Residential Proxies Hide Abuse Behind Trusted IPs

The hard part is not taking a botnet offline. It is that residential proxy layers let abuse blend into normal consumer traffic, so IP reputation and geo-blocking miss the real source of the attack. When the source looks like a home or mobile user, standard filtering loses its edge. Dutch police and the NCSC seized more than 200 servers in the Netherlands and took down a botnet tied to at least 17 million infected devices. Reporting linked the infrastructure to ASOCKS, a commercial residential and mobile proxy service used for DDoS, fraud, scraping, and other abuse. The devices behind that traffic still exist, and the same model can be rebuilt elsewhere. For defenders who trust source IPs too much, the bigger problem is the proxy market itself, which can turn ordinary-looking addresses into cover for large-scale malicious traffic.

Part of the PlainSec briefing for 2026-06-01

Sources