Home › Guides › Residential Proxy Botnet & Takedown Timeline
✓ 27 dated events, 16 Jun 2022 to 24 Jul 2026 · 97 quotes checked word for word against saved copies of 36 primary sources on 2 October 2026 · the timeline · method · download the data
Residential proxies route traffic through home internet connections, so it looks like it comes from an ordinary household. Some networks get those connections with consent, for example through bandwidth-sharing apps. Others have been accused of using malware, backdoored devices and hidden app code to do it. Since 2022, U.S. prosecutors, the FBI, the U.S. Treasury, Europol, Germany’s BSI, the courts and private security teams have been acting against that second group more and more often.
This page is a dated reference of those actions: takedowns, indictments, guilty pleas, sentences, sanctions, civil lawsuits, government advisories and the main security research reports. Each entry links to the primary source, meaning the press release, court filing, advisory or research post itself rather than news coverage. Every figure is quoted exactly as published.
Read this first. An indictment or charge is an allegation; a person charged is presumed innocent unless and until proven guilty. Sanctions designations, domain seizures and civil default judgments are not criminal convictions. Researchers’ device and IP counts are estimates, and the methods behind them differ. Where a company has responded publicly, we quote its response. We name companies only as the cited sources do.
911 S5 RSOCKS IPStorm Socks5Systemz / PROXY.AM TheMoon / Faceless PROXYLIB BadBox & BADBOX 2.0 Anyproxy / 5socks Lumma / GhostSocks Kimwolf IPIDEA SocksEscort NetNut / Popa
Headline numbers
- 911 S5 is the largest case by the figures authorities cite. The U.S. Justice Department says the botnet behind it compromised “more than 19 million unique IP addresses, including 613,841 IP addresses located in the United States”. It says 911 S5 customers allegedly targeted pandemic relief programs, and that “the United States estimates that 560,000 fraudulent unemployment insurance claims originated from compromised IP addresses”, resulting in a “confirmed fraudulent loss exceeding $5.9 billion”. It also says the indictment alleges the administrator “received approximately $99 million”. YunHe Wang was arrested in Singapore in May 2024 and is charged, not convicted. A Singapore High Court decision of 15 January 2026 ([2026] SGHC 11) shows the U.S. extradition proceedings still under way. Wang had applied to the court “(before his committal hearing)”, the application was dismissed, and he appealed.
- The largest device count comes from a lawsuit, not a prosecution. Google said BADBOX 2.0 “compromised over 10 million uncertified devices” when it sued the operators, who were not named, in New York in July 2025. The court entered a default judgment and permanent injunction on 18 September 2025, noting that “Defendants have failed to appear”. The FBI separately warned that “The BADBOX 2.0 botnet consists of millions of infected devices and maintains numerous backdoors to proxy services”.
- Most of the networks in this timeline relied on hacked devices. The networks include RSOCKS (the plea agreement says the defendant and his conspirators “gained unauthorized access to over 900,000 computers” “From June 27, 2015, through November 20, 2019”), 911 S5, IPStorm, Anyproxy/5socks and SocksEscort. Researchers have also documented two other ways of recruiting devices: code hidden in apps (PROXYLIB, IPIDEA, Popa) and TV boxes that ship with a backdoor already installed (BadBox).
- Takedowns hurt these networks, but they do not finish them. In one seven-day period in January 2026, Google’s threat intelligence team (GTIG) saw “over 550 individual threat groups” using IPIDEA exit nodes. After Google’s January 2026 action, Lumen measured “an approximate 33% decrease in overall traffic volumes and a 25% reduction in victim population”. Lumen also found that “IPIDEA surpassed its pre-January 2026 disruption botnet size in early July 2026”.
- SocksEscort, March 2026: the Justice Department says the service “has offered to sell access to about 369,000 different IP addresses” since the summer of 2020. Europol says it “allegedly compromised over 369 000 routers and Internet of Things devices in 163 countries”. On the action day, it says, police took down and seized “34 domains as well as 23 servers located in seven countries”, and “the United States froze a total of USD 3.5 million in cryptocurrency”.
