A headline pool size tells you scale, not provenance. For procurement, security and compliance teams, the source of residential IP capacity can determine whether a proxy service is a defensible supplier or an unmanaged cyber risk.
Two providers can both sell access to millions of residential IPs. One may recruit participants through clear, revocable consent and controlled partnerships. Another may acquire capacity through opaque software development kits, misleading disclosures, or malware. To the buyer, the products can look similar until a security review, law-enforcement action or poor IP reputation exposes the difference.
This briefing focuses on malware-sourced residential proxies and the evidence enterprise teams should request before procurement.
Key takeaways
- Residential proxy inventory can be recruited through transparent opt-in programmes, ambiguously disclosed proxyware, or outright malware and botnets.
- Academic research and the 911 S5 prosecution show that compromised-device networks have operated at very large scale.
- Meaningful consent is necessary, but it is not sufficient: providers also need strong abuse controls, monitoring and partner governance.
- An unusually low price is not proof of misconduct, but opaque economics and evasive sourcing answers should trigger deeper due diligence.
- Enterprise buyers should assess residential proxy sourcing as a cyber supply-chain dependency, not merely a connectivity purchase.
Pool size is not provenance
A residential proxy routes traffic through an IP address assigned by an internet service provider to a residential network or device. That network position can support legitimate use cases such as localised public-web research, price monitoring, ad verification and search-data collection. But the label “residential” says nothing about how the endpoint joined the network, what the participant was told or what controls govern the traffic.
That distinction matters because the endpoint is not an abstract cloud resource. It is a real connection belonging to a person, household, or organisation. Procurement teams, therefore, need to understand both the sourcing chain and the operating controls around it. The right question is not only “how many IPs are in the pool?” It is “how did those IPs get there, and what evidence makes that answer defensible?”
Three sourcing models sit behind the same product label
| Sourcing model | How capacity is recruited | What buyers should verify |
|---|---|---|
| Transparent opt-in | Participants receive clear notice, affirmatively join, understand the value exchange and can withdraw without unnecessary friction. | Consent records, withdrawal process, partner governance, participant communications and abuse controls. |
| Proxyware or SDK monetisation | A relay SDK is embedded in an application or service. The user may receive payment, free features or another benefit, but the quality of disclosure and consent can vary significantly. | Exact consent wording, separate opt-in, app or SDK partner contracts, notification behaviour, audit rights and revocation controls. |
| Malware or botnet recruitment | Devices are enrolled through malicious software, pirated applications or covert backdoors without meaningful permission. | No legitimate evidence should exist. Treat any indication of covert recruitment as a critical supplier-risk finding. |
The middle category is where simplistic “ethical versus unethical” labels often break down. A user may technically click “agree” while still receiving confusing, bundled, or incomplete information. A robust review should test whether consent is specific, informed, visible and genuinely revocable rather than treating any consent screen as sufficient.
What the research shows about compromised and ambiguously recruited networks
The 2019 IEEE study Resident Evil: Understanding Residential IP Proxy as a Dark Service identified roughly six million residential proxy IPs across more than 230 countries and 52,000 internet service providers. The researchers reported that many observed proxies appeared to run on likely compromised hosts, including IoT devices, and linked some hosts to phishing, malware hosting, and other illicit activity.
A 2021 NDSS study of mobile proxy networks found 1,701 Android packages across 963 applications containing proxy SDKs, with at least 300 million installations in total. The researchers found consent notices could be confusing and documented one SDK that relayed traffic without showing a notification. They also reported that 48.43% of the packages were flagged by at least five antivirus engines and that 86.60% of the applications had been removed from Google Play by October 2019.
More recent research adds an important qualification: even a voluntarily installed network can carry material downstream risk if customer activity is not governed. A 2024 study operated eight user-installed residential proxy applications for 7.5 months and analysed 368 GB of proxied traffic. Its case studies indicated likely use in dating-platform fraud, phishing-related activity and web scraping, underscoring the need for abuse detection and provider-side controls as well as participant consent.
Consent is a threshold control, not the entire control environment. A defensible residential network also needs partner oversight, acceptable-use enforcement, traffic monitoring, incident response and a process for removing abused or compromised endpoints.
Case study: what the 911 S5 botnet revealed
The 911 S5 case is the clearest public example of a malware-fed residential proxy service operating at global scale. In May 2024, the US Department of Justice announced the disruption of the service and the arrest of its alleged administrator. According to the indictment and official announcements, malware was distributed through free VPN applications, pirated software, and pay-per-install bundles, creating access to more than 19 million unique IP addresses across more than 190 countries.
The FBI described 911 S5 as one of the largest residential proxy services and botnets, and said it was built from compromised devices whose owners did not know their connections were being used as relays. Authorities linked the service to confirmed victim losses in the billions of dollars, while the indictment alleges that the operator received approximately US$99 million from selling access to the hijacked IP addresses.
The case also shows why procurement risk does not stop at technical performance. The US Treasury sanctioned individuals and entities associated with the network. Once a provider or connected entity becomes the subject of criminal proceedings or sanctions, customers may need to explain what due diligence they performed, whether they continued transacting after public action, and how quickly they can replace a critical supplier.
Four risks that can transfer to the buyer
1. Privacy and legal risk
The legal analysis depends on the data, roles, jurisdictions, and contractual arrangement. IP addresses can constitute personal data in some circumstances, and organisations using suppliers to process personal data may need to assess lawful basis, transparency, security, contracts, and ongoing supplier assurance. The UK Information Commissioner’s Office says controllers must assess whether processors provide sufficient guarantees and should monitor compliance on an ongoing basis.
That does not mean every proxy transaction creates the same legal exposure. It does mean that a buyer should not accept vague sourcing claims where the service may involve personal devices, network identifiers or cross-border data flows. Where participants have not given meaningful permission, the sourcing model may create serious privacy, contractual and audit concerns. Organisations should obtain advice based on their own use case. Our own treatment of this is in residential proxies and GDPR compliance.
2. Cyber and supply-chain risk
A proxy provider becomes part of the customer’s digital supply chain: it handles network traffic, credentials and routing metadata, and may depend on SDK partners or other upstream suppliers. The UK National Cyber Security Centre recommends that organisations understand who their suppliers are, assess the risks they create and gain confidence that appropriate controls are in place.
For a residential proxy purchase, that means asking how far the provider can trace its own supply chain, how partners are assessed, what technical access third parties retain and how incidents are investigated. A provider that cannot map its endpoint sources is asking the customer to accept an unmeasured dependency.
3. Operational and IP-reputation risk
A compromised endpoint may already carry abuse history, blocklist exposure, or a reputation for suspicious activity. In practice, that can mean more CAPTCHAs, more retries, lower completion rates and higher bandwidth cost per usable result. This is why sourcing is also a quality question. Our guide to IP reputation explains how abuse history and poor pool management can affect whether an otherwise residential IP is trusted by target sites.
4. Investigative, sanctions and reputational risk
A law-enforcement takedown may expose infrastructure, accounts and transaction records to investigation. This does not make every customer culpable, but it can create significant audit, legal and reputational work. Sanctions create an additional concern: organisations need screening and escalation processes so they can identify and respond when a supplier, owner or related entity is designated.
Price is a due-diligence signal, not proof
An unusually low price does not prove that a network is malware-sourced. Scale, automation, commercial strategy and long-term contracts can all reduce cost. But legitimate residential capacity still has economics: participants or distribution partners need a clear value exchange, endpoints need monitoring, and the provider must fund abuse prevention, support and network maintenance.
The useful procurement question is therefore not “is this price too cheap to be true?” It is “can the provider explain the economics and controls behind this price?” A defensible supplier should be able to describe how participants are recruited, what they receive, how consent is recorded, how partners are governed and how abusive traffic is detected. If the answer is simply “proprietary”, the risk remains with the buyer.
