News
MARKET SIGNAL:

Lumen Tracks Proxy Botnets Approaching 60 Million IPs

Newsroom brief

CyberScoop reported that Lumen Black Lotus Labs is tracking malicious residential proxy botnets approaching 60 million victim IP addresses, with takedowns failing to stop rapid rebuilds.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
Lumen Tracks Proxy Botnets Approaching 60 Million IPs
Image source: cyberscoop.com

Malicious residential proxy botnets are approaching 60 million victim IP addresses, CyberScoop reported, turning ordinary home and office connections into a traffic layer that helps criminals hide behind legitimate-looking network paths.

The scale creates a disruption problem as much as an infection problem.

Lumen Technologies' Black Lotus Labs found botnet operators rebuilding quickly after takedowns, while compromised routers, cameras, smart devices and other poorly defended equipment continue to feed new proxy capacity.

Lumen Maps The Proxy Botnet Scale

Black Lotus Labs senior information security engineer Chris Formosa told CyberScoop that the lab's view of the global botnet population is approaching 60 million victim IP addresses.

He said roughly 1 in 4 of those IPs are in the United States, while the device count is likely higher because a single IP address can represent several compromised devices.

The largest clusters operate at a scale normally associated with infrastructure providers rather than isolated malware crews.

Black Lotus Labs said it observed an average of 10 distinct botnets, with each controlling about 1 million active victims a day.

Black Lotus Labs said it tracks more than 30 malicious proxy botnet clusters, most of which regularly exceed 100,000 daily victims.

Residential Proxies Let Criminal Traffic Blend In

A residential proxy routes someone else's traffic through an internet connection that appears to belong to a normal household or business.

That cover is valuable for fraud, scraping, credential attacks, spam, DDoS activity and other abuse because a defender sees traffic coming from a familiar access network instead of an obvious data-centre host.

The proxy market also changes the economics of takedowns.

Formosa told CyberScoop that the growth persists because buyers want routine access to millions of IP addresses.

Operators can sell access, resell capacity or shift demand between botnet services when law enforcement or private-sector defenders disrupt one provider.

IPIDEA Rebuilt After January Disruption

IPIDEA gave the researchers a case study in resilience.

Black Lotus Labs researchers put the January disruption against a later rebuild: the residential proxy network recovered to nearly half strength within hours and later passed its pre-disruption size with about 10 million IPs.

Ryan English, an information security engineer at Black Lotus Labs, called the speed of the rebound unusual even against other botnets that have rebuilt after takedowns.

The result left defenders facing not just infected endpoints, but a supply chain that can reassemble capacity quickly enough to keep proxy services useful to customers.

Older Devices Keep Feeding The Botnet Pool

The device pipeline remains broad.

English put the vulnerable pool available to proxy hunters at more than 1 billion devices, a supply that expands as inexpensive internet-connected hardware ships with weak defences and older products lose security updates while staying in use.

Black Lotus Labs framed isolated takedowns as short-lived remedies because multiple residential proxy services can cooperate and move millions of IPs within hours.

The public material does not name a regulatory mechanism or provider commitment that would remove capacity across cooperating proxy services.

Share this article
inXf

Related articles

More
Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain
Cybersecurity

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain

Bright Data's SDK has been reverse-engineered in research showing how free apps can turn consumer devices, including smart TVs, into residential proxy nodes for web-scraping traffic. The issue matters because AI data harvesting is increasing demand for residential IPs, while consent screens and background network behavior may not be clear to users or IT teams.

Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study
Cybersecurity

Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study

Palo Alto Networks’ Unit 42 said its phantom-squatting research generated 685,339 prompts across 913 brands and produced 2.1 million unique URLs, including 13,229 malicious URLs and about 250,000 unique phantom domains. The public report did not disclose the brand list, affected customer names or named domains tied to data loss.

Socket Tracks 108 Malicious Packages In PolinRider Supply-Chain Attack
Cybersecurity

Socket Tracks 108 Malicious Packages In PolinRider Supply-Chain Attack

Socket reported 162 malicious release artefacts across 108 packages in the PolinRider supply-chain campaign. Victim companies remain outside the public record.

UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan
Cybersecurity

UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan

The UAE’s 3rd Government Cybersecurity Summit in Abu Dhabi framed cyber defence as a national resilience issue, linking AI-enabled threats, telecom exposure, data compression and regional cooperation.

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem
Cybersecurity

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem

Palo Alto Networks shares fell more than 4% after stronger quarterly results and current-quarter guidance failed to satisfy investors looking for faster AI-linked earnings upside. CEO Nikesh Arora reiterated a fiscal 2030 target of more than 4,000 platformizations and a USD 20 billion NGS ARR goal. The practical question is whether AI-related security demand turns into NGS ARR progress as data center infrastructure is ordered, installed and brought online.

