"The only reason these botnets keep getting more and more victims is because there is clearly a market. Aside from criminal activity, who wants access to millions of IPs regularly?" Chris Formosa, senior lead information security engineer at Black Lotus Labs, said in describing why residential proxy-powered botnets keep expanding.
Lumen Technology’s Black Lotus Labs: the headline numbers
Researchers at Lumen Technology’s Black Lotus Labs report that the global scale of botnets they observe is approaching 60 million victim IP addresses. Chris Formosa told CyberScoop that roughly one in four of those compromised IPs are based in the United States, and that the true number of infected devices is higher because multiple devices can share a single IP and many networks lie outside Lumen’s visibility.
Super-sized botnets and a cooperative proxy ecosystem
Black Lotus Labs describes an environment of “super-sized” botnets. The firm reports an average of 10 distinct botnets each controlling a population of roughly 1 million active victims on a daily basis. The team currently tracks more than 30 distinct malicious proxy botnet clusters, and says most of those regularly boast more than 100,000 daily victims.
Researchers warned that operators are not acting alone. The report states that “we have observed multiple residential proxy services collaborating to form what amounts to the largest cooperative network ever seen on the internet,” and concludes that “the malicious proxy environment has essentially created the largest collective botnet currently active on the internet, capable of moving millions of IPs within hours to wherever they are needed.”
IPIDEA’s rebound after coordinated disruption in January
One concrete example Black Lotus Labs highlights is IPIDEA, described as “one of the largest residential proxy networks in operation” at the time it was disrupted by coordinated strikes in January. The company’s infrastructure, the report says, recovered at nearly half-strength within hours and subsequently surpassed its pre-disruption botnet size. Black Lotus Labs reported a current botnet population for IPIDEA of about 10 million IPs.
“Their rebuild was eye-opening as they began to rebound from that interdiction,” Ryan English, information security engineer at Black Lotus Labs, told CyberScoop. “Even for how quickly some botnets can rebound, theirs was surprising. We’ve seen them all rebuild, but we haven’t seen anybody do it that fast.”
Drivers: persistent demand and an expanding pool of vulnerable devices
Black Lotus Labs attributes continued growth to market demand and to the ongoing availability of exploitable devices. “The only reason these botnets keep getting more and more victims is because there is clearly a market,” Formosa said, and the report adds that this demand fuels “growth, reselling, collaboration, and quick rebounds following massive disruptions.”
Ryan English told CyberScoop that “Your available pool for those proxy hunters grows every year, and it will continue to grow every year,” noting that more cheap and poorly defended devices are entering the market and that vendors stop providing security updates for older but still usable products. English said that “more than 1 billion devices are currently vulnerable and available to be unknowingly sucked up into botnets.”
Black Lotus Labs also observed that, despite frequent disruptions and seizures, operators have formed a “global supply chain with pathways that are difficult to break,” leaving the environment resilient to isolated takedowns.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Black Lotus Labs warns that “taking down a single malicious proxy provider or their botnet in isolation is likely to result in a short-lived solution,” suggesting defenders will face recurring rebounds unless action is coordinated across multiple providers and jurisdictions.
- Policymakers and regulators: The report directly links future risk to regulatory and law enforcement coordination, concluding, “Until the malicious proxy landscape is properly addressed and regulated on both the private industry and law enforcement sides, this issue will grow.”
- Affected enterprises and procurement leaders: The blending of malicious proxy traffic with legitimate residential traffic, combined with the scale of these networks, increases the chance that enterprise-facing systems will see noteable volumes of traffic originating from compromised consumer devices—traffic that can be moved quickly to meet criminal demand.
Black Lotus Labs’ findings frame a specific, measurable problem: tens of millions of compromised IPs, clustered botnets able to mobilize millions of addresses in hours, and a marketplace that rewards rapid rebuilds. The report’s closing assessment leaves a narrow path forward explicit — coordinated private-sector and law enforcement measures and regulation — and a stark question implicit: will those actors act together before the collective botnet grows further and the DDoS and proxy-enabled threats become still harder to disrupt?




