Massive 20-Year-Old Botnet Busted—Used 1,000 Hacked Devices Weekly

Massive 20-Year-Old Botnet Busted—Used 1,000 Hacked Devices Weekly

A global crackdown led by Lumen Technologies’ Black Lotus Labs, in close collaboration with U.S. and Dutch law enforcement, has brought down a long-running proxy botnet that quietly hijacked digital infrastructure worldwide since 2004.

Hidden in Plain Sight: The Botnet’s Shadow Network

For over a year, researchers at Black Lotus Labs closely monitored a stealthy operation infecting thousands of outdated and unsecured Internet-connected devices—from aging routers to obsolete IoT gadgets. These compromised systems were weaponized to shield threat actors, allowing them to carry out a range of illicit actions, including digital ad manipulation, distributed denial-of-service (DDoS) attacks, credential stuffing, and sensitive data theft—all while masking their true origins behind layers of hijacked residential IPs.

Anatomy of a Covert Operation

At the heart of this infrastructure was a resilient network fueled by malicious code designed to exploit neglected vulnerabilities in home and small office tech. Each week, roughly 1,000 unique compromised systems quietly relayed instructions to and from command-and-control (C2) servers based in Turkey, forming a decentralized web of digital camouflage for cybercriminals operating under the radar.

Inside the Collapse of a Stealth Proxy Empire

Command Layer and Global Footprint

Operating largely under the radar, a sprawling proxy-for-hire network leveraged thousands of hijacked end-of-life (EoL) and IoT devices to shield cybercriminal activity. More than half of the infected systems were traced back to U.S. households and small offices, with additional hotspots in Canada and Ecuador. Although the operators advertised access to 7,000 rotating proxies per day, analysis by Black Lotus Labs revealed a leaner, more surgical operation—smaller in scope but highly persistent and effective.

Five backend command-and-control (C2) nodes powered the infrastructure, with four communicating via standard HTTP (port 80), while a fifth collected data through UDP on port 1443. This decentralized design supported the network’s flexibility and resilience.

Staying Hidden in Plain Sight

What made this botnet particularly durable was its selective targeting. By compromising aging, unsupported hardware—devices that haven’t seen a firmware update in years—the network slipped past most detection systems. Only about 10% of the IPs tied to this operation were flagged by conventional scanning platforms like VirusTotal.

Unlike zero-day exploit campaigns, this operation favored exploiting known security gaps, allowing it to maintain control of infected devices for over a week on average. The Lumen team also observed signs that multiple types of vulnerabilities were being used across various IoT device families—without evidence of novel or zero-day exploits.

Criminal Infrastructure-as-a-Service

The operation functioned as a “plug-and-play” rental service, where users could purchase temporary proxy access using cryptocurrency. The platform issued fresh IP/port combinations valid for 24 hours, eliminating the need for user registration or authentication. Once someone located the service, access was immediate—an approach similar to the tactics employed by NSOCKS and Faceless botnets.

To avoid exposure, the network performed deny-list checks, weeding out proxies that might appear on blacklists or monitoring feeds. This evasion tactic significantly complicated detection efforts for both researchers and enterprise defenders.

Neutralizing the Threat

The takedown was executed by Lumen’s cybersecurity arm in partnership with Spur, building on prior intelligence gathered by CERT Orange Polska. By null-routing data flowing to and from the botnet’s core infrastructure, Lumen severed communications at the backbone level, effectively rendering the network inoperable.

Indicators of compromise (IoCs), technical indicators, and details of the infrastructure are now publicly available on Black Lotus Labs’ GitHub repository to help other defenders identify and neutralize any remnants.

Looking Ahead

The disruption highlights the growing threat of residential IP botnets, especially as IoT adoption accelerates and legacy hardware lingers unpatched. These networks are hard to detect because their traffic blends seamlessly into everyday consumer activity.

Black Lotus Labs urges businesses to stay vigilant by blocking known malicious proxies, monitoring for credential stuffing or anomalous login behavior, and employing threat intelligence to preempt botnet abuse. Consumers are advised to reboot networking hardware regularly, apply firmware updates where available, and upgrade outdated devices that no longer receive vendor support.

The success of this operation underscores the power of international collaboration, with special recognition to the FBI and Dutch National Police for their pivotal roles in dismantling this long-standing cyber threat.

More Articles & Posts