"Residential proxy": what it is and why criminals want it
A residential proxy is a normal home internet connection — with an IP from your own ISP, the same one you use to stream video or handle an errand — that a third party uses to route their own traffic. To anti-fraud services and firewalls, traffic coming from a "real" residential IP looks far more trustworthy than traffic from a datacenter, which is exactly why these networks became a core tool for hiding malicious activity at scale1.
The problem is how these networks get built: by recruiting infected home devices, without their owners' knowledge or consent.
Google took down one of the world's largest networks — and named TV boxes explicitly
In January 2026, Google disclosed the takedown of IPIDEA, described as one of the largest residential proxy networks in the world: millions of devices removed from the pool, roughly 7,400 "Tier Two" command-and-control servers identified, and over 600 Android apps found with IPIDEA's proxy code embedded. In a single 7-day period, more than 550 distinct threat groups used this network's exit nodes2.
"Researchers have previously found uncertified and off-brand Android Open Source Project devices, such as television set top boxes, with hidden residential proxy payloads."
— Google Threat Intelligence, official Google Cloud blog2
That quote is verbatim from Google's own blog. It's not an inference by AMK — it's the conclusion of the investigation that led to the network's takedown.
Aisuru: from DDoS attacks to reselling your connection
Aisuru is a botnet first identified in August 2024, which infected roughly 700,000 IoT devices (routers, security cameras, and other connected equipment). Originally used for record-setting DDoS attacks — reaching almost 30 terabits per second of traffic — in 2025 its operators started renting the infected devices out as residential proxies instead of (or alongside) using them to take down websites3.
According to Roland Dobbins, a Netscout engineer quoted by security journalist Brian Krebs, outbound attack traffic from these compromised devices exceeded 1 terabit per second in some cases, causing "significant disruption to wireline and wireless broadband access networks"3. In plain terms: it's not just the owner of the infected device who suffers — the sheer volume of traffic generated can degrade service for other customers on the same ISP.
The same Krebs on Security coverage specifically mentions BADBOX 2.0 as one of the related operations, compromising "smart-TV boxes, digital projectors, vehicle infotainment units, picture frames," and other IoT devices3.
Is your internet slow for no obvious reason? It might be your TV box, not your provider.
Scan my deviceWhat this means for your upload bandwidth
Most home connections are built to download far more than they upload: streaming, browsing, online gaming. Almost no legitimate home app sustains 100% of your upload bandwidth. A device turned into a residential proxy node does exactly that: it continuously forwards someone else's traffic in the background, consuming precisely the resource you monitor least and that your router almost never shows you in detail.
This explains a very specific, common symptom: internet that "feels slow" especially for calls, video conferencing, or live gaming — upload-sensitive activities — without downloading a file or streaming video feeling especially affected.
The risk doesn't stop at speed
According to Google's own analysis of IPIDEA, a device turned into a residential proxy "exit node" exposes three more problems beyond speed2:
- Security vulnerabilities: the proxy software itself introduces security gaps into the device and your home network.
- Exposure of the rest of your network: once your device becomes an exit node, traffic you don't control passes through it — which can give an attacker access to other devices on the same network.
- Damage to your own IP's reputation: your connection can end up flagged as suspicious or blocked by other services, without you having done anything wrong.
What to do
If you have a generic TV box, especially a cheap or unrecognized-brand one, it's exactly the type of device these investigations flag as a target. AMK scans your device's actual system — not just what you see on screen — and compares it against a threat catalog built from this same kind of real research, including known ad-fraud and residential-proxy apps.
Scanning is free. You only pay if we find a real threat.
Scan my device for free