Threat reportThreat IntelligenceTL-2026-1467

Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defenses

mediumACTIVE

Residential Proxy Rotation Networks Defeat (TL-2026-1467), also tracked as The Rotation Economy, is a medium-severity tracked intrusion set, first published 2026-04-02. It has no confirmed attribution, affects N/A IP-reputation-based network defenses (blocklists, geo-IP, maps to 26 MITRE ATT&CK techniques (T1005, T1018, T1036), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
26MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1467

Threat ID
TL-2026-1467
Also known as
The Rotation Economy, Invisible Army
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, finance, government administration, ecommerce, telecoms, criticalinfrastructure
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
20

Malware and tooling in Residential Proxy Rotation Networks Defeat

Malware and tooling: BadBox 2.0, aisuru, kimwolf, GreyNoise, IPIDEA-proxy-client-sdk

How Residential Proxy Rotation Networks Defeat works

GreyNoise analysis of 4 billion internet-edge sessions over 90 days found 39% of unique attacking IPs originate from residential connections, with 78% of those IPs seen at most twice and averaging fewer than 3 sessions before rotating out of visibility — structurally defeating IP-reputation blocklists. Three major law-enforcement/industry disruptions (Google/IPIDEA, DOJ/911 S5, Operation Moonlander/AnyProxy-5Socks) confirm the scale of the underlying proxy-for-hire ecosystem used by 550+ threat groups spanning nation-state and cybercriminal actors.

GreyNoise Intelligence's April 2026 report, "The Invisible Army: Why IP Reputation Fails Against the Rotation Economy," analyzed 4 billion internet-edge sessions collected over a 90-day observation window. The core finding is a structural one: 39% of unique attacking IP addresses originate from residential/consumer ISP connections (versus 22% of total sessions), and of those residential IPs, 78% are observed no more than twice, with a median of 1 session per address and an average of fewer than 3 sessions before the address rotates out of the visible attack surface. This rotation cadence means that by the time a reputation feed ingests, scores, and propagates a malicious IP, the underlying infrastructure has already moved on to a new address — rendering static IP-reputation blocklists and long-lived deny-lists structurally ineffective against this traffic class.

GreyNoise's payload analysis shows residential-sourced sessions carry exploitation code far less often than hosting-provider-sourced sessions (0.1% vs 1.0%), consistent with residential nodes being used primarily as anonymizing relay/proxy infrastructure rather than as the origin of exploit payloads themselves — the actual attacker sits behind the proxy layer. A striking behavioral signature was identified in SMB worm-propagation traffic: 84% of SMB-based propagation activity originates from residential IP space, with zero population overlap against Telnet-sourced scanning, suggesting distinct botnet cohorts (compromised home routers/IoT vs. compromised home PCs) are being used for different attack modalities. Diurnal traffic analysis reinforces the compromised-device theory: India-geolocated attack traffic drops 34% between daytime peak and overnight hours, while equivalent server/hosting-sourced traffic varies less than 3% across the same window — consistent with the residential nodes being unwitting/infected home PCs and IoT devices that get powered off overnight, not willing paid VPN participants.

The underlying proxy-for-hire ecosystem enabling this rotation economy has been the target of three major disruption actions documented in the same period. Google's Threat Intelligence Group (GTIG) disrupted the IPIDEA residential proxy network in a 72-hour operation beginning January 28, 2026, obtaining a court order to remove dozens of IPIDEA-owned domains. IPIDEA served as backend infrastructure secretly powering at least 13 different proxy/VPN storefront brands, with 9-11 million daily active proxy exit nodes. In a single 7-day observation window, GTIG identified over 550 distinct threat groups — including state-sponsored clusters tracked to China, North Korea (DPRK), Iran, and Russia — routing operational traffic through IPIDEA exit nodes to obfuscate origin. IPIDEA's SDKs were found embedded in multiple Android botnets, most notably BadBox 2.0 (the subject of prior Google legal action), as well as the more recently identified Aisuru and Kimwolf botnets, with the SDK responsible for silently enrolling devices into the proxy pool and the accompanying proxy client software then used by threat actors to route traffic through those enrolled devices.

The DOJ's 2024 dismantlement of the 911 S5 botnet (referenced in the GreyNoise report as evidence of ecosystem scale) remains the largest confirmed case of its kind: 19 million compromised residential/IoT devices across 190+ countries, administered by Chinese national YunHe Wang (arrested in Singapore, May 24, 2024) from 2014-2022. Wang monetized the botnet by leasing proxy access to cybercriminals, generating approximately $99 million in revenue between 2018-2022; downstream abuse of the leased infrastructure is estimated by DOJ to have enabled over $5.9 billion in fraudulent U.S. pandemic-era unemployment insurance and Economic Injury Disaster Loan (EIDL) claims. The takedown seized 23 domains, 70+ servers, ~$29 million in cryptocurrency, and ~$30 million in real estate.

A third disruption, "Operation Moonlander" (announced May 2025), targeted the AnyProxy and 5Socks residential proxy services, which had operated since approximately 2004 by compromising end-of-life home and small-business routers with known, unpatched vulnerabilities. Four defendants — Russian nationals Alexey Viktorovich Chertkov, Kirill Vladimirovich Morozov, Aleksandr Aleksandrovich Shishkin, and Kazakhstani national Dmitriy Rubtsov — were indicted for operating the services, which generated an estimated $46 million in subscription revenue from over 7,000 compromised residential IP addresses sold to cybercriminal customers. The joint operation involved the FBI, Dutch National Police, the Netherlands Public Prosecution Service, Royal Thai Police, and Lumen Technologies' Black Lotus Labs.

