Where Do Residential Proxies Actually Come From?

By Nicholas St. Germain —

Every residential proxy provider makes the same basic claim: millions of real IPs on real home connections. Ask where those IPs actually come from and the answers thin out fast. "Ethically sourced" appears on a lot of homepages. A mechanism rarely does.

The question has a concrete answer, and over the past two years it has accumulated receipts: a DOJ indictment with hard dollar figures, two Google threat-intelligence takedowns, an FBI domain seizure against a Nasdaq-listed company, and civil rulings that cut in both directions. A residential proxy works because someone's phone or smart TV or desktop forwards a stranger's traffic over a home connection. Everything that matters about this industry is in how that device ended up doing it.

How residential proxy sourcing works

The supply sits on a consent spectrum. At one end, people knowingly sell their idle bandwidth. In the middle, devices join pools through setup prompts their owners forgot within a week. At the bottom, malware conscripts machines outright.

Tier How devices join the pool Consent Where the law stands
Paid bandwidth-sharing apps (Grass, Honeygain) The user installs an app that plainly says it resells idle bandwidth, and gets paid for it Disclosed and compensated Civil scraping disputes only
SDK monetization (free apps, smart-TV apps) A developer embeds a proxy vendor's SDK and the vendor pays the developer A one-time prompt; the proxy often keeps running after the app closes Platform policies are uneven: Amazon prohibits it, LG and Samsung have no public policy
Proxyware and botnets (911 S5, BADBOX 2.0, Popa) Malware, fake VPN installers, or hardware that ships pre-botted Little or none Indictments, Treasury sanctions, FBI domain seizures

This post walks that spectrum end to end with dates and sources, then covers what enforcement and the courts have done. There is a short note at the end about where our own IPs come from, because it is a different supply chain entirely, and it would be dishonest to pretend the rest of this piece was not written from that vantage point.

The disclosed end: paid bandwidth-sharing apps

The cleanest residential supply comes from apps whose entire pitch is bandwidth sharing. A user installs software that says, plainly, that it will resell their idle connection, and they get compensated for it. Grass (getgrass.io) is the current high-profile example of the model; Krebs on Security described it in November 2025 reporting on consumer-device proxy networks. Honeygain is the older one, operated by Honeygain UAB, which Spur identifies as an Oxylabs-affiliated brand.

Even here, consent has edges. The person sharing bandwidth has no visibility into who rents their line or what it gets used for, and the disclosure is only as good as the moment someone actually read it. But a human clicked yes on an accurate description of the deal. In this market, that makes it the top tier.

The middle: SDK monetization buried in free apps and smart TVs

The bigger channel is quieter. A developer embeds a proxy vendor's SDK in a free app or game, the vendor pays the developer, and every device running that app becomes an exit node. If the mechanics of how these pools carry traffic are new to you, our guide to datacenter, residential, and ISP proxies covers how each type routes a request; this section is about how the devices get into the pool in the first place.

The best current measurement of how far this reaches is Spur's smart-TV study published June 22, 2026. Spur scanned 6,038 LG webOS and Samsung Tizen apps and found residential proxy SDKs in 2,058 of them, roughly 34 percent overall: 42.5 percent of the LG apps and 26.9 percent of the Samsung apps. The publishers were not obscure. Bright Data entities (Bright Data Ltd and Bright SDK) were listed as the publisher on 367 of the flagged apps, Honeygain UAB on 16.

Consent exists on paper. Spur's description of it in practice is worth quoting: the SDKs rely on "a one-time prompt navigated with the remote" that "can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted." All three proxy vendors' prompts in the study allow the proxy to keep running after the app is closed. Platform rules are uneven too: the same report notes that Amazon explicitly prohibits proxy services in its Device and System Abuse Policy, while LG and Samsung have no equivalent public policy.

Some hardware skips the prompt entirely. The same Krebs reporting from November 24, 2025 found that cheap "Superbox" Android TV streaming boxes ship already botted, and that the BADBOX 2.0 botnet, more than 10 million Android streaming devices, was the target of a John Doe lawsuit Google filed in July 2025. Those devices fed residential proxy networks including China-based IPidea.

From the buyer's side, none of this is visible. An IP from an informed Grass user and an IP from a TV whose owner clicked through a setup screen two years ago look identical in the pool you are renting.