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Cybersecurity

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

Neo Raises $100M To Control Enterprise AI Software Actions
Cybersecurity

Neo Raises $100M To Control Enterprise AI Software Actions

SecurityWeek reported that Neo emerged from stealth with $100 million for a platform that governs AI agents, MCP servers and software actions across enterprise systems.

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk
Cybersecurity

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk

Socket, Ox Security and StepSecurity said they detected wallet-stealing code in @injectivelabs/sdk-ts npm package version 1.20.21 after an Injective Labs contributor account was compromised. Socket said the malicious release was downloaded 310 times before deprecation, while Ox Security counted 87 direct dependencies and described a six-figure cumulative download count across dependent packages.

Keep Reading

More Stories

Latest
Ramp And FIS Add AI Controls For Spend And Payments SecurityFintech & Digital PaymentsJul 27, 2026Ramp And FIS Add AI Controls For Spend And Payments SecurityRamp launched controls for AI spending while FIS joined Anthropic Project Glasswing to test Mythos 5 against payment-infrastructure vulnerabilities, leaving adoption and measured security results outside the public record.UAE Statistics Programme Targets AI-Ready Official DataCapital & PolicyJul 27, 2026UAE Statistics Programme Targets AI-Ready Official DataThe UAE has approved a national programme to improve official statistics as government agencies seek higher-quality data for economic policy and artificial intelligence systems.SourTrade Malvertising Makes Browsers Assemble Windows MalwareCybersecurityJul 27, 2026SourTrade Malvertising Makes Browsers Assemble Windows MalwareThe Hacker News reported that Confiant analysed SourTrade, a malvertising campaign that uses fake trading pages and browser-side assembly to vary Windows malware files for retail trading and crypto targets.Shopify Reworks Theme Code For AI Agents And ReadabilityAIJul 27, 2026Shopify Reworks Theme Code For AI Agents And ReadabilityShopify is preparing a cleaner storefront theme that shifts from JSON-heavy configuration toward mostly HTML and Liquid, as AI-assisted theme editing makes readable code and explicit contracts more important.Empery Invests $20 Million In Cardinal Data PowerCloud & Data CentersJul 27, 2026Empery Invests $20 Million In Cardinal Data PowerEmpery Digital invested $20 million in Cardinal Data Power, backing a West Texas data centre campus plan with a 750MW first phase and potential expansion beyond 5GW.AI Distillation Debate Moves From Labs To WashingtonAIJul 27, 2026AI Distillation Debate Moves From Labs To WashingtonCNBC reported that AI distillation has become a policy fight after Moonshot AI's Kimi K3 raised questions about open-weight models, proprietary model output and U.S. restrictions.Hugging Face Adds 4-Bit Nunchaku Loading To DiffusersChips & SemiconductorsJul 27, 2026Hugging Face Adds 4-Bit Nunchaku Loading To DiffusersHugging Face added Nunchaku Lite support to Diffusers, letting developers load 4-bit diffusion checkpoints with `from_pretrained()` while using Hub-delivered CUDA kernels.CFTC Warning Narrows Prediction-Market Contract FilingsFintech & Digital PaymentsJul 27, 2026CFTC Warning Narrows Prediction-Market Contract FilingsCoinDesk reported on July 26 that the CFTC warned prediction-market operators against broad template certifications, tightening the filing burden for event contracts while courts still test the regulator’s authority.B Capital Names Ex-G42 AI Chief To Doha Investment RoleAIJul 27, 2026B Capital Names Ex-G42 AI Chief To Doha Investment RoleB Capital has appointed former G42 executive Dr Andrew Jackson as General Partner and Chief AI Officer in Doha, tying the firm’s Gulf office to AI investment governance and Stargate UAE experience.Ajman AI Agent Renews Trade Licences Through AjmanOneEconomyJul 27, 2026Ajman AI Agent Renews Trade Licences Through AjmanOneMiddle East AI News reported that Ajman used agentic AI to renew a trade licence through AjmanOne, moving a government service from chatbot support toward an automated transaction flow that still depends on governed data and system integration.AMD Helios AI Racks Bring Epyc CPUs To Nvidia Compute ChallengeChips & SemiconductorsJul 26, 2026AMD Helios AI Racks Bring Epyc CPUs To Nvidia Compute ChallengeData Center Knowledge reported that AMD moved Helios into production with MI455X GPUs, Epyc processors, Pensando networking and ROCm software, while vendor performance claims still lack third-party benchmark validation.Dubai Airports Adds Smart Gate Pre-Check Before Summer PeakEconomyJul 26, 2026Dubai Airports Adds Smart Gate Pre-Check Before Summer PeakEconomy Middle East reported that Dubai Airports launched a Smart Gates Eligibility Pre-Check at DXB, letting passengers confirm eligibility through Pocket Flights or terminal QR codes before passport control.