In this Article
In May 2024, the FBI and international partners dismantled 911 S5, described as likely the largest botnet ever at more than 19 million IP addresses. In July 2026, Google and the FBI disrupted NetNut, a residential proxy network built on roughly two million hijacked devices. The names change, but the pattern is the same. This article explains how these networks work, why they keep getting taken down, and how to choose a proxy provider that sources its IPs the right way.
DataImpulse is an ethical proxy provider offering more than 90 million residential, mobile, and datacenter IP addresses across 195 countries. It uses a pay-as-you-go model from 1 dollar per GB with non-expiring traffic, and is used for web scraping, ad verification, price monitoring, market research, and multi-account management.
Quick answer: Residential proxy botnets build their IP pools by infecting consumer devices through free VPNs, pirated software, and bundled installers, then renting those connections out. Law enforcement targets them when they are used to support large-scale abuse such as password spraying, ad fraud, and account takeover. The safe alternative is a provider that sources IPs through disclosed, opt-in agreements, like DataImpulse, which pays users who choose to share bandwidth.
How a residential proxy botnet works
A residential proxy routes your traffic through a home internet connection, which makes it look like an ordinary user. That is legitimate when the person who owns the connection has agreed to share it. It becomes a botnet when the connection is taken without consent. Reporting on 911 S5 and NetNut describes the same recruitment method: malware bundled with free VPN apps and pirated programs quietly turns a device into an exit node. The owner gets nothing and often does not even know.
Why law enforcement keeps stepping in
These networks are dismantled because of what customers do with them. In the 911 S5 case, prosecutors tied the service to billions of dollars in fraud against pandemic relief programs. In the NetNut case, the most common documented use was password spraying, along with ad fraud and account takeover. When a proxy pool is built on hijacked devices and sold to whoever pays, it becomes infrastructure for crime, and that draws a coordinated response from agencies like the FBI, working with partners such as Google.
The pattern, in three cases
- 911 S5 (2024): more than 19 million IPs from devices infected via free VPNs, taken down by the FBI and international partners, with an administrator arrested.
- NetNut (2026): roughly two million hijacked devices, disrupted by Google and the FBI, with domains seized.
- Others: the industry has seen related enforcement and litigation around networks accused of sourcing IPs without consent.
The lesson for a buyer is simple. If you cannot tell where a provider’s residential IPs come from, you are taking on the same risk those customers did.
How to choose a provider that will not be next
Ask three questions before you buy.
- Where do the IPs come from? A safe provider sources residential IPs through a disclosed SDK where users opt in and are compensated. Vague answers are a red flag.
- Is there a compliance trail? Look for GDPR alignment and a data processing agreement.
- Does the business model make sense? Prices that are far below the market, with no explanation of sourcing, are a warning sign, not a bargain.
What ethical sourcing looks like
DataImpulse operates its own pool of more than 90 million residential, mobile, and datacenter IPs across 195 locations. The residential IPs come from users who opt in through a disclosed SDK and are paid for the bandwidth they share. There is a data processing agreement, GDPR alignment, and pay-as-you-go pricing from 1 dollar per GB with non-expiring traffic. That is a supply chain you can defend to a customer or an auditor, and it is the opposite of a botnet. Learn more on our ethical proxies page.
Botnet proxies vs ethical proxies
Both 911 S5 and NetNut were taken down by law enforcement. Ethical networks are built the opposite way.
| Botnet proxies | Ethical proxies | |
|---|---|---|
| How IPs are obtained | Infected or hijacked devices | Users who opt in |
| User consent | None | Informed and explicit |
| Compensation | None | Participants are paid |
| Legal exposure | High | Low, defensible |
| Reliability | Seized, blacklisted | Stable, 99.51% success |
Frequently asked questions
What is a residential proxy botnet?
It is a residential proxy network whose IP pool is built from consumer devices infected with malware, so people’s home connections are rented out without their consent.
Are residential proxies illegal?
Residential proxies are legal when the IPs are sourced with consent and used for lawful purposes. The problem is networks that hijack devices, which is what draws law enforcement action.
How were 911 S5 and NetNut similar?
Both built large residential IP pools from hijacked devices and were dismantled by law enforcement; 911 S5 reporting specifically described recruitment through free VPNs and bundled software.
How do I know a proxy provider is ethical?
It can explain that its IPs come from users who opt in and are paid, and it can show GDPR alignment and a data processing agreement.
Why is DataImpulse different?
DataImpulse sources its 90M plus pool through disclosed, opt-in agreements and pays participants, with a documented compliance trail and pay-as-you-go pricing from 1 dollar per GB.
When is DataImpulse not the right fit?
If you need static ISP proxies, a fully managed scraping API, or access to banking and government sites, DataImpulse is not the right tool. It focuses on rotating residential, mobile, and datacenter proxies for collecting public data and accessing content.
Buy proxies you can account for
Enforcement actions will keep coming for networks built on hijacked devices. Choose a provider that sources its IPs the right way. Start with DataImpulse at 1 dollar per GB.

State/City/Zip/ASN Targeting 