The criminal end: proxyware and botnets

At the bottom is straight malware, and the defining case is 911 S5. According to the Justice Department's May 29, 2024 announcement, the operation spread malware from 2014 until July 2022 and amassed a pool of compromised residential Windows computers associated with more than 19 million unique IP addresses, 613,841 of them in the United States. Its administrator, YunHe Wang, allegedly earned about $99 million selling proxy access to that pool. The headline harm figure: 560,000 fraudulent unemployment claims filed from compromised IPs, with confirmed losses above $5.9 billion.

The distribution method matters here, because it impersonated the top tier. Krebs's coverage of the Treasury sanctions notes the malware rode along with free VPN products named MaskVPN, DewVPN, and PaladinVPN. Users thought they were installing privacy software; their machines became rentable exits. After a breach, the service rebranded as Cloud Router, which rented access to more than 140,000 IPs before shutting down.

The boundary between this tier and the SDK tier is thinner than the industry likes to admit. Google's July 2, 2026 analysis of the Popa network that fed NetNut counted at least 2 million hijacked devices, and Krebs's reporting on the seizure says those devices were compromised "with little or no consent from victims." That network was not sold on a forum. It was retailed by a Nasdaq-listed company and, per Google, white-labeled by many residential proxy brands through an extensive reseller program. A customer buying residential IPs from one of those brands in early 2026 had no way to know some of the exits were Popa nodes.

What enforcement has done

Two years of action, each move aimed higher up the supply chain than the last:

Date Enforcement action
May 24, 2024 YunHe Wang arrested in Singapore over the 911 S5 botnet
May 28, 2024 Treasury sanctions Wang, Jingping Liu, and Yanni Zheng, plus three Thailand-based companies
May 29, 2024 DOJ announces 911 S5 dismantled: more than 19 million unique IPs, about $99 million in alleged proxy sales
January 28, 2026 Google's Threat Intelligence Group announces the disruption of IPIDEA
June 19, 2026 Three security firms publish findings linking NetNut to the Popa botnet
July 2, 2026 FBI seizes hundreds of NetNut-associated domains; Google publishes its Popa analysis

The 911 S5 action came first. Wang was arrested in Singapore on May 24, 2024 and charged with conspiracy to commit computer fraud, wire fraud conspiracy, and money laundering conspiracy, counts carrying a 65-year statutory maximum. Forfeiture targets included a Ferrari F8 and 21 properties across five countries, with roughly $30 million in assets seized and about the same again identified. Four days after the arrest, on May 28, the Treasury Department sanctioned Wang, Jingping Liu, and Yanni Zheng along with three Thailand-based companies. One caveat we want on the record: we could find no public report of a conviction or sentence for Wang as of July 2026, so all of this remains charges, not a verdict.

Google then started attacking supply networks directly. On January 28, 2026, its Threat Intelligence Group announced the disruption of IPIDEA, which it called one of the world's largest residential proxy networks. The scale numbers are the point. In a single seven-day window that January, GTIG observed more than 550 distinct threat groups, operating from China, North Korea, Iran, and Russia, using IPIDEA exit nodes. It mapped about 7,400 tier-two servers and over 600 Android apps carrying IPIDEA proxy code, then combined legal takedowns of command-and-control domains with Play Protect warnings and removals that Google says pulled millions of devices out of the pool.

NetNut came six months later, and it was the escalation. Three security firms published findings linking NetNut to the Popa botnet on June 19, 2026. On July 2, the FBI seized hundreds of NetNut-associated domains, with netnut.com, proxyjet.io, and divinetworks.com among those named in public reporting, in coordination with Google, Lumen, and Shadowserver. NetNut's operator, Alarum Technologies (NASDAQ: ALAR), said it is cooperating with law enforcement; its stock fell about 67 percent within a week, to $2.62 by July 8. A listed company's network, per Google, carried traffic for 316 distinct threat clusters in one week of June 2026.

Where the courts pushed back the other way

It would be easy to read the takedowns and conclude the whole industry is one indictment from collapse. The civil courts have said something more complicated, and honesty requires noting that proxy providers have won the biggest scraping cases outright.

On January 23, 2024, Judge Edward Chen of the Northern District of California granted Bright Data summary judgment against Meta, holding that Facebook's and Instagram's terms "do not bar logged-off scraping of public data" and cannot bar the sale of that data. A month later, on February 23, Meta dropped its remaining claim and waived its appeal. The ruling did not address logged-in scraping, but on public data the scraper won cleanly.

