Jessica Entwistle
July 27 2026
Despite multiple coordinated law enforcement takedowns, residential proxy botnets continue to grow in size and sophistication, according to research from Lumen's Black Lotus Labs. The research shows that roughly one in four compromised IP addresses used in these botnets are based in the United States, with networks like IPIDEA rebounding quickly after disruption and surpassing their pre-takedown footprint. These botnets compromise consumer routers, IoT devices and other internet-connected equipment to create large-scale proxy networks that attackers use to disguise malicious traffic, conduct credential stuffing attacks, scrape data and evade detection. The research highlights that takedowns, while temporarily disruptive, are not preventing botnet operators from rebuilding infrastructure and expanding their reach.
The persistence and growth of residential proxy botnets has direct operational implications for UK organisations. Attackers use these networks to make malicious activity appear to originate from legitimate residential IP addresses, which can bypass geographic restrictions, evade rate limiting and make attribution significantly harder. This affects how organisations detect and respond to credential stuffing, account takeover attempts, web scraping and automated abuse of online services. The fact that botnets are rebuilding faster than they are being dismantled suggests that organisations cannot rely solely on law enforcement action to reduce this threat and must instead focus on defensive measures that assume attackers will continue to have access to large, distributed and constantly refreshed proxy infrastructure. For organisations in sectors such as retail, finance, media and online services, where account security and protection against automated abuse are critical, this represents a persistent and evolving risk that requires ongoing attention and investment in detection and response capabilities.
Organisations should review whether their defences against automated attacks, credential stuffing and account takeover are designed to detect and respond to traffic originating from residential IP addresses, not just known malicious infrastructure. This includes revisiting rate limiting policies to ensure they are tuned for behaviour rather than just IP reputation, and considering whether anomaly detection is capable of identifying malicious activity distributed across thousands of legitimate-looking IP addresses. Authentication controls should be reviewed to ensure they are resilient to attacks that use residential proxies to evade detection, with consideration given to risk-based authentication, device fingerprinting and behavioural analysis. Organisations should also review whether they have visibility into patterns of automated abuse, and whether security operations teams have the tools and processes to respond effectively when attacks are distributed across large numbers of residential IP addresses. Finally, organisations should clarify who is responsible for monitoring and responding to automated attacks, and ensure that defensive measures are regularly tested and updated as botnet infrastructure continues to evolve.
Source: CyberScoop