A due-diligence checklist for residential proxy procurement
The following questions turn a broad ethical claim into evidence that procurement, security and compliance teams can assess. The depth of review should be proportionate to the use case and the sensitivity of the data or systems involved.
| Question | Evidence to request | Potential red flags |
|---|---|---|
| How are endpoints recruited? | A written sourcing model, partner categories, participant journey and geographic restrictions. | The provider cannot explain its supply chain beyond “global partners”. |
| What does consent look like? | The actual notice, separate opt-in, version history, withdrawal process and participant support route. | Consent is bundled into long terms, preselected, difficult to withdraw or not shown consistently. |
| What value does the participant receive? | A clear description of payment, service benefit or other exchange, including who funds it. | No coherent explanation of why device owners would participate. |
| How are SDK and distribution partners governed? | Contracts, audit rights, technical restrictions, approval criteria and a current sub-supplier inventory. | Unrestricted sub-distribution or inability to identify where the SDK is embedded. |
| How is customer abuse controlled? | Acceptable-use rules, customer risk assessment, traffic monitoring, rate controls, investigation and termination procedures. | A “no questions asked” sales model or no evidence of enforcement. |
| How is endpoint quality managed? | IP reputation monitoring, blocklist checks, endpoint retirement, incident metrics and remediation processes. | Burned or suspicious endpoints remain active because pool size is prioritised over quality. |
| What independent assurance exists? | Relevant audit reports, certifications, penetration-test summaries, policies and security contacts. | Logos without scope, dates or supporting documentation. |
| What happens during an incident? | Incident-response plan, notification commitments, evidence preservation, sanctions screening and exit or continuity arrangements. | No named owner, no notification timeline and no process for isolating affected endpoints. |
What defensible sourcing looks like
A defensible residential proxy network should be able to demonstrate five things:
- Traceable provenance. The provider can explain where endpoints come from and how far it can see into its partner chain.
- Meaningful participation. People receive clear information, make an affirmative choice, and can withdraw.
- Active abuse governance. Sourcing controls are matched by customer controls, monitoring and enforcement.
- Independent assurance. Security and compliance claims are supported by current, scoped evidence.
- Operational transparency. The provider can explain incidents, endpoint quality, service continuity, and corrective action.
At Shifter, we believe buyers should expect documented answers to these questions from any provider they evaluate, including us. “Ethically sourced” should not be a marketing label that ends the conversation. It should be the start of an evidence-based review. For the wider governance context, see our guide to ethical residential proxies for AI data collection.
The bottom line
Pool size answers how much capacity a provider claims to offer. Provenance answers whether an enterprise can defend the purchase. Research into compromised and ambiguously recruited networks, together with the 911 S5 case, shows that residential proxy sourcing belongs in the same conversation as cyber supply-chain assurance, processor due diligence and operational resilience.
The market does not need another unverified “ethical” badge. It needs a procurement standard: clear recruitment, meaningful consent, partner accountability, abuse controls and evidence that can survive follow-up questions. An unexplained price gap should prompt those questions, not replace them.
If your procurement, security or compliance team is assessing residential proxy infrastructure, talk to the Shifter team about network controls, deployment requirements and the assurance documentation available for your review.
This briefing is provided for general information only and does not constitute legal advice.
Frequently asked questions
What are malware-sourced residential proxies?
They are residential proxy endpoints created from devices enrolled without meaningful permission, typically through malware, covert backdoors or deceptive software distribution. The buyer receives access to a residential IP, but the device owner did not knowingly agree to provide the connection.
Are cheap residential proxies always malware-sourced?
No. A low price can result from scale, efficiency or commercial strategy. It should become a due-diligence signal when the provider cannot explain how participants are recruited, compensated, informed and protected.
What was the 911 S5 botnet?
911 S5 was a residential proxy service built from malware-compromised devices. US authorities said it involved more than 19 million IP addresses across nearly 200 countries and enabled large-scale cybercrime. The DOJ announced its disruption and the arrest of its alleged administrator in May 2024.
Does user opt-in make a residential proxy network safe?
Not by itself. Meaningful consent is an essential sourcing control, but a provider must also govern SDK partners, monitor customer activity, enforce acceptable-use rules, investigate abuse and remove compromised or burned endpoints.
What evidence should an enterprise buyer request?
Ask for the sourcing model, participant consent and withdrawal process, partner-governance controls, abuse-monitoring process, endpoint-quality controls, independent assurance evidence, sub-supplier information and incident-response commitments.
Can residential proxy use be compliant?
It can support legitimate business uses, but compliance depends on the sourcing model, intended activity, data involved, jurisdictions, contracts and technical controls. Organisations should assess their own role and obtain legal advice where appropriate.