X Corp. fared no better at first. On May 9, 2024, Judge William Alsup dismissed all of X's claims against Bright Data, holding that the Copyright Act preempted X's state-law theories and warning that giving platforms free rein over public data "risks the possible creation of information monopolies." In December 2024, Alsup allowed X to file an amended complaint with new server-burden allegations, so that case is partially revived, but the May ruling stands as written.

The providers have also litigated against each other. On November 5, 2021, an Eastern District of Texas jury found that Oxylabs infringed Bright Data (then Luminati) residential-proxy patents. Damages were reported at roughly $7.5 million, though that figure appears only in secondary headlines, not in either party's official statements. And per Oxylabs' own legal timeline, the Federal Circuit affirmed invalidation of two of the three patents in August 2025 and the Supreme Court declined review in February 2026. We found no evidence that any money ever changed hands, so treat the $7.5 million as reported, never collected.

The pattern across all of it: courts have been surprisingly tolerant of scraping public data, while criminal exposure attaches to how the IP pool was built. What you collect and whose device you route through are separate legal questions, and the second one is where the arrests happen.

FAQ

How do residential proxies work?

A residential proxy routes your traffic through a real consumer device on a home internet connection, so the sites you visit see that household's IP address instead of yours. Providers assemble those devices into pools through bandwidth-sharing apps, SDKs embedded in free apps and smart TVs, or, at the criminal end, malware, and then rent access to the pool. From the buyer's side the sourcing is invisible: an IP volunteered by a paid user and an IP from a hijacked TV look identical.

Are residential proxies illegal to use?

No. Scraping public data through proxies has repeatedly survived in civil court, most notably in the Meta and X cases against Bright Data. The criminal actions targeted operators who built pools from hijacked devices, not the customers renting access. Customers of a compromised network still inherit practical problems, including seized infrastructure and IPs tied to fraud investigations.

How can I tell how a provider sources its residential IPs?

Ask for the mechanism rather than the adjective. A real answer names the apps or SDK partners supplying the pool, describes the consent prompt users see, and explains whether the proxy keeps running after the app closes. If the pool is white-labeled from another network, ask which one. The NetNut case showed that many resellers could not answer that question about their own product.

What happened to the 911 S5 botnet operator?

YunHe Wang was arrested in Singapore in May 2024 and charged with computer fraud, wire fraud conspiracy, and money laundering conspiracy, facing a statutory maximum of 65 years. As of July 2026 we found no public record of a conviction or sentence, so the case should be described as pending charges rather than a verdict.

What is the difference between residential and static ISP proxies?

A residential proxy exits through a real consumer device on a home connection, usually drawn from a rotating pool. A static ISP proxy is a fixed IP registered in carrier address space but announced from server infrastructure, so no consumer device ever carries the traffic. Residential pools offer rotation and wide geography; static ISP proxies trade that away for stability and a supply chain that can be audited.

Where our IPs come from

This closing section is first person and about us, so weigh it accordingly.

Stat Proxies does not operate a residential pool. We sell US-only static ISP proxies: address space leased through Tier-1 US carriers and announced from infrastructure we run ourselves. There is no SDK, no bandwidth-sharing app, and no third-party device anywhere in the path, which means the consent questions this article is about do not arise in our supply chain. Every IP we sell traces from a carrier lease to our own racks, the standard we document on our ethically sourced proxies page. Keeping that announcement path clean is its own ongoing job, one we talked through in our interview on fighting IP hijacking.

That is a different risk category, not a claim of universal superiority. When the FBI seized NetNut's domains this month, resellers and their customers learned overnight what their supply chain had been; our breakdown of the NetNut seizure covers how that unfolded. Nothing in our chain depends on a stranger's television staying opted in.

And to be equally plain about the limits: static ISP proxies lose to rotating residential pools on hostile anti-bot targets that burn individual IPs quickly, we offer US locations only, the proxy connection is HTTP/HTTPS with username and password authentication and nothing else, and no proxy of any kind fixes a JavaScript or TLS fingerprinting challenge. If the job needs a rotating pool across fifty countries, we are the wrong tool. If it needs stable US IPs whose provenance you can verify, that is the category we are in.