Collectively, these three cases (IPIDEA: ~10M devices/550+ threat groups; 911 S5: 19M devices/190 countries; AnyProxy-5Socks: 7,000+ devices/$46M revenue over 20 years) demonstrate that the residential-proxy-for-hire market is mature, large-scale, multi-vendor, and used indiscriminately by both nation-state APT clusters and financially motivated cybercriminal groups to defeat network-layer geolocation and reputation controls. No single CVE or vendor product is implicated; this is a structural evasion-technique and infrastructure trend directly relevant to detection engineering, specifically the tuning of IP-reputation feeds, rate-limiting logic, and behavioral/session-based detection to compensate for the collapse of address-based blocking.

MITRE ATT&CK techniques used in TL-2026-1467

Collection

T1005 Data from Local System

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Defense Evasion

T1036 Masquerading

Execution

T1072 Software Deployment Tools

Command and Control

T1090 Proxy; T1090.003 Multi-hop Proxy; T1102 Web Service; T1568 Dynamic Resolution

command-and-control

T1090.002 External Proxy; T1090.003 Multi-hop Proxy

Lateral Movement

T1091 Replication Through Removable Media; T1210 Exploitation of Remote Services

Credential Access

T1110.003 Password Spraying; T1110.004 Credential Stuffing

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Impact

T1496 Resource Hijacking; T1498 Network Denial of Service

Persistence

T1505 Server Software Component; T1525 Implant Internal Image

Resource Development

T1583.005 Botnet; T1584.005 Botnet; T1585 Establish Accounts; T1587.001 Malware

defense-impairment

T1601.002 Downgrade System Image

stealth

T1684.001 Impersonation

Affected products and versions in Residential Proxy Rotation Networks Defeat

  • N/A — IP-reputation-based network defenses (blocklists, geo-IP filtering, static deny-lists)
    Vulnerable versions: All implementations relying solely on static/long-TTL IP reputation scoring
    Fixed in: N/A - architectural/detection-methodology issue, not a patchable product

Remediation for Residential Proxy Rotation Networks Defeat

Immediate actions

  • Shift from static IP-reputation blocklisting to behavioral and session-based detection for edge-facing services
  • Deploy rate-limiting and anomaly detection keyed on request patterns (velocity, header entropy, TLS/JA3 fingerprint, login-failure clustering) rather than source IP alone
  • Flag and monitor traffic matching known residential-proxy ASN/ISP ranges combined with automation signatures (missing browser fingerprint entropy, headless client patterns)
  • Correlate authentication and API abuse events across sessions using device/browser fingerprinting and behavioral biometrics instead of relying on IP as an identity proxy
  • Block or heavily scrutinize traffic still resolving to seized/sinkholed IPIDEA, 911 S5, and AnyProxy/5Socks C2 and exit-node infrastructure where indicators remain published by GTIG/DOJ/Lumen

Workarounds

  • Layer CAPTCHA/proof-of-work challenges on high-value authentication and checkout flows to raise the cost of automation regardless of proxy rotation
  • Require step-up authentication (MFA) when a session's IP reputation is unknown/residential-flagged in combination with other risk signals

Longer-term hardening

  • Adopt GreyNoise/threat-intel feeds specifically scored for proxy/anonymization-network origin rather than generic malicious-IP reputation
  • Invest in credential-stuffing and bot-management platforms that use behavioral risk scoring (mouse/touch telemetry, timing, session graph analysis) as the primary control, with IP reputation as a secondary weak signal only
  • Harden edge devices and home/SOHO routers within managed fleets against known end-of-life vulnerabilities to reduce the compromised-device pool feeding these proxy networks
  • Participate in industry information-sharing (Google GTIG, Lumen Black Lotus Labs, GreyNoise) to receive updated IOC feeds as proxy infrastructure is re-established post-takedown

Timeline of Residential Proxy Rotation Networks Defeat

  • AnyProxy and 5Socks residential proxy services begin operation, building their network by compromising end-of-life home and small-business routers with known vulnerabilities.
  • YunHe Wang begins creating and administering the 911 S5 proxy botnet.
  • 911 S5 operator YunHe Wang's active administration period concludes, having generated an estimated $99 million from proxy leasing since 2018.
  • YunHe Wang is arrested in Singapore for creating and administering the 911 S5 botnet.
  • DOJ announces dismantlement of the 911 S5 botnet (19 million devices, 190+ countries); seizure of 23 domains, 70+ servers, ~$29M cryptocurrency, ~$30M real estate.
  • FBI-led Operation Moonlander, with Dutch National Police, Netherlands Public Prosecution Service, Royal Thai Police, and Lumen Black Lotus Labs, dismantles the AnyProxy and 5Socks residential proxy botnets (7,000+ devices, $46M revenue) and indicts four Russian/Kazakhstani administrators.
  • Google Threat Intelligence Group begins a 72-hour operation disrupting the IPIDEA residential proxy network, obtaining a court order to remove dozens of IPIDEA-owned domains.
  • Google publishes findings on the IPIDEA takedown, revealing 9-11 million daily active proxies, 13 downstream proxy/VPN brands, and 550+ threat groups (including China-, DPRK-, Iran-, and Russia-nexus actors) observed using IPIDEA exit nodes in a single 7-day window; links IPIDEA SDKs to the BadBox 2.0, Aisuru, and Kimwolf botnets.
  • TL-Intel-Harness hunt phase surfaces the GreyNoise report via RSS ingestion for threat intelligence tracking.
  • GreyNoise publishes "The Invisible Army: Why IP Reputation Fails Against the Rotation Economy," analyzing 4 billion sessions over the preceding 90 days and quantifying the structural failure of IP-reputation-based defenses against residential proxy rotation.

Sources cited for Residential Proxy Rotation Networks Defeat

Detection coverage for TL-2026-1467

As of 2026-04-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1467 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats