Comparison

What Happened to VIP72? The 15-Year Malware Proxy Network That Went Dark

VIP72 sold access to malware-infected PCs as SOCKS proxies for 15 years, then vanished in 2021. Who ran it, how it worked, and the sourcing lesson.

HProxy Team · ·Updated July 21, 2026 ·7 min read
HProxy. Comparison

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.65/GB, pay as you go.

See plans & pricing

If you were anywhere near the fraud or account-farming scene in the 2010s, you knew VIP72. It was one of the oldest and best-known anonymity services on the market, a place to buy a SOCKS proxy (a proxy protocol that forwards raw traffic) that came out of a real residential connection instead of a data center. Then, in the late summer of 2021, its storefront simply vanished. No announcement, no goodbye, just a dead domain where a 15-year-old business used to be.

We run a residential proxy network, so the VIP72 story is one we keep coming back to. It is the clearest early example of a lesson that still decides whether a proxy purchase is safe or radioactive: the words "residential" and "anonymity" tell you nothing on their own. What matters is where the IPs came from. VIP72's came from other people's hacked computers.

What VIP72 actually was

On the surface, VIP72 looked like a privacy tool. You paid a small subscription, roughly ten dollars a month for around 90 proxies according to industry tracking, and you got access to a rotating pool of "real" residential IP addresses to route your traffic through. To a target website, your connection looked like an ordinary person at home.

Underneath, it was a botnet (a network of hacked devices under one operator's control). According to reporting by security journalist Brian Krebs, VIP72 routed its customers' traffic through computers that had been infected and seeded with malicious software. The people whose machines made up that pool had no idea they were part of it, and no idea that strangers were committing fraud under their home IP addresses. VIP72 was not selling privacy. It was renting out victims.

Who was behind it: "Corpse" and the Haxdoor trojan

VIP72 did not come from nowhere. Krebs traced the vip72.com domain, registered in 2006, to a Russian-speaking hacker who went by the handle "Corpse" (and earlier "Revive" on cybercrime forums). Corpse was not a small player. Between roughly 2003 and 2006, he built and sold one of the most advanced banking trojans of its era: A311 Death, better known as Haxdoor and sometimes Nuclear Grabber. A trojan is malware that hides inside or disguises itself as ordinary software. Haxdoor was years ahead of its time and was used in multiple million-dollar cyberheists before that kind of attack was daily news.

VIP72 was, in effect, the second act. The same malware operation that infected computers to steal from them could also rent those infected computers out as proxies. One crime funded the infrastructure for the next. That is the detail that makes VIP72 worth remembering: the proxy service and the malware were the same business.

How it worked: your PC as someone else's SOCKS proxy

The mechanic is simple and ugly. A computer gets infected, whether by Haxdoor or by whatever malware was bundling the VIP72 client later on. Once infected, that machine quietly starts accepting and forwarding other people's traffic. It is now a SOCKS exit node. VIP72 lists it in its storefront, a paying customer rents it, and every request that customer sends now comes out of a stranger's home internet connection.

This is exactly the appeal of a residential proxy to a buyer, and exactly the problem. The traffic looks human because it is literally coming out of a human's computer. When that human never consented, the "proxy" is stolen access, and everything routed through it is riding on a crime.

The slow fade and the day it went dark

For most of its life, VIP72 was big. Krebs reported that at its peak the service had several hundred thousand compromised systems available for rent at any given time, with its infrastructure sitting at the same United States internet address for over a decade. That longevity was part of the brand. In a scene where services appear and vanish constantly, VIP72 felt permanent.

By the end, it was not. When the storefront disappeared in mid-August 2021, the pool had shrunk to fewer than 25,000 systems worldwide.

Here is the arc in one view, from the malware that started it to the day the lights went out.

VIP72: a 15-year arc
2003 to 2006
"Corpse" builds and sells the A311 Death banking trojan, better known as Haxdoor, used in multiple million-dollar cyberheists.
2006
vip72.com is registered. The anonymity service launches as a side business off the same malware operation.
2010s
Peak years. Several hundred thousand infected systems are available for rent at any one time, hosted at a steady US address for over a decade.
Aug 2021
The storefront vanishes without notice. The pool has already fallen to fewer than 25,000 systems worldwide.
Sep 1 2021
Krebs reports VIP72 dark. It never comes back.

Why it died, and why that matters to a buyer

Nobody outside the operation ever confirmed why VIP72 went dark. Krebs laid out the two most likely explanations, and both are instructive. The domain may have been quietly seized in a law enforcement operation. Or the operator may simply have walked away, because VIP72 was losing ground to a newer generation of criminal proxy services and to the rise of so-called "bulletproof" residential proxy networks. A shrinking pool of fewer than 25,000 machines, down from hundreds of thousands, points at a service that was dying on its own before it disappeared.