- NetNut, July 2026: GTIG estimated the network at “at least 2 million devices”. In one week it saw “316 distinct threat clusters” using suspected NetNut exit nodes. NetNut’s parent company, Alarum, said it learned of the FBI’s seizure of NetNut domains on 2 July 2026. The next day it said that “neither the Company nor NetNut has been formally contacted by the FBI or any other governmental or regulatory authority”. We found no announced charges against NetNut or Alarum.
- The ecosystem is far bigger than any one case. Lumen’s Black Lotus Labs said in July 2026 that it tracks “nearly 20 million distinct IPs per day across more than 30 malicious proxy botnet clusters”.
- The pace is increasing. This timeline records 7 events in 2024, 7 in 2025 and 9 in 2026 up to July. In March 2026 the FBI published a general warning about residential proxies. It named the sourcing methods researchers had documented, among them paying app developers to bundle proxy SDKs (“Proxy services convince mobile application developers to include their SDK in applications in exchange for payment”) and free VPN apps (“Exercise caution before downloading free VPN applications”).
Timeline at a glance

How big, as claimed
The largest scale figure published for each network, quoted as published. The units are not the same: some count IP addresses per day or per week, some count IP addresses over several years, and some count devices. IP counts run higher than device counts because a home connection’s IP address changes over time. Treat the bars as orders of magnitude, not a ranking.

| Network | Figure, exactly as published | Source |
|---|---|---|
| All tracked proxy botnets (Lumen, Jul 2026) | “nearly 20 million distinct IPs per day across more than 30 malicious proxy botnet clusters” | Lumen Black Lotus Labs |
| 911 S5 (DOJ, May 2024) | “more than 19 million unique IP addresses, including 613,841 IP addresses located in the United States” | U.S. Department of Justice (Office of Public Affairs) |
| Kimwolf (Synthient, Jan 2026) | “around 12 million unique IP addresses per week” | Synthient |
| BADBOX 2.0 (Google, Jul 2025) | “compromised over 10 million uncertified devices” | |
| NetNut (GTIG estimate, Jul 2026) | “at least 2 million devices” | Google Threat Intelligence Group |
| Kimwolf (Synthient, Jan 2026) | “has surpassed 2 million” | Synthient |
| BADBOX 2.0 (HUMAN, Mar 2025) | “impacted more than 1 million consumer devices” | HUMAN Satori Threat Intelligence (Wayback copy) |
| RSOCKS (plea agreement, 2023) | “gained unauthorized access to over 900,000 computers” | U.S. District Court, S.D. Cal. (plea agreement, via CourtListener) |
| SocksEscort (DOJ, Mar 2026) | “has offered to sell access to about 369,000 different IP addresses” | U.S. Attorney's Office, E.D. Cal. (DOJ) |
| Socks5Systemz/PROXY.AM (Bitsight, Dec 2024) | “250,000 compromised systems at its peak” | Bitsight TRACE |
| TheMoon/Faceless (Lumen, Mar 2024) | “over 40,000 bots from 88 countries in January and February of 2024” | Lumen Black Lotus Labs |
| BadBox sinkhole (BSI, Dec 2024) | “bei bis zu 30.000 solcher Geräte in Deutschland die Kommunikation zwischen der Schadsoftware BadBox und den Tätern unterbunden” (German: “up to 30,000 such devices in Germany”, communication with BadBox cut off) | BSI (German Federal Office for Information Security) |
| IPStorm (DOJ, Nov 2023) | “over 23,000 “highly anonymous” proxies” | U.S. Attorney's Office, D. Puerto Rico (DOJ) |
| Anyproxy/5socks (DOJ, May 2025) | “more than 7,000 proxies” | U.S. Attorney's Office, N.D. Okla. (DOJ) |
The timeline
The “Status” column reflects only what the cited sources say. Cases may have moved on since; see caveats.
