62M+ IPs online · 195+ countriesKYC-verified · Ethical peer network
★ Engaging 5M+ customers As featured in PTI · The Wire · Business Standard

The Botnet Hiding Inside “Residential” Proxy Networks

Fact Checked
Disclosure: Some of the links on this site are affiliate links, meaning that if you click on one of the links and purchase an item, I may receive a commission. All opinions however are my own.

A 2 million device Android botnet called Kimwolf has been spreading by hijacking the very residential proxy networks that scraping and SEO teams rely on, and security researchers say the underlying flaw is still not fully fixed.

  • Kimwolf infects cheap, unofficial Android TV boxes, then resells their bandwidth as “residential” proxy IPs without the device owner’s knowledge

  • The botnet has produced roughly 12 million unique IP addresses a week, most concentrated in Vietnam, Brazil, India, and Saudi Arabia

  • Compromised devices get used for DDoS attacks, ad fraud, account takeovers, and mass scraping, not just proxy resale

How it spreads

The Botnet Hiding Inside "Residential" Proxy Networks

Security firm Synthient traced Kimwolf’s growth to a specific weakness: many proxy providers were not blocking their own customers from reaching into the local network of the device running the proxy.

That let attackers tunnel through legitimate-looking residential proxy traffic straight into unsecured Android TV boxes running an exposed Android Debug Bridge service. Two out of three infected devices had no authentication at all.

Why it matters for proxy buyers

This is the exact risk that separates ethical, verified residential proxy networks from botnet-fed ones. A meaningful share of cheap “residential” IP pools on the market are sourced from devices that never consented to being proxy nodes, sold pre-infected by the hardware vendor itself. Synthient found some devices shipped with modified provider SDKs baked in before they ever reached a customer.

What’s being done

One major provider, IPIDEA, patched the exposed ports in December after Synthient’s disclosure. Synthient recommends proxy providers block access to local network addresses by default, and it offers a free check at synthient.com to see if a device is part of the botnet, with destruction recommended for anything flagged.

Quick Links:

Scroll to Top