On June 16, 2022, the United States Department of Justice announced that it had dismantled a Russian botnet called RSOCKS, working with the FBI and partners in Germany, the Netherlands, and the United Kingdom. To its customers, RSOCKS was a proxy service: pay by the day, get access to thousands of "residential" IP addresses, route your traffic through them. To investigators, it was a network of millions of hacked devices, and the people who owned those devices had never agreed to anything.
We run a residential proxy network, so RSOCKS is one of the cases we point to most, because it has everything the marketing hides in one place: a named operator, an official takedown, a guilty plea, and a device list that tells you exactly what "residential proxy" can quietly mean. A proxy (a server that forwards your traffic so a target site sees its address instead of yours) is only as clean as the machine it runs on. RSOCKS ran on stolen ones.
What RSOCKS actually was
RSOCKS first appeared in the cybercrime underground in 2014 as the web-based storefront for a botnet (a network of hacked devices controlled by one operator). Customers rented access to a pool of compromised machines that RSOCKS advertised as proxies. According to the Justice Department, the botnet's victims ran into the millions of devices worldwide.
The selling point was the same one every residential proxy service uses today. Traffic routed through a hacked home router or streaming box looks like an ordinary person online, not like a scraper or a fraud tool. That is what buyers were paying for, and RSOCKS delivered it by breaking into other people's hardware.
How it built its pool: brute force, not magic
RSOCKS did not need a sophisticated exploit. It got in by guessing. It ran brute-force attacks, trying weak and default passwords against internet-connected devices until one worked. The Internet of Things, meaning the everyday gadgets now connected to the internet, was a soft target because so many devices ship with a default password nobody ever changes.
The Justice Department's own description of what RSOCKS compromised is the most useful thing in the whole case, because it makes "residential proxy" concrete:
A smart garage door opener is not a data center. It is a real device on a real home connection, which is exactly why its IP address was worth money, and exactly why routing traffic through it is renting a stranger's hacked hardware.
The scale and the price list
RSOCKS grew fast. By 2016 it was advertising more than 80,000 proxies, and at its height it offered up to 90,000. Access was sold by the day, on a tiered rental model that reads like any cloud service, except the inventory was hijacked:
| Rental tier | Price | Proxies included |
|---|---|---|
| Entry | $30 per day | 2,000 |
| Top tier | $200 per day | up to 90,000 |
Those numbers come from the Justice Department and from Brian Krebs's reporting. Two hundred dollars a day for ninety thousand residential IPs is cheap, and the reason it was cheap is the whole point: RSOCKS paid nothing for its bandwidth, because it stole it.
The takedown and the operator
The June 2022 operation seized the infrastructure but did not name a defendant right away. The person behind it was identified and prosecuted afterward: Denis Emelyantsev, a 36-year-old Russian also known as Denis Kloster. He was arrested in Bulgaria in 2022 and, after a fight over extradition, sent to the United States.
In January 2023, Emelyantsev pleaded guilty in a California federal court to two counts, damage to protected computers and conspiracy to damage protected computers, and faced a maximum of 20 years in prison. Krebs also reported that he claimed ownership of RUSdot, a spam forum that succeeded the notorious Spamdot, and that he kept a blog under the Kloster name discussing, of all things, "security and anonymity services." The man selling anonymity to criminals was building his own brand around it.
Here is the sequence in one view:
- 2014First advertisedin the cybercrime underground
- By 201680,000+ devices offeredsold as proxies by the day
- June 16, 2022Infrastructure dismantledDOJ, FBI, and partners in Germany, the Netherlands, and the UK
- 2022Operator arrestedDenis Emelyantsev, in Bulgaria, then extradited to the US
- January 2023Guilty pleatwo computer-crime counts, facing up to 20 years
What replaced RSOCKS, and what did not change
There was no clean successor that inherited the RSOCKS name, but the model did not die with it. It is a template that keeps coming back. We took apart the 911 S5 botnet, which infected millions of Windows PCs through fake free VPN apps and whose operator was arrested in 2024, and VIP72, a 15-year malware-proxy network sourced from trojan-infected computers. In 2026 came the NetNut botnet takedown, allegedly running on more than two million smart TVs. Fake VPNs, banking trojans, brute-forced garage door openers, bundled TV apps: the delivery method changes, the product does not. Someone else's device, rented to you as "residential," without consent.
For a buyer, the practical risk is always the same. When you route through a proxy, you inherit its exit node's reputation. A pool built from a botnet is used for fraud and account takeover (fraudulently logging into accounts that are not yours) around the clock, so to a fraud-detection system your traffic looks identical to the crime that shares those IPs. That is why a botnet-sourced pool is burned before your first request, and why how websites detect proxies begins with IP reputation. There is also a legal edge that a proxy list never mentions: the RSOCKS case ended in a guilty plea for damaging protected computers, and its customers were routing traffic through machines that were, by definition, hacked.
How to avoid buying the next RSOCKS
You cannot inspect a provider's supply chain from outside, but you can ask the questions a clean one answers easily, and you can check what you are handed. The full version is our how to vet a proxy provider checklist:
- Ask how the pool is sourced. Disclosed, consented opt-in is the standard, and a provider that uses it can say so in a sentence. Vagueness is the answer.
- Be suspicious of cheap "SOCKS5 residential" sold by the day. That per-day, per-thousand-IP model priced far below the cost of real bandwidth is the RSOCKS shape.
- Check the network behind an IP. Our free proxy checker makes a real connection through a proxy and reports the exit location, anonymity grade, and the network the IP actually belongs to.
- Know who owns the brand. Ownership is not a guarantee, but a name you can trace is a start. We mapped the industry in who owns your proxy provider.
The honest takeaway
RSOCKS is the cleanest proof of a point the marketing will never make for you: "residential proxy" describes what the IP looks like, not where it came from. The IPs were genuinely residential. They were also genuinely stolen, one brute-forced password at a time, from routers and streaming boxes and a lot of people who never knew. The difference between that and a legitimate network is not the technology. It is consent, and whether the provider can tell you the truth about sourcing.
If you just need to test tooling or run something low-stakes, our free proxy list is honest about being mostly short-lived datacenter IPs, re-checked every few minutes. When you need residential IPs that hold up, we sell them at $0.65/GB pay as you go with no KYC and a balance that never expires, and the entire reason this article exists is the thing we would rather compete on: being able to tell you where they come from.
Sources
- U.S. Department of Justice, Southern District of California, "Russian Botnet Disrupted in International Cyber Operation" (June 16, 2022): the takedown, the agencies and countries involved, the device types, and the rental pricing.
- Krebs on Security, "Administrator of RSOCKS Proxy Botnet Pleads Guilty" (January 2023): the 2014 origin, the 80,000-plus proxy count, the operator's identity as Denis Emelyantsev / Denis Kloster, the arrest and extradition, the guilty plea, and the RUSdot connection.
- TechCrunch, "Rsocks, a popular proxy service, was just seized by the DOJ" (June 17, 2022): contemporaneous coverage of the seizure.