reports nearly 60 million compromised IP addresses due to residential proxy botnets. • About 25% of these compromised IPs are located in the United States. • Botnets are rebounding quickly after takedowns, with some recovering to full strength within hours.

ThreatCluster AI

Timeline

2026-07-24
Lumen releases report on residential proxy botnets
Lumen's Black Lotus Labs reveals the scale of botnets powered by residential proxy networks, affecting millions globally.
Lumen
2026-07-24
Cyberscoop reports on botnet growth
Cyberscoop highlights Lumen's findings, noting the rapid recovery of botnets post-takedown and the increasing number of compromised devices.
Cyberscoop

Community

Browse all →