Ransomware , Security Operations Botnets powered by residential proxy networks are growing July 27, 2026 Share By SC Staff Botnets powered by residential proxy networks are proliferating, enabling cybercriminals to evade detection by blending in with legitimate traffic, Lumen Technology’s Black Lotus Labs said in a report. The global scale of botnets observed by Lumen is currently approaching 60 million victim IP addresses, with roughly 1 in 4 of those compromised IPs based in the United States, based on information published by cyberscoop. These botnets are growing in size, with an average of 10 distinct botnets controlling about 1 million active victims daily. The demand for access to these IP addresses fuels opportunities for growth, reselling, and quick rebounds following disruptions. For example, the IPIDEA residential proxy network, disrupted in January, recovered to nearly half its strength within hours and has since surpassed its pre-disruption botnet size. Cybercriminals are exploiting a growing pool of vulnerable devices, with over 1 billion devices currently available to be unknowingly incorporated into botnets. Defenders face a challenge as botnet operators have formed a global supply chain that is difficult to break. Multiple residential proxy services are collaborating, creating the largest cooperative network ever seen on the internet. Black Lotus Labs tracks more than 30 distinct malicious proxy botnet clusters, most boasting over 100,000 daily victims. Taking down individual botnets is likely a short-lived solution, as the malicious proxy environment has created a collective botnet capable of moving millions of IPs quickly. This issue is expected to grow without proper industry and law enforcement regulation. Source: cyberscoop An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Ransomware Steam forums used for ClickFix cryptominer attacks SC Staff July 27, 2026 In a report by Bleeping Computer, threat actors are exploiting Steam discussion forums to distribute cryptominers through a social engineering tactic known as ClickFix. Phishing Phishing attacks on insurance companies evolve to real-time account hijacking SC Staff July 27, 2026 Phishing campaigns targeting financial institutions are evolving from credential harvesting for later use to real-time account hijacking, based on information published by The Hacker News. Malware Golden Chickens malware-as-a-service resurfaces with four new families SC Staff July 24, 2026 The Hacker News disclosed that the threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Blue Team Cold Warm Hot Disaster Recovery Site Countermeasure Cron Daemon Disaster Recovery Plan (DRP) You can skip this ad in 5 seconds