| Date | Network | Event | Type | Status (per sources) | Key figures, quoted | Primary sources |
|---|---|---|---|---|---|---|
| 16 Jun 2022 | RSOCKS | RSOCKS botnet infrastructure disrupted by DOJ/FBI with Germany, Netherlands and UK | Law enforcement / takedown | Operator later pleaded guilty (see E02-E03) | “which hacked millions of computers and other electronic devices around the world” (U.S. Attorney's Office, S.D. Cal.) “ranged from $30 per day for access to 2,000 proxies to $200 per day for access to 90,000 proxies” (U.S. Attorney's Office, S.D. Cal.) | U.S. Attorney's Office, S.D. Cal. (DOJ) |
| 23 Jan 2023 | RSOCKS | RSOCKS operator's plea agreement filed (S.D. Cal. 3:19-cr-04748) | Court & prosecution | Pleaded guilty | “gained unauthorized access to over 900,000 computers” (U.S. District Court, S.D. Cal.) | U.S. District Court, S.D. Cal. (plea agreement, via CourtListener) |
| 2 Nov 2023 | Socks5Systemz | Bitsight exposes the Socks5Systemz proxy botnet (later linked to PROXY.AM) | Security research | Research finding; no charges cited | “ranging from $1 USD to $4000 USD” (Bitsight TRACE) “around 10,000 compromised systems” (Bitsight TRACE) | Bitsight TRACE Bitsight TRACE |
| 14 Nov 2023 | IPStorm (proxx.io / proxx.net) | IPStorm botnet dismantled; operator Sergei Makinin's guilty plea (entered Sept. 18, 2023) announced | Court & prosecution | Pleaded guilty; we found no public sentencing record in our sources | “over 23,000 “highly anonymous” proxies” (U.S. Attorney's Office, D. Puerto Rico) “gained at least $550,000” (U.S. Attorney's Office, D. Puerto Rico) | U.S. Attorney's Office, D. Puerto Rico (DOJ) |
| 12 Feb 2024 | RSOCKS | Amended judgment: Denis Emelyantsev sentenced to 51 months (sentence imposed December 2023) | Court & prosecution | Sentenced | “51 months as to each count” (U.S. District Court, S.D. Cal.) | U.S. District Court, S.D. Cal. (amended judgment, via CourtListener) |
| 26 Mar 2024 | TheMoon / Faceless | Lumen Black Lotus Labs links TheMoon router malware to the Faceless proxy service | Security research | Research finding; no charges cited | “over 40,000 bots from 88 countries in January and February of 2024” (Lumen Black Lotus Labs) “nearly 7,000 new users per week” (Lumen Black Lotus Labs) “targeted over 6,000 ASUS routers in less than 72 hours” (Lumen Black Lotus Labs) | Lumen Black Lotus Labs |
| 26 Mar 2024 | PROXYLIB / LumiApps SDK | HUMAN Satori reports PROXYLIB apps turning phones into proxy nodes; Google Play removes apps | Security research | Research finding; app removals | “28 applications related to PROXYLIB” (HUMAN Satori Threat Intelligence) | HUMAN Satori Threat Intelligence (Wayback copy) |
| 28 May 2024 | 911 S5 | OFAC sanctions three individuals and three entities linked to 911 S5 | Law enforcement / takedown | Designated (sanctions are an administrative action, not a criminal conviction) | “designated three individuals, Yunhe Wang, Jingping Liu, and Yanni Zheng” (U.S. Treasury) “compromised approximately 19 million IP addresses” (U.S. Treasury) | U.S. Treasury (OFAC) |
| 29 May 2024 | 911 S5 | 911 S5 botnet dismantled; alleged administrator YunHe Wang arrested May 24, 2024 | Law enforcement / takedown | Charged (indictment, E.D. Tex.); presumed innocent unless proven guilty | “more than 19 million unique IP addresses, including 613,841 IP addresses located in the United States” (U.S. Department of Justice) “the United States estimates that 560,000 fraudulent unemployment insurance claims originated from compromised IP addresses” (U.S. Department of Justice) “confirmed fraudulent loss exceeding $5.9 billion” (U.S. Department of Justice) “received approximately $99 million” (U.S. Department of Justice) “maximum penalty of 65 years” (U.S. Department of Justice) “MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN, and ShineVPN” (FBI) “over 190 countries” (FBI) | U.S. Department of Justice (Office of Public Affairs) FBI CourtListener docket, E.D. Tex. 4:23-cr-00101 |
| 3 Dec 2024 | Socks5Systemz / PROXY.AM | Bitsight: Socks5Systemz powered PROXY.AM, peaking at 250,000 systems | Security research | Research finding; no charges cited | “250,000 compromised systems at its peak” (Bitsight TRACE) | Bitsight TRACE |
| 12 Dec 2024 | BadBox | Germany's BSI sinkholes BadBox, cutting off up to 30,000 devices in Germany | Law enforcement / takedown | Sinkholing (technical disruption) | “bei bis zu 30.000 solcher Geräte in Deutschland die Kommunikation zwischen der Schadsoftware BadBox und den Tätern unterbunden” (BSI) | BSI (German Federal Office for Information Security) |
| 5 Mar 2025 | BADBOX 2.0 | HUMAN Satori discloses and disrupts BADBOX 2.0 with Google, Trend Micro, Shadowserver and others | Security research | Research + disruption; no charges cited | “impacted more than 1 million consumer devices” (HUMAN Satori Threat Intelligence) “222 countries and territories” (HUMAN Satori Threat Intelligence) | HUMAN Satori Threat Intelligence (Wayback copy) |
| 7 May 2025 | TheMoon (EOL routers) | FBI PSA: proxy services exploiting end-of-life routers via TheMoon variant | Government advisory | Advisory | – | FBI (IC3 PSA I-050725-PSA) |
| 9 May 2025 | Anyproxy / 5socks | Anyproxy/5socks: FBI seizes domains; indictment unsealed charging four Russian and Kazakhstani nationals | Law enforcement / takedown | Charged (indictment, N.D. Okla.); presumed innocent unless proven guilty | “more than 7,000 proxies” (U.S. Attorney's Office, N.D. Okla.) “$9.95 to $110 per month” (U.S. Attorney's Office, N.D. Okla.) “believed to have amassed more than $46 million” (U.S. Attorney's Office, N.D. Okla.) | U.S. Attorney's Office, N.D. Okla. (DOJ) |
| 21 May 2025 | Lumma Stealer (linked GhostSocks proxy) | Microsoft DCU and partners disrupt Lumma Stealer (legal action filed May 13); Lumma had partnered with the GhostSocks proxy malware | Private civil / platform action | Civil/infrastructure action | “approximately 2,300 malicious domains” (Microsoft Digital Crimes Unit) | Microsoft Digital Crimes Unit Synthient |
| 5 Jun 2025 | BADBOX 2.0 | FBI PSA warns BADBOX 2.0 infects home IoT devices and feeds proxy services | Government advisory | Advisory | “The BADBOX 2.0 botnet consists of millions of infected devices and maintains numerous backdoors to proxy services” (FBI) | FBI (IC3 PSA I-060525-PSA) |
| 17 Jul 2025 | BADBOX 2.0 | Google sues unnamed BADBOX 2.0 operators in S.D.N.Y. | Private civil / platform action | Civil suit against unnamed (Doe) defendants | “compromised over 10 million uncertified devices” (Google) | Google U.S. District Court, S.D.N.Y. 1:25-cv-04503 (complaint, via CourtListener) |
| 18 Sep 2025 | BADBOX 2.0 | S.D.N.Y. enters default judgment and permanent injunction for Google against BADBOX 2.0 Does | Court & prosecution | Civil default judgment (defendants did not appear) | – | U.S. District Court, S.D.N.Y. 1:25-cv-04503 (default judgment, via CourtListener) |
| 2 Jan 2026 | Kimwolf | Synthient: Kimwolf Android botnet exceeds 2 million devices, spread via residential proxy access | Security research | Research finding; no charges cited | “has surpassed 2 million” (Synthient) “around 12 million unique IP addresses per week” (Synthient) | Synthient |
| 15 Jan 2026 | 911 S5 | Singapore High Court dismisses YunHe Wang's pre-committal application in U.S. extradition case | Court & prosecution | Extradition proceedings pending as of the decision; appeal filed | – | High Court of Singapore, [2026] SGHC 11 |
| 28 Jan 2026 | IPIDEA | Google GTIG and partners disrupt the IPIDEA residential proxy network | Law enforcement / takedown | Technical/legal disruption by Google; no criminal charges cited | “over 550 individual threat groups” (Google Threat Intelligence Group) “reducing the available pool of devices for the proxy operators by millions” (Google Threat Intelligence Group) “approximately 7,400 Tier Two servers” (Google Threat Intelligence Group) “3,075 unique Windows PE file hashes” (Google Threat Intelligence Group) “over 600 applications” (Google Threat Intelligence Group) | Google Threat Intelligence Group |
| 11 Mar 2026 | SocksEscort (AVrecon) | SocksEscort proxy service dismantled on March 11 (DOJ; Europol 'Operation Lightning'; FBI FLASH on AVrecon), announced March 12 | Law enforcement / takedown | Infrastructure disrupted; no charges announced in the cited DOJ release | “has offered to sell access to about 369,000 different IP addresses” (U.S. Attorney's Office, E.D. Cal.) “allegedly compromised over 369 000 routers and Internet of Things devices in 163 countries” (Europol) “34 domains as well as 23 servers located in seven countries” (Europol) “USD 3.5 million in cryptocurrency” (Europol) | U.S. Attorney's Office, E.D. Cal. (DOJ) Europol FBI (FLASH 20260312-001) |
| 12 Mar 2026 | Residential proxies (general) | FBI PSA 'Evading Residential Proxy Networks' names SDK deals, free VPNs and IoT malware as sourcing routes | Government advisory | Advisory | – | FBI (IC3 PSA I-031226-PSA) |
| 18 Jun 2026 | Popa / Moneytiser SDK | Synthient assesses the Popa SDK shares infrastructure with NetNut (Synthient's assessment) | Security research | Research assessment; no charges cited | “Eighteen distinct Android proxyware samples” (Synthient) | Synthient |
| 2 Jul 2026 | NetNut / Popa | Google acts against the NetNut network with FBI and Lumen; NetNut domains display an FBI seizure notice | Law enforcement / takedown | Domain seizure reported; no charges against NetNut or Alarum found in cited sources; company says it was not formally contacted (E26) | “at least 2 million devices” (Google Threat Intelligence Group) “316 distinct threat clusters” (Google Threat Intelligence Group) | Google Threat Intelligence Group netnut.io (page as captured) Alarum Technologies (SEC Form 6-K exhibit) |
| 3 Jul 2026 | NetNut / Alarum | Alarum update: says neither it nor NetNut was formally contacted by authorities; July 4 'temporary operational pause' | Company statement | Company statement | – | Alarum Technologies (SEC Form 6-K exhibit) Alarum Technologies (SEC Form 6-K) |
| 24 Jul 2026 | Ecosystem (30+ clusters) | Lumen: ~20 million IPs/day across 30+ proxy botnet clusters; IPIDEA rebounds past pre-takedown size | Security research | Research finding | “nearly 20 million distinct IPs per day across more than 30 malicious proxy botnet clusters” (Lumen Black Lotus Labs) “an approximate 33% decrease in overall traffic volumes and a 25% reduction in victim population” (Lumen Black Lotus Labs) | Lumen Black Lotus Labs |
Case notes
911 S5 (2014–2022)
The Justice Department writes: “According to an indictment unsealed on May 24, from 2014 through July 2022, Wang and others are alleged to have created” and distributed malware to build the botnet. On 28 May 2024 the Treasury’s sanctions office (OFAC) “designated three individuals, Yunhe Wang, Jingping Liu, and Yanni Zheng”, and three companies it says Wang owned or controlled. The FBI published a guide to finding and removing the free VPN apps it linked to the botnet: “MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN, and ShineVPN”. The criminal case is United States v. Yunhe Wang, 4:23-cr-00101 (E.D. Tex.), listed as “Date Filed: May 10, 2023” on CourtListener (docket). The Singapore High Court records that Wang “was arrested in Singapore pursuant to a request by the United States of America” and that “I dismissed the applicant’s application, and he has appealed”.
RSOCKS (2015–2022)
The Justice Department describes RSOCKS as a botnet “which hacked millions of computers and other electronic devices around the world”, and that access was priced from $30 a day for 2,000 proxies to $200 a day for 90,000. In the plea agreement signed by Denis Emelyantsev, the factual basis states that “From June 27, 2015, through November 20, 2019”, the defendant and his conspirators “gained unauthorized access to over 900,000 computers”. The amended judgment (“Filed 02/12/24”) gives a sentence of “51 months as to each count”, with the counts to run concurrently.
IPStorm and Anyproxy/5socks
IPStorm: the Justice Department says that, “on September 18, 2023, Sergei Makinin, a Russian and Moldovan national, pled guilty to three counts”. The Justice Department says he sold access to “over 23,000 “highly anonymous” proxies” and “gained at least $550,000”. We did not find a public sentencing record in the sources we saved. Anyproxy/5socks: four men “were charged with Conspiracy and Damage to Protected Computers”. The FBI seized the Anyproxy.net and 5socks.net domains. The Justice Department says the defendants are “believed to have amassed more than $46 million” from selling access to infected routers. The charges are allegations.
IPIDEA (January 2026)
Google’s GTIG took action against IPIDEA’s infrastructure and SDKs with partners. It reported “approximately 7,400 Tier Two servers”, “3,075 unique Windows PE file hashes” and “over 600 applications” with code connecting to IPIDEA’s command domains. Google says its action ended up “reducing the available pool of devices for the proxy operators by millions”. That is a disruption by a private company; no criminal charges are cited.
NetNut (July 2026): what is and isn’t established
On 18 June 2026, Synthient published its assessment. Its research team “is highly confident that the Popa SDK and its associated labels” (Loopop, Neupop and a Moneytiser variant) “share operational infrastructure and telemetry with NetNut”. The evidence it cites includes “Eighteen distinct Android proxyware samples” that communicate directly with NetNut’s SDK endpoints. On 2 July 2026, Google said that “in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network”. When we captured netnut.io, the page title read “Seized by the Federal Bureau of Investigation”. Alarum Technologies, NetNut’s parent company, said it and NetNut “were made aware of the seizure of certain domains associated with NetNut by the FBI”. On 3 July it added that “neither the Company nor NetNut has been formally contacted by the FBI or any other governmental or regulatory authority”, and on 4 July it announced a “Temporary Operational Pause of Certain Network Services”. We found no announced criminal charges, indictment or court finding against NetNut or Alarum in any of the sources cited here. A domain seizure is not a conviction. The descriptions of NetNut’s network on this page are the assessments of Google and Synthient.
Methodology
- What’s included. Public actions and disclosures from June 2022 to July 2026 that involve residential proxy services or the botnets and proxyware that supply them: government takedowns and seizures, charges, pleas, sentences, sanctions, court rulings, civil lawsuits by platforms, government advisories, and the research reports most often cited in those actions. Wider malware takedowns (such as Lumma) are included only where a cited source links them to proxy services.
- Primary sources only. Each entry cites the original document: a DOJ, FBI/IC3, Treasury, Europol or BSI release; a court filing (U.S. filings through CourtListener’s RECAP archive, the Singapore judgment through eLitigation); a company’s SEC filing; or the research post itself (Google GTIG, Lumen Black Lotus Labs, HUMAN Satori, Bitsight, Synthient, Microsoft DCU). We did not use news coverage as a source.
- Snapshots and quote checks. On 2 October 2026 we saved a copy of every source page or PDF, with its HTTP status and fetch time. A script then checks that every quoted string on this page appears word for word in the saved copy, after normalising whitespace and curly quotes. All 97 pass. Where a vendor site blocked automated access (HUMAN), we used the Wayback Machine’s raw capture of the same page. Where fbi.gov blocked access, we used the identical advisory on ic3.gov.
- Dates. Each event is dated by its primary source: the release date for press releases, the “Filed” stamp for court documents, the publication date for research. Where the action happened before the announcement, the table says so (for example, Wang’s arrest on 24 May 2024 was announced on 29 May; SocksEscort was taken down on 11 March 2026 and announced on 12 March).
- Status wording. “Charged” means an indictment or complaint has been announced. “Pleaded guilty” and “sentenced” follow the court documents. For research reports and company actions we say “no charges cited”, which means none appear in the cited sources. It does not mean we have confirmed that no charges exist.
Caveats
- Allegations are not findings. Except for the RSOCKS guilty plea and sentence and the IPStorm guilty plea, the criminal matters here are charges. Sanctions are administrative. The BADBOX 2.0 judgment is a civil default judgment against defendants who were never named and did not appear.
- Counts are not comparable. “IP addresses”, “devices”, “bots” and “proxies” measure different things, over different periods. Vendor counts come from the vendor’s own visibility, such as its network telemetry, sinkholes or sample sets. Authorities’ loss figures cover the activity they charged or confirmed.
- Snapshot in time. The status of each matter is as recorded in sources saved on 2 October 2026. Cases can move on, through extradition, pleas, dismissals or appeals, without a new press release. We found no public sentencing record for IPStorm and no later public update on the Anyproxy/5socks defendants.
- Not comprehensive. This is a curated list of major public actions. Many smaller seizures, regional cases and private disruptions are missing.
- Legitimate proxy use exists. Many residential proxy providers say they source IPs with consent. This page records enforcement and research about specific networks named by the sources. It is not a finding about the residential proxy industry as a whole or about any provider not named here.
Download the data
- Timeline (CSV): one row per event, with date, network, type, status, key figures and source URLs.
- Evidence log (CSV): every quote on this page, with source URL, fetch time (UTC), HTTP status and the result of the quote check.
Free to use with attribution (CC BY 4.0).
Cite or embed
Suggested citation: ProxyPicker (2026). “Residential Proxy Botnet & Takedown Timeline, 2022–2026: takedowns, indictments, sanctions and research on residential proxy networks.” Sources checked 2 October 2026. https://proxypicker.com/residential-proxy-botnet-timeline/
Embed the timeline chart:
<a href="https://proxypicker.com/residential-proxy-botnet-timeline/"><img src="https://proxypicker.com/wp-content/uploads/2026/10/proxypicker-residential-proxy-takedown-timeline-2026-10-timeline.png" alt="Residential proxy botnet and takedown timeline, 2022 to 2026 (ProxyPicker)" width="800" /></a><br />Source: <a href="https://proxypicker.com/residential-proxy-botnet-timeline/">ProxyPicker, Residential Proxy Botnet & Takedown Timeline</a> (2 October 2026)Related: Anti-Bot vs Proxy Patents (proxy-network and anti-bot patents in USPTO data) · What your Wi-Fi is worth (what bandwidth-sharing apps pay, and what they do with your connection) · Scraping Law Hub (court cases and statutes on scraping) · Proxies for web scraping · Anti-Bot Census · AI Crawler Census · Open-Source Scraping Index · What’s my IP? Proxy & VPN checker (why residential proxy IPs are hard to spot) · Residential IP Supply by Country (what providers claim, against internet users) · Where Bot Traffic Comes From (honeypot attacks by source country).
Press & data requests: email [email protected] for interviews, the raw data behind this page, or corrections. See also our contact page.