Black Lotus Labs reported a sprawling malicious residential proxy ecosystem built from compromised IoT and SOHO routers, Android devices, and Android TV boxes, tracking nearly 20 million distinct IPs per day across 30+ botnet clusters. The research identified major services and botnets including IPIDEA, Jaguar, Kookeey, NetNut/Popa, G3Proxy, NSOCKS/Ngioweb, and ASOCKS/Nexusnet, and said many operators both maintain their own botnets and resell access to other infected devices. Lumen said more than 20 of the clusters regularly exceed 100,000 daily victims, with roughly half of the tracked malicious proxy botnets operated by Chinese actors and many services excluding mainland China from their proxy pools.
Separate analysis of the low-cost Android-based Magcubic HY300 Pro+ projector showed how consumer hardware can feed that ecosystem. Investigators found preinstalled firmware components, including com.hotack.silentsdk and com.hotack.writesn, generating suspicious DNS requests such as usmyip.kkoip.com and appearing designed to register the owner’s IP address for possible enrollment into a residential proxy network without consent. Researchers warned the issue may extend to other inexpensive Android projectors tied to Hotack, Huyukang, and Nonete, reinforcing concerns that cheap, poorly vetted smart devices are being used as covert infrastructure for proxy botnets and related criminal activity, including card fraud operations and DDoS abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Black Lotus Labs published research describing a large global ecosystem of malicious residential proxy botnets built from compromised IoT/SOHO routers, Android devices, and Android TV boxes. The report said Lumen tracks nearly 20 million distinct IPs per day across more than 30 botnet clusters.
Analysis described in Zane St. John’s blog found that the low-cost Android-based Magcubic HY300 Pro+ projector made suspicious DNS requests immediately after joining Wi‑Fi. Investigators identified pre-installed components including com.hotack.silentsdk and com.hotack.writesn as likely responsible for background communications that could enroll the device into a residential proxy network without user consent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecert.gov.az
Open sourcezanestjohn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.