For a buyer, the reason barely matters. What matters is the shape of the risk. When you route a request through a proxy, you inherit that exit node's reputation. A pool built from malware-infected machines is used for fraud and account takeover around the clock, so to any fraud-detection system your traffic looks exactly like the crime it shares those IPs with. A botnet-sourced pool is burned before you send a single request, which is why how websites detect proxies starts with IP reputation, not with clever headers.

"Anonymity service" and "residential proxy" were the same trick

The uncomfortable part of the VIP72 story is that its product was, technically, a residential proxy. The IPs really were residential. The traffic really did come from real consumer connections. Everything a legitimate provider advertises today, VIP72 could have claimed truthfully. The only difference, the one that mattered, is that its residential IPs belonged to people who had been hacked.

That is the same lesson we drew from the 911 S5 botnet, which infected millions of machines through fake free VPN apps, and from the NetNut botnet takedown, where a botnet allegedly ran on more than two million smart TVs. Different decade, different malware, identical shape: someone else's device, rented out as your "residential" IP, without consent. The technology is neutral every time. The supply chain is where the crime lives.

Where an honest network fits

You cannot audit a provider's whole supply chain from the outside, but you can ask the questions a shady one does not want to answer, and you can check what you are handed. The long version of this list is our how to vet a proxy provider guide:

  • Ask how the pool is sourced. A provider using disclosed, consented opt-in can say so plainly. Vagueness is the answer.
  • Distrust "anonymity" and "free VPN" as sources. That framing is the VIP72 and 911 model by definition.
  • Check the network behind an IP before trusting it. Our free proxy checker makes a real connection through a proxy and reports its exit location, anonymity grade, and the network the IP actually belongs to.
  • Know who stands behind the brand. Ownership does not guarantee clean sourcing, but a name you can trace is a start. We mapped the industry's real corporate structure in who owns your proxy provider.

VIP72 is proof that a proxy service can look established, run for 15 years, and still be a botnet the entire time. The label never changed. The sourcing was rotten from the first infected PC in 2006 to the last one in 2021.

If you just need to test tooling or run something low-stakes, our free proxy list is honest about being mostly short-lived datacenter IPs, re-checked every few minutes. When you need residential IPs that hold up, we sell them at $0.65/GB pay as you go with no KYC and a balance that never expires, and the whole point of this article is the thing we would rather compete on: being able to tell you where they come from.

Sources

  • Krebs on Security, "15-Year-Old Malware Proxy Network VIP72 Goes Dark" (September 1, 2021): the "Corpse"/Haxdoor attribution, the 2006 domain registration, the peak and shutdown pool figures, and the reasons it went dark.
  • Krebs on Security, VIP72 tag archive: ongoing coverage of the service and its place in the malware-proxy ecosystem.
  • HProxy internal competitor research (2026): the subscription price point (roughly $10/month for around 90 proxies) and the vip72.org secondary-domain flag.

Frequently asked questions

What was VIP72?
VIP72 was a cybercrime anonymity service that sold access to hacked home and office computers, offered to buyers as SOCKS proxies. For roughly 15 years it let fraudsters hide their real location by routing traffic through malware-infected machines belonging to ordinary people. Its online storefront (vip72.com) vanished without notice in August 2021.
Who ran VIP72?
Security journalist Brian Krebs traced VIP72 to a Russian-speaking hacker who used the handle 'Corpse' (also 'Revive' on underground forums). The same person built and sold the A311 Death banking trojan, better known as Haxdoor, between roughly 2003 and 2006. VIP72's domain was registered in 2006, and the proxy service grew out of that malware operation.
How did VIP72 get its proxies?
By infecting people's computers. VIP72 routed customer traffic through machines seeded with malware, starting with the operator's own Haxdoor trojan. Each infected PC quietly became a SOCKS exit node that strangers paid to route traffic through, all under the victim's home IP address. The device owners never agreed to any of it.
When and why did VIP72 shut down?
Its storefront disappeared in mid-August 2021, about two weeks before Krebs reported it dark on September 1, 2021. The exact cause was never confirmed. It may have been a law enforcement seizure, or the operator may have walked away, since the service had trouble competing with newer criminal proxy services and its pool had dwindled from several hundred thousand infected systems to fewer than 25,000.
Is VIP72 still around, and are vip72.com or vip72.org safe?
The original service is dead. The vip72.com domain still exists on a registrar, and a secondary vip72.org has been flagged as a legal-risk domain, but the network people remember is gone. Any site trading on the VIP72 name today is trading on a dead brand built on hijacked machines, not a service you want to touch.
How do I avoid buying proxies sourced like VIP72?
Ask any provider how its pool is sourced and treat vague answers as the answer. Avoid anything marketed as 'anonymity' from hacked or malware-infected machines, since that is the VIP72 model by definition. And verify any IP you are handed with a proxy checker to see the real network behind it before you trust it.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires.

47M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup