# Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defenses

> GreyNoise analysis of 4 billion internet-edge sessions over 90 days found 39% of unique attacking IPs originate from residential connections, with 78% of those IPs seen at most twice and averaging fewer than 3 sessions before rotating out of visibility — structurally defeating IP-reputation blocklists. Three major law-enforcement/industry disruptions (Google/IPIDEA, DOJ/911 S5, Operation Moonlander/AnyProxy-5Socks) confirm the scale of the underlying proxy-for-hire ecosystem used by 550+ threat groups spanning nation-state and cybercriminal actors.

- **Published:** 2026-04-02T00:00:00Z
- **Last reviewed:** 2026-04-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1467
- **ID:** TL-2026-1467
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

GreyNoise Intelligence's April 2026 report, "The Invisible Army: Why IP Reputation Fails Against the Rotation Economy," analyzed 4 billion internet-edge sessions collected over a 90-day observation window. The core finding is a structural one: 39% of unique attacking IP addresses originate from residential/consumer ISP connections (versus 22% of total sessions), and of those residential IPs, 78% are observed no more than twice, with a median of 1 session per address and an average of fewer than 3 sessions before the address rotates out of the visible attack surface. This rotation cadence means that by the time a reputation feed ingests, scores, and propagates a malicious IP, the underlying infrastructure has already moved on to a new address — rendering static IP-reputation blocklists and long-lived deny-lists structurally ineffective against this traffic class.

GreyNoise's payload analysis shows residential-sourced sessions carry exploitation code far less often than hosting-provider-sourced sessions (0.1% vs 1.0%), consistent with residential nodes being used primarily as anonymizing relay/proxy infrastructure rather than as the origin of exploit payloads themselves — the actual attacker sits behind the proxy layer. A striking behavioral signature was identified in SMB worm-propagation traffic: 84% of SMB-based propagation activity originates from residential IP space, with zero population overlap against Telnet-sourced scanning, suggesting distinct botnet cohorts (compromised home routers/IoT vs. compromised home PCs) are being used for different attack modalities. Diurnal traffic analysis reinforces the compromised-device theory: India-geolocated attack traffic drops 34% between daytime peak and overnight hours, while equivalent server/hosting-sourced traffic varies less than 3% across the same window — consistent with the residential nodes being unwitting/infected home PCs and IoT devices that get powered off overnight, not willing paid VPN participants.

The underlying proxy-for-hire ecosystem enabling this rotation economy has been the target of three major disruption actions documented in the same period. Google's Threat Intelligence Group (GTIG) disrupted the IPIDEA residential proxy network in a 72-hour operation beginning January 28, 2026, obtaining a court order to remove dozens of IPIDEA-owned domains. IPIDEA served as backend infrastructure secretly powering at least 13 different proxy/VPN storefront brands, with 9-11 million daily active proxy exit nodes. In a single 7-day observation window, GTIG identified over 550 distinct threat groups — including state-sponsored clusters tracked to China, North Korea (DPRK), Iran, and Russia — routing operational traffic through IPIDEA exit nodes to obfuscate origin. IPIDEA's SDKs were found embedded in multiple Android botnets, most notably BadBox 2.0 (the subject of prior Google legal action), as well as the more recently identified Aisuru and Kimwolf botnets, with the SDK responsible for silently enrolling devices into the proxy pool and the accompanying proxy client software then used by threat actors to route traffic through those enrolled devices.

The DOJ's 2024 dismantlement of the 911 S5 botnet (referenced in the GreyNoise report as evidence of ecosystem scale) remains the largest confirmed case of its kind: 19 million compromised residential/IoT devices across 190+ countries, administered by Chinese national YunHe Wang (arrested in Singapore, May 24, 2024) from 2014-2022. Wang monetized the botnet by leasing proxy access to cybercriminals, generating approximately $99 million in revenue between 2018-2022; downstream abuse of the leased infrastructure is estimated by DOJ to have enabled over $5.9 billion in fraudulent U.S. pandemic-era unemployment insurance and Economic Injury Disaster Loan (EIDL) claims. The takedown seized 23 domains, 70+ servers, ~$29 million in cryptocurrency, and ~$30 million in real estate.

