Botnet
A network of compromised devices controlled without their owners' knowledge, the criminal end of where proxy and residential supply can come from.
A botnet is a collection of devices, computers, phones, routers, cameras, anything connected, that have been compromised and are controlled remotely by an operator the owners know nothing about. The word belongs in a proxy glossary for an uncomfortable reason: a botnet and an ethically sourced residential proxy pool are, at the network level, nearly the same thing. Both are large populations of consumer devices routing someone else's traffic. The difference is consent, and it is the whole difference.
That overlap is the sharp edge of the supply-provenance question raised under bandwidth sharing and peer-to-peer proxies. Residential exits have to come from real devices, and the honest sources enrol participants who agreed and are paid. The dishonest end of the market sources the same capability from compromised devices instead, where the person whose connection carries your traffic never agreed to anything. Buying from there is not a technicality; it is renting access to crime, with the legal exposure that implies.
From the detection side, which is why the term sits in this category, botnets are also a thing defences hunt. Coordinated traffic from many consumer addresses is the signature of both a residential proxy pool and an attack, so anti-bot and fraud systems treat sudden correlated behaviour across residential IPs with suspicion, and reputation systems flag addresses observed participating in botnet activity. An address that was part of a botnet carries that history regardless of who is using it now.
For a buyer the practical takeaway is that provenance is the one property you cannot see in a test and cannot afford to ignore. A pool sourced from a botnet performs identically to a clean one right up until it does not, legally and reputationally. The defence is the diligence covered elsewhere: ask how participants were enrolled, what they were told and how they are paid, and treat a provider who cannot or will not answer as telling you where their addresses came from.
Frequently asked questions
Are residential proxies botnets?
Ethically sourced ones are not, but at the network level the two are nearly identical: large populations of consumer devices routing others' traffic. The difference is entirely consent. Honest pools enrol participants who agreed and are paid; a botnet uses compromised devices whose owners never agreed. Which one a pool is built on is the most important and least visible fact about it.
How do I avoid buying botnet-sourced proxies?
You cannot detect it in a speed test, so you have to interrogate provenance. Ask how participants enter the pool, what they were shown at enrolment, and how they are compensated. Consented supply has clear answers; botnet-sourced supply does not. A provider who is vague on all of it is answering the question by refusing to, and buying anyway means renting access to compromised devices.
Why do anti-bot systems associate residential IPs with botnets?
Because coordinated traffic from many consumer addresses is the shared signature of a residential proxy pool and a botnet attack. Defences cannot always tell them apart, so they treat sudden correlated behaviour across residential IPs warily, and reputation systems flag addresses seen in botnet activity. An address carries that history forward regardless of who is using it now.
Back to the full glossary.