If you were anywhere near the fraud or account-farming scene in the 2010s, you knew VIP72. It was one of the oldest and best-known anonymity services on the market, a place to buy a SOCKS proxy (a proxy protocol that forwards raw traffic) that came out of a real residential connection instead of a data center. Then, in the late summer of 2021, its storefront simply vanished. No announcement, no goodbye, just a dead domain where a 15-year-old business used to be.
We run a residential proxy network, so the VIP72 story is one we keep coming back to. It is the clearest early example of a lesson that still decides whether a proxy purchase is safe or radioactive: the words "residential" and "anonymity" tell you nothing on their own. What matters is where the IPs came from. VIP72's came from other people's hacked computers.
What VIP72 actually was
On the surface, VIP72 looked like a privacy tool. You paid a small subscription, roughly ten dollars a month for around 90 proxies according to industry tracking, and you got access to a rotating pool of "real" residential IP addresses to route your traffic through. To a target website, your connection looked like an ordinary person at home.
Underneath, it was a botnet (a network of hacked devices under one operator's control). According to reporting by security journalist Brian Krebs, VIP72 routed its customers' traffic through computers that had been infected and seeded with malicious software. The people whose machines made up that pool had no idea they were part of it, and no idea that strangers were committing fraud under their home IP addresses. VIP72 was not selling privacy. It was renting out victims.
Who was behind it: "Corpse" and the Haxdoor trojan
VIP72 did not come from nowhere. Krebs traced the vip72.com domain, registered in 2006, to a Russian-speaking hacker who went by the handle "Corpse" (and earlier "Revive" on cybercrime forums). Corpse was not a small player. Between roughly 2003 and 2006, he built and sold one of the most advanced banking trojans of its era: A311 Death, better known as Haxdoor and sometimes Nuclear Grabber. A trojan is malware that hides inside or disguises itself as ordinary software. Haxdoor was years ahead of its time and was used in multiple million-dollar cyberheists before that kind of attack was daily news.
VIP72 was, in effect, the second act. The same malware operation that infected computers to steal from them could also rent those infected computers out as proxies. One crime funded the infrastructure for the next. That is the detail that makes VIP72 worth remembering: the proxy service and the malware were the same business.
How it worked: your PC as someone else's SOCKS proxy
The mechanic is simple and ugly. A computer gets infected, whether by Haxdoor or by whatever malware was bundling the VIP72 client later on. Once infected, that machine quietly starts accepting and forwarding other people's traffic. It is now a SOCKS exit node. VIP72 lists it in its storefront, a paying customer rents it, and every request that customer sends now comes out of a stranger's home internet connection.
This is exactly the appeal of a residential proxy to a buyer, and exactly the problem. The traffic looks human because it is literally coming out of a human's computer. When that human never consented, the "proxy" is stolen access, and everything routed through it is riding on a crime.
The slow fade and the day it went dark
For most of its life, VIP72 was big. Krebs reported that at its peak the service had several hundred thousand compromised systems available for rent at any given time, with its infrastructure sitting at the same United States internet address for over a decade. That longevity was part of the brand. In a scene where services appear and vanish constantly, VIP72 felt permanent.
By the end, it was not. When the storefront disappeared in mid-August 2021, the pool had shrunk to fewer than 25,000 systems worldwide.
Here is the arc in one view, from the malware that started it to the day the lights went out.
Why it died, and why that matters to a buyer
Nobody outside the operation ever confirmed why VIP72 went dark. Krebs laid out the two most likely explanations, and both are instructive. The domain may have been quietly seized in a law enforcement operation. Or the operator may simply have walked away, because VIP72 was losing ground to a newer generation of criminal proxy services and to the rise of so-called "bulletproof" residential proxy networks. A shrinking pool of fewer than 25,000 machines, down from hundreds of thousands, points at a service that was dying on its own before it disappeared.
For a buyer, the reason barely matters. What matters is the shape of the risk. When you route a request through a proxy, you inherit that exit node's reputation. A pool built from malware-infected machines is used for fraud and account takeover around the clock, so to any fraud-detection system your traffic looks exactly like the crime it shares those IPs with. A botnet-sourced pool is burned before you send a single request, which is why how websites detect proxies starts with IP reputation, not with clever headers.
"Anonymity service" and "residential proxy" were the same trick
The uncomfortable part of the VIP72 story is that its product was, technically, a residential proxy. The IPs really were residential. The traffic really did come from real consumer connections. Everything a legitimate provider advertises today, VIP72 could have claimed truthfully. The only difference, the one that mattered, is that its residential IPs belonged to people who had been hacked.
That is the same lesson we drew from the 911 S5 botnet, which infected millions of machines through fake free VPN apps, and from the NetNut botnet takedown, where a botnet allegedly ran on more than two million smart TVs. Different decade, different malware, identical shape: someone else's device, rented out as your "residential" IP, without consent. The technology is neutral every time. The supply chain is where the crime lives.
Where an honest network fits
You cannot audit a provider's whole supply chain from the outside, but you can ask the questions a shady one does not want to answer, and you can check what you are handed. The long version of this list is our how to vet a proxy provider guide:
- Ask how the pool is sourced. A provider using disclosed, consented opt-in can say so plainly. Vagueness is the answer.
- Distrust "anonymity" and "free VPN" as sources. That framing is the VIP72 and 911 model by definition.
- Check the network behind an IP before trusting it. Our free proxy checker makes a real connection through a proxy and reports its exit location, anonymity grade, and the network the IP actually belongs to.
- Know who stands behind the brand. Ownership does not guarantee clean sourcing, but a name you can trace is a start. We mapped the industry's real corporate structure in who owns your proxy provider.
VIP72 is proof that a proxy service can look established, run for 15 years, and still be a botnet the entire time. The label never changed. The sourcing was rotten from the first infected PC in 2006 to the last one in 2021.
If you just need to test tooling or run something low-stakes, our free proxy list is honest about being mostly short-lived datacenter IPs, re-checked every few minutes. When you need residential IPs that hold up, we sell them at $0.65/GB pay as you go with no KYC and a balance that never expires, and the whole point of this article is the thing we would rather compete on: being able to tell you where they come from.
Sources
- Krebs on Security, "15-Year-Old Malware Proxy Network VIP72 Goes Dark" (September 1, 2021): the "Corpse"/Haxdoor attribution, the 2006 domain registration, the peak and shutdown pool figures, and the reasons it went dark.
- Krebs on Security, VIP72 tag archive: ongoing coverage of the service and its place in the malware-proxy ecosystem.
- HProxy internal competitor research (2026): the subscription price point (roughly $10/month for around 90 proxies) and the vip72.org secondary-domain flag.