A third disruption, "Operation Moonlander" (announced May 2025), targeted the AnyProxy and 5Socks residential proxy services, which had operated since approximately 2004 by compromising end-of-life home and small-business routers with known, unpatched vulnerabilities. Four defendants — Russian nationals Alexey Viktorovich Chertkov, Kirill Vladimirovich Morozov, Aleksandr Aleksandrovich Shishkin, and Kazakhstani national Dmitriy Rubtsov — were indicted for operating the services, which generated an estimated $46 million in subscription revenue from over 7,000 compromised residential IP addresses sold to cybercriminal customers. The joint operation involved the FBI, Dutch National Police, the Netherlands Public Prosecution Service, Royal Thai Police, and Lumen Technologies' Black Lotus Labs.

Collectively, these three cases (IPIDEA: ~10M devices/550+ threat groups; 911 S5: 19M devices/190 countries; AnyProxy-5Socks: 7,000+ devices/$46M revenue over 20 years) demonstrate that the residential-proxy-for-hire market is mature, large-scale, multi-vendor, and used indiscriminately by both nation-state APT clusters and financially motivated cybercriminal groups to defeat network-layer geolocation and reputation controls. No single CVE or vendor product is implicated; this is a structural evasion-technique and infrastructure trend directly relevant to detection engineering, specifically the tuning of IP-reputation feeds, rate-limiting logic, and behavioral/session-based detection to compensate for the collapse of address-based blocking.

## MITRE ATT&CK

- T1583.005 Botnet
- T1584.005 Botnet
- T1585 Establish Accounts
- T1587.001 Malware
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1072 Software Deployment Tools
- T1505 Server Software Component
- T1525 Implant Internal Image
- T1090.003 Multi-hop Proxy
- T1090.002 External Proxy
- T1684.001 Impersonation
- T1036 Masquerading
- T1601.002 Downgrade System Image
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1210 Exploitation of Remote Services
- T1091 Replication Through Removable Media
- T1090.003 Multi-hop Proxy
- T1090 Proxy
- T1102 Web Service
- T1568 Dynamic Resolution
- T1496 Resource Hijacking
- T1498 Network Denial of Service
- T1005 Data from Local System
- T1110.004 Credential Stuffing
- T1110.003 Password Spraying

## Sources

- [The Invisible Army: Why IP Reputation Fails Against the Rotation Economy](https://www.greynoise.io/blog/invisible-army-why-ip-reputation-fails-against-rotation-economy)
- [Disrupting the World's Largest Residential Proxy Network](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network)
- [Google dismantled IPIDEA, the world's largest residential proxy network](https://cyberinsider.com/google-dismantled-ipidea-the-worlds-largest-residential-proxy-network/)
- [Google targets IPIDEA in crackdown on global residential proxy networks](https://securityaffairs.com/187463/security/google-targets-ipidea-in-crackdown-on-global-residential-proxy-networks.html)
- [Google disrupts proxy network used by 550+ threat groups](https://www.helpnetsecurity.com/2026/01/29/ipidea-proxy-network-disrupted/)
- [US Dismantles World's Largest 911 S5 Botnet with 19 Million Infected Devices](https://thehackernews.com/2024/05/us-dismantles-worlds-largest-911-s5.html)
- [911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation](https://www.justice.gov/archives/opa/pr/911-s5-botnet-dismantled-and-its-administrator-arrested-coordinated-international-operation)
- [911 S5 Botnet Dismantled and Its Administrator Arrested](https://flashpoint.io/blog/911-s5-botnet-dismantled/)
- [FBI and Dutch police seize and shut down botnet of hacked routers](https://techcrunch.com/2025/05/09/fbi-and-dutch-police-seize-and-shut-down-botnet-of-hacked-routers/)
- [Botnet Dismantled in International Operation, Russian and Kazakhstani Administrators Indicted](https://www.justice.gov/usao-ndok/pr/botnet-dismantled-international-operation-russian-and-kazakhstani-administrators)
- [US seizes Anyproxy, 5socks botnets and indicts alleged administrators](https://cyberscoop.com/anyproxy-5socks-botnets-seized/)
- [Law enforcement takes down proxy botnets used by criminals](https://www.helpnetsecurity.com/2025/05/12/law-enforcement-takes-down-proxy-botnets-5socks-anyproxy-used-by-criminals/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1467
