Comparison

What Happened to AWM Proxy? The Malware Service That Sold Your PC for 13 Years

AWM Proxy sold access to malware-infected PCs as proxies from 2008 until Google sued its operators in 2021. How it worked, who ran it, and the Glupteba link.

HProxy Team · ·Updated July 21, 2026 ·8 min read
HProxy. Comparison

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.65/GB, pay as you go.

See plans & pricing

For thirteen years, if you were a criminal who needed to route traffic through a stranger's computer, AWM Proxy was where you went. It launched in March 2008 and quietly became the largest service of its kind, a storefront where you could rent access to tens of thousands of malware-infected PCs and send your traffic out through their owners' home internet connections. It ran in plain sight for over a decade. Then, in December 2021, Google sued the men behind it, and the mask came off.

We run a residential proxy network, so we keep coming back to AWM Proxy for the same reason we keep coming back to 911 S5 and RSOCKS: it is a clean, documented example of the one thing marketing never tells you. A proxy (a server that forwards your traffic so a target site sees its address instead of yours) is only ever as clean as the machine it runs on. AWM Proxy ran on hundreds of thousands of hacked ones, and the paper trail that ended it is unusually complete.

What AWM Proxy actually was

On the surface, AWM Proxy was a proxy service like any other. You paid, you got access to a pool of IP addresses, you routed traffic through them. Underneath, every one of those IPs belonged to a computer that had been infected with malware and turned into an exit node without its owner's knowledge.

According to reporting by security journalist Brian Krebs, when AWM Proxy first drew attention in 2011 it was renting out roughly 24,000 infected PCs scattered across dozens of countries. That was already large for the era. What made it notable was not just the size but the source. Kaspersky Lab researchers examined the machines for rent and found that virtually all of them had been compromised by the same thing: a rootkit.

The malware underneath: TDSS, then Glupteba

The rootkit was TDSS, also known as TDL-4 and Alureon. A rootkit is malware that installs itself deep inside a system, so deep that TDSS loaded before the Windows operating system itself, which made it extremely hard to detect or remove. A machine infected with TDSS was, for practical purposes, owned by whoever controlled the botnet, and one of the things that control was used for was to quietly turn the PC into a proxy and list it on AWM Proxy.

The story did not stop with TDSS. In March 2011, researchers at ESET found that TDSS was being used to install a newer piece of malware called Glupteba. Over the following decade, Glupteba grew into a botnet of more than a million infected Windows computers. It is a nastier and more modern thing than the old rootkit: it mines cryptocurrency on victims' machines, steals their account credentials to sell, commits credit-card fraud, and rents out access to the compromised devices. And it is deliberately hard to kill, because it uses the Bitcoin blockchain to store the addresses of its command servers, so even if those servers are seized, the infected machines can look up new ones. AWM Proxy was one of the ways all that hijacked capacity got turned into cash.

The scale, and the price of a stranger's computer

AWM Proxy grew for a decade. The 24,000 machines Krebs counted in 2011 were only the beginning. A decade later the service was offering roughly ten times that number of hacked systems, and by the middle of 2022 Krebs reported it advertising about 175,000 compromised computers available in a single day.

The pricing is the tell. Krebs reported access ranging from about $50 a day up to nearly $700 for "VIP access." Renting a large slice of a global botnet for the price of a nice dinner only works because the operator pays nothing for the underlying bandwidth or hardware. Every one of those machines was somebody's actual computer, running up somebody's actual electricity and data, while a stranger committed fraud through it. The cheapness was not a bargain. It was the fingerprint of stolen infrastructure, the same fingerprint you see on every botnet-sourced proxy service.

The takedown, the operators, and the sanctions

For years AWM Proxy operated without anyone publicly attached to it. That changed when Google went after the botnet underneath it.

Krebs traced the service to Dmitry Sergeevich Starovikov, a Russian man connected to AWM Proxy through the email address [email protected] and the Skype handle "lycefer." On December 7, 2021, Google announced it had moved to disrupt the Glupteba botnet and filed a civil lawsuit in the Southern District of New York against Starovikov and a second Russian, Alexander Filippov, who both claimed to work as software engineers for a company called Valtron LLC. AWM Proxy went offline the same day Google made its announcement.

It did not stay offline, because Glupteba was built not to. The botnet's blockchain-based control system let it survive Google's disruption, and the service resurfaced. That resilience is exactly why the 175,000-machine figure comes from mid-2022, months after the supposed takedown.

The court case, though, went badly for the operators. Rather than mount a real defense, Starovikov and Filippov at one point offered to hand Google information about the botnet's Bitcoin addresses in exchange for a million dollars each and a promise not to report them to law enforcement. Google treated the offer as attempted extortion and told law enforcement. In November 2022, the court ruled for Google and imposed monetary sanctions on the defendants and, unusually, on their own US-based lawyers, finding they had acted in bad faith and tried to mislead the court. The operators were ordered to pay Google's legal fees.

Why this matters to a buyer, not just a victim

It is easy to read a story like this as being only about the people whose PCs were hijacked. It is about them. But there is a direct lesson for anyone buying proxies too.

When you route a request through a proxy, you inherit that exit node's reputation. A pool assembled from a botnet is used for cryptomining, fraud, spam, and account takeover (fraudulently logging into accounts that are not yours) around the clock, so to any fraud-detection system your traffic looks exactly like the crime it shares those IPs with. A botnet-sourced pool is burned before you send your first request, which is the practical reason how websites detect proxies starts with IP reputation and not with clever headers. And there is a legal edge the marketing never mentions: the machines were, by definition, hacked, and routing traffic through them meant using access that a court eventually treated as a crime.

The uncomfortable part is that AWM Proxy, technically, delivered exactly what a residential-style proxy promises. The IPs were real consumer connections. The traffic looked human because it was coming out of real humans' computers. Everything a legitimate provider advertises, AWM Proxy could have claimed. The only difference, the one that mattered, is that its machines belonged to people who had been infected. We saw the same shape in 911 S5, which spread through fake free VPN apps, and in RSOCKS, which brute-forced routers and smart devices. The delivery method changes. The product does not.

How to avoid buying the next AWM Proxy

You cannot audit a provider's whole supply chain from the outside, but you can ask the questions a shady one does not want to answer, and you can check what you are handed:

  • Ask how the pool is sourced. A provider using disclosed, consented opt-in can say so in a sentence. Vagueness is the answer.
  • Distrust cheap access to hacked-looking IPs sold by the day. Rock-bottom per-day pricing for "SOCKS" or "residential" access, priced far below the cost of real bandwidth, is the AWM Proxy and RSOCKS shape.
  • Check the network behind an IP. Our free proxy checker makes a real connection through a proxy and reports the exit location, anonymity grade, and the network the IP actually belongs to.
  • Know who stands behind the brand. Ownership is not a guarantee, but a name you can trace is a start. We mapped the industry's real corporate structure in who owns your proxy provider.

AWM Proxy is proof that a proxy service can run for thirteen years, look established, and be a malware operation the entire time. The label never changed. The sourcing was rotten from the first infected PC in 2008 to the day a court finally put a number on the damage.

If you just need to test tooling or run something low-stakes, our free proxy list is honest about being mostly short-lived datacenter IPs, re-checked every few minutes. When you need residential IPs that hold up, we sell them at $0.65/GB pay as you go with no KYC and a balance that never expires, and the whole point of this article is the thing we would rather compete on: being able to tell you where they come from.

Sources

Frequently asked questions

What was AWM Proxy?
AWM Proxy (awmproxy.net, later awmproxy.com) was a service that sold access to malware-infected computers as proxies. Launched in March 2008, it became the largest marketplace for criminals who wanted to route their traffic through other people's hacked PCs, all under those victims' home IP addresses. The people whose machines it rented out never agreed to any of it.
How did AWM Proxy get its proxies?
From malware. In 2011, Kaspersky Lab found that almost every machine for rent on AWM Proxy had been infected by the TDSS rootkit, also known as TDL-4 and Alureon, malware that installs deep in a PC and loads before Windows does. Each infected computer quietly became a proxy that strangers paid to route traffic through. Later, the same operation was tied to the much larger Glupteba botnet.
Who ran AWM Proxy?
Security journalist Brian Krebs traced AWM Proxy to Dmitry Sergeevich Starovikov, a Russian man linked to the service through the email [email protected] and the Skype handle 'lycefer.' In December 2021, Google named Starovikov and a second Russian, Alexander Filippov, in a civil lawsuit over the Glupteba botnet that powered the service.
What is the Glupteba botnet?
Glupteba is a botnet of more than a million infected Windows computers used for cryptocurrency mining, credential theft, credit-card fraud, and renting out compromised machines. Its defining trick is resilience: it uses the Bitcoin blockchain to hide the addresses of its control servers, so it can survive attempts to shut it down. AWM Proxy was one of the ways that hijacked capacity was sold.
What happened to AWM Proxy?
On December 7, 2021, Google announced it had disrupted Glupteba and sued its operators, and AWM Proxy went offline that day. Because Glupteba's blockchain-based control system survived, the service came back, and by mid-2022 Krebs reported it advertising roughly 175,000 hacked systems a day. In November 2022 a US court ruled for Google and sanctioned the operators and their own lawyer for acting in bad faith.
How do I avoid buying a botnet-sourced proxy?
Ask any provider how its pool is sourced and treat a vague answer as the answer, because consented, disclosed opt-in is a standard a clean provider can state plainly. Be suspicious of very cheap access to hacked-looking 'SOCKS' or 'residential' IPs sold by the day. And verify any IP you are handed with a proxy checker before you route anything sensitive through it.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires.

47M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup