- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,243
53 million accomplices who do not know anything about anything.

Millions of home devices around the world imperceptibly for owners help cybercriminals hide attacks, circumvent company protection and hack other people’s accounts. BitSight experts found that a significant part of the market of so-called resident proxies is directly related to malware and botnets.
Resident proxies allow you to direct traffic through conventional home computers, smartphones, televisions and routers. For sites and security systems, such traffic looks like the actions of real users from different countries. Thanks to such services, attackers bypassing restrictions on geography, hiding real addresses and avoiding locks.
The authors of the study observed the infrastructure of proxy services for 55 days, from January to March 2026. During this time, it was possible to find more than 53 million unique nodes through which traffic passed. On some days, the largest sites provided more than two million active addresses at the same time.
The test showed a disturbing picture. About 15% of all detected addresses were used simultaneously by infected devices that malware worked on. Nearly 13% of the systems contained potentially dangerous software. Among the discovered malware families were Vo1d, Badbox, RootSTV/Pandoraspear, Gamarue and others.
Experts believe that the real scale of infection can be much higher. Surveillance was conducted only for devices that at the time of the study contacted controlled servers. Sleeping infected systems and devices with blocked traffic did not get into the statistics. For individual networks, the share of infected nodes, according to the authors, can reach 50%.
Special attention was paid to the IPIDEA ecosystem. The network has been pooled by several well-known brands of proxy services, including 922Proxy, LunaProxy and IP2World. The infrastructure actively used devices infected with malware Vo1d, Badbox and RootSTV/Pandorasear. At the end of January 2026, Google, together with its partners, conducted a large-scale operation against IPIDEA, but the market quickly recovered. After a few weeks, the activity of the network returned to almost the same indicators.
The authors of the study note that traditional methods of protection are gradually losing effectiveness. Previously, companies could block suspicious addresses by reputation, but with a constant change in millions of home IP addresses, this approach ceases to work. Attackers use one address for only a few minutes or even for one entry attempt, after which they switch to another node.
The problem affects not only the victims of the attacks. If an employee’s infected computer starts working as a proxy node, the company actually turns into a source of malicious traffic. Enterprise networks, remote connections and reputation of the organization are at risk.
The authors advise companies to pay more attention to analyzing traffic behavior, not just checking IP addresses. In their opinion, protective systems should monitor the nature of suspicious actions, rapid address switching and atypical activity associated with entry attempts, spamming and automated attacks.

Millions of home devices around the world imperceptibly for owners help cybercriminals hide attacks, circumvent company protection and hack other people’s accounts. BitSight experts found that a significant part of the market of so-called resident proxies is directly related to malware and botnets.
Resident proxies allow you to direct traffic through conventional home computers, smartphones, televisions and routers. For sites and security systems, such traffic looks like the actions of real users from different countries. Thanks to such services, attackers bypassing restrictions on geography, hiding real addresses and avoiding locks.
The authors of the study observed the infrastructure of proxy services for 55 days, from January to March 2026. During this time, it was possible to find more than 53 million unique nodes through which traffic passed. On some days, the largest sites provided more than two million active addresses at the same time.
The test showed a disturbing picture. About 15% of all detected addresses were used simultaneously by infected devices that malware worked on. Nearly 13% of the systems contained potentially dangerous software. Among the discovered malware families were Vo1d, Badbox, RootSTV/Pandoraspear, Gamarue and others.
Experts believe that the real scale of infection can be much higher. Surveillance was conducted only for devices that at the time of the study contacted controlled servers. Sleeping infected systems and devices with blocked traffic did not get into the statistics. For individual networks, the share of infected nodes, according to the authors, can reach 50%.
Special attention was paid to the IPIDEA ecosystem. The network has been pooled by several well-known brands of proxy services, including 922Proxy, LunaProxy and IP2World. The infrastructure actively used devices infected with malware Vo1d, Badbox and RootSTV/Pandorasear. At the end of January 2026, Google, together with its partners, conducted a large-scale operation against IPIDEA, but the market quickly recovered. After a few weeks, the activity of the network returned to almost the same indicators.
The authors of the study note that traditional methods of protection are gradually losing effectiveness. Previously, companies could block suspicious addresses by reputation, but with a constant change in millions of home IP addresses, this approach ceases to work. Attackers use one address for only a few minutes or even for one entry attempt, after which they switch to another node.
The problem affects not only the victims of the attacks. If an employee’s infected computer starts working as a proxy node, the company actually turns into a source of malicious traffic. Enterprise networks, remote connections and reputation of the organization are at risk.
The authors advise companies to pay more attention to analyzing traffic behavior, not just checking IP addresses. In their opinion, protective systems should monitor the nature of suspicious actions, rapid address switching and atypical activity associated with entry attempts, spamming and automated attacks.