Lumen Tracks Proxy Botnets Approaching 60 Million IPs
CyberScoop reported that Lumen Black Lotus Labs is tracking malicious residential proxy botnets approaching 60 million victim IP addresses, with takedowns failing to stop rapid rebuilds.

Malicious residential proxy botnets are approaching 60 million victim IP addresses, CyberScoop reported, turning ordinary home and office connections into a traffic layer that helps criminals hide behind legitimate-looking network paths.
The scale creates a disruption problem as much as an infection problem.
Lumen Technologies' Black Lotus Labs found botnet operators rebuilding quickly after takedowns, while compromised routers, cameras, smart devices and other poorly defended equipment continue to feed new proxy capacity.
Lumen Maps The Proxy Botnet Scale
Black Lotus Labs senior information security engineer Chris Formosa told CyberScoop that the lab's view of the global botnet population is approaching 60 million victim IP addresses.
He said roughly 1 in 4 of those IPs are in the United States, while the device count is likely higher because a single IP address can represent several compromised devices.
The largest clusters operate at a scale normally associated with infrastructure providers rather than isolated malware crews.
Black Lotus Labs said it observed an average of 10 distinct botnets, with each controlling about 1 million active victims a day.
Black Lotus Labs said it tracks more than 30 malicious proxy botnet clusters, most of which regularly exceed 100,000 daily victims.
Residential Proxies Let Criminal Traffic Blend In
A residential proxy routes someone else's traffic through an internet connection that appears to belong to a normal household or business.
That cover is valuable for fraud, scraping, credential attacks, spam, DDoS activity and other abuse because a defender sees traffic coming from a familiar access network instead of an obvious data-centre host.
The proxy market also changes the economics of takedowns.
Formosa told CyberScoop that the growth persists because buyers want routine access to millions of IP addresses.
Operators can sell access, resell capacity or shift demand between botnet services when law enforcement or private-sector defenders disrupt one provider.
IPIDEA Rebuilt After January Disruption
IPIDEA gave the researchers a case study in resilience.
Black Lotus Labs researchers put the January disruption against a later rebuild: the residential proxy network recovered to nearly half strength within hours and later passed its pre-disruption size with about 10 million IPs.
Ryan English, an information security engineer at Black Lotus Labs, called the speed of the rebound unusual even against other botnets that have rebuilt after takedowns.
The result left defenders facing not just infected endpoints, but a supply chain that can reassemble capacity quickly enough to keep proxy services useful to customers.
Older Devices Keep Feeding The Botnet Pool
The device pipeline remains broad.
English put the vulnerable pool available to proxy hunters at more than 1 billion devices, a supply that expands as inexpensive internet-connected hardware ships with weak defences and older products lose security updates while staying in use.
Black Lotus Labs framed isolated takedowns as short-lived remedies because multiple residential proxy services can cooperate and move millions of IPs within hours.
The public material does not name a regulatory mechanism or provider commitment that would remove capacity across cooperating proxy services.




















