Executive Summary
In August 2025, longstanding residential proxy provider DSLRoot was exposed for recruiting US residents to host dedicated proxy devices on their home Internet lines, including high-risk individuals such as a U.S. Air National Guard member with top-secret clearance. The company, with origins and affiliations in Russia and Eastern Europe, leverages consent-based proxy networks—sometimes referred to as 'legal botnets'—enabling anonymized traffic redirection and potential abuse by third parties. DSLRoot's proxies are promoted on underground forums and have leveraged adware pay-per-install schemes, bypassing traditional ISP terms and offering services worldwide. The incident raised concerns about unmanaged East-West network traffic, lack of egress controls, and gaps in threat detection on residential endpoints, highlighting the ease with which attackers or unauthorized users can exploit commoditized infrastructure for fraud, anonymity, or more severe criminal purposes.
This case underscores the growing risks of proxy network abuse, which threatens both enterprise and government environments by eroding identity controls and facilitating untraceable activity. The increasing prevalence of 'legal botnets' fueled by incentives and lax regulation makes this a high-priority issue for organizations seeking to enforce policy, maintain compliance, and detect anomalous traffic patterns across diverse environments.
Why This Matters Now
Residential proxy networks like DSLRoot blur the lines between legitimate and malicious infrastructure, creating opportunities for fraudsters and advanced threat actors alike. As remote work expands and more employees possess sensitive network access, unmanaged devices or side-loaded hardware present significant threats to data security, compliance, and incident response. Organizations must urgently address proxy abuse and lateral movement risk.
Attack Path Analysis
The attacker gained initial access by convincing hosts to physically connect proxy devices or install proxy software, often leveraging social engineering and possibly exploiting default device credentials. Once foothold was established, escalation may occur via deploying custom proxy software with elevated privileges on the host systems. Attackers could then map and exploit the local LAN or nearby WiFi to move laterally and expand proxy presence to additional networks. The proxy infrastructure established persistent command and control channels to external proxy management domains using encrypted or covert communications. Exfiltration occurred as attacker-provisioned client traffic was tunneled through compromised residential endpoints, facilitating masking of malicious or fraudulent internet activity. The final impact was the facilitation of abuse (spam, fraud, banned content, anonymity) through the proxy network, undermining trust in residential IP spaces and enabling threats to target victims or organizations under the guise of legitimate users.
Kill Chain Progression
Initial Compromise
Description
Attackers used social engineering to convince individuals to install hardware or software, or they exploited default credentials and pre-configured equipment to establish a physical or virtual network presence.
Related CVEs
CVE-2019-16920
CVSS 9.8A remote code execution vulnerability in D-Link routers allows unauthenticated attackers to execute arbitrary code via crafted HTTP requests.
Affected Products:
D-Link DIR-655 – 1.37
D-Link DIR-866L – 1.03
D-Link DIR-652 – 1.03
D-Link DIR-655 – 1.37
Exploit Status:
exploited in the wildCVE-2018-13379
CVSS 9.8An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Fortinet FortiOS SSL VPN web portal may allow an unauthenticated attacker to download system files via specially crafted HTTP resource requests.
Affected Products:
Fortinet FortiOS – 5.6.3 to 5.6.7, 6.0.0 to 6.0.4
Exploit Status:
exploited in the wildCVE-2019-19781
CVSS 9.8A directory traversal vulnerability in Citrix Application Delivery Controller (ADC) and Gateway allows unauthenticated attackers to perform arbitrary code execution.
Affected Products:
Citrix Application Delivery Controller – 10.5, 11.1, 12.0, 12.1, 13.0
Citrix Gateway – 10.5, 11.1, 12.0, 12.1, 13.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
User Execution: Malicious File
Valid Accounts: Local Accounts
Proxy: External Proxy
Create Account: Local Account
Process Injection
Remote Access Software
Masquerading
Network Service Scanning
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Configuration of System Components
Control ID: 2.2.5
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 9(2)
CISA ZTMM 2.0 – Continuous Device Discovery
Control ID: Asset Management: Device Discovery and Inventory
NIS2 Directive – Risk Analysis and Information System Security Policies
Control ID: Article 21(2)(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Military personnel with top-secret clearance compromised by proxy networks threatens national security through unauthorized network access and potential foreign intelligence operations.
Defense/Space
Air National Guard cybersecurity breach via residential proxy services exposes defense infrastructure to foