If you have been in the proxy world for more than a few years, you remember "911," or 911[.]re, one of the best-known residential proxy services on the market. Then it vanished, came back under a different name, and ended with its operator in handcuffs in Singapore and the U.S. Treasury freezing his assets. This is what actually happened to 911 S5, why the FBI called it likely the largest botnet ever, and why the whole story is really about one question every proxy buyer should ask: where do these IPs come from?
We run a residential proxy network, so this case is the cautionary tale we point to most. 911 S5 is not ancient history. Its exact model, get onto real people's devices, then rent them out as "residential," is alive and well today under other names, and the lesson from its collapse is the most useful thing you can carry into any proxy purchase.
What 911 S5 actually was
On the surface, 911 was a residential proxy service: pay a fee, get access to millions of "real" home IP addresses, and route your traffic through them so target sites see an ordinary residential connection instead of yours. That is a normal, legal product when the IPs are sourced with consent.
911 S5's were not. According to the U.S. Department of Justice, the operation infected millions of residential Windows computers worldwide and amassed access to more than 19 million unique IP addresses across nearly 200 countries, including 613,841 in the United States alone, all managed through roughly 150 dedicated servers. The FBI called it "likely the world's largest botnet ever." The people whose computers made up that network had no idea they were part of it.
How it spread: fake free VPNs
The genius and the ugliness of 911 S5 was the delivery method. It did not need an exotic exploit. It shipped its proxy backdoor inside software people installed on purpose: six free VPN applications named MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN and ShineVPN, plus pirated software bundled with the same code.
Someone would download a "free VPN" to hide their traffic, and in doing so hand their computer over as an exit node for everyone else. Their machine now carried strangers' traffic under their home IP address.
That is the entire appeal of residential proxies to a buyer: the traffic looks human because it is literally coming out of a human's computer. It is also the entire problem, because that human never agreed to any of it.
What the network was used for
This was not a victimless gray-market convenience. The Justice Department tied 911 S5 to a staggering volume of real-world crime committed through those hijacked home connections: roughly 560,000 fraudulent unemployment insurance claims and more than 47,000 pandemic-relief (EIDL) applications, part of billions of dollars in pandemic-relief losses, alongside ransomware, harassment, and other attacks. Every one of those came out of an ordinary person's IP address, which is exactly why the operator's customers valued it and exactly why investigators eventually moved.
The takedown, and the operator
911 S5 shut down in July 2022 after its infrastructure was exposed, but it did not stay dead. It re-emerged in October 2023 as "Cloud Router," rebuilt on the same idea. That resurrection is why the 2024 operation mattered: it went after the successor, not just a corpse.
In May 2024, a coordinated international operation dismantled the network and arrested its administrator, YunHe Wang, in Singapore on May 24, 2024. Prosecutors say Wang earned roughly $99 million selling access to the compromised devices. On May 29, 2024, the U.S. Treasury sanctioned Wang and two associates, and he was charged with computer fraud, wire fraud, and money laundering conspiracy, facing up to 65 years in prison.
A short timeline
- 2014 to July 2022: 911 S5 operates, building a network linked to 19 million-plus unique IPs via fake free VPNs and pirated software.
- July 2022: the service shuts down after its infrastructure is exposed.
- October 2023: it re-emerges as "Cloud Router," the same model under a new name.
- May 24, 2024: administrator YunHe Wang is arrested in Singapore.
- May 29, 2024: the U.S. Treasury sanctions Wang and two associates; the botnet is dismantled in a coordinated international operation.
The lesson: this model did not die with 911
Here is why we keep pointing at this case. The 911 S5 model, quietly turn real consumer devices into exit nodes and rent them out as "residential," is not a one-off crime. It is a recurring template.
We saw it again in 2026 with the NetNut botnet takedown, where a botnet researchers call "Popa" allegedly ran on more than two million smart TVs and streaming boxes through bundled SDKs, and the FBI seized the proxy service that allegedly monetized it. Different decade, different devices, identical shape: someone else's hardware, turned into your "residential" IP, without consent.
The through-line is sourcing, and it is not an ethics footnote. When you route a request through a residential proxy, you inherit that exit node's reputation. A pool built from a botnet is used for fraud and account takeover around the clock, so to every fraud-detection system your traffic looks exactly like the crime that shares those IPs. A botnet-sourced pool is burned before you send a single request, which is the practical reason how websites detect proxies starts with IP reputation.
Why "free residential" is where this still hides
The uncomfortable takeaway is that 911 S5 was, at its core, a "free VPN." That is not a coincidence. Honestly sourced residential bandwidth costs real money, so when a residential IP is handed out for free, the device owner is almost always the one paying for it without knowing. Most free proxies on a public list are actually short-lived datacenter IPs, and in our own study of 47 million proxy checks the free pool is overwhelmingly datacenter. But the "free residential" category specifically is the direct descendant of the 911 model, and we take that trap apart in free residential proxies: what is real and what is a trap and are free proxies safe.
How to not buy the next 911
You cannot audit a provider's whole supply chain from the outside, but you can ask the questions that make a shady one uncomfortable, and you can check what you are handed:
- Ask how the pool is sourced. A provider using consented, disclosed opt-in can say so plainly. Vagueness is the answer.
- Distrust "free residential" and "free VPN" as sources. That is the 911 S5 delivery method by definition.
- Check the network behind an IP before trusting it. Our free proxy checker makes a real connection through a proxy and reports the exit location, anonymity grade, and the network the IP actually belongs to.
- Know who stands behind the brand. Ownership does not guarantee clean sourcing, but a name you can trace is a start. We mapped the industry's real corporate structure in who owns your proxy provider.
The honest takeaway
911 S5 is the clearest proof that "residential proxy" tells you nothing on its own. The label was identical to what a legitimate provider sells. The difference, the only difference that mattered, was that its 19 million IPs belonged to people who never agreed to share them. The technology is neutral. The supply chain is where the crime lived.
If you just need to test tooling or run a low-stakes task, our free proxy list is honest about being mostly short-lived datacenter IPs, re-checked every few minutes. When you need residential IPs that hold up, we sell them at $0.65/GB pay as you go with no KYC, and the entire point of this article is the thing we would rather compete on: being able to tell you where they come from.
Sources
- U.S. Department of Justice, "911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation" (May 29, 2024)
- BleepingComputer, "US dismantles 911 S5 residential proxy botnet used for cyberattacks, arrests admin" (device counts, VPN app names, fraud figures)
- SecurityWeek, "Massive 911 S5 Botnet Dismantled, Chinese Mastermind Arrested" (arrest, penalties)
- CyberScoop, "Chinese national arrested for operating proxy service linked to billions in cybercrime" (Cloud Router re-emergence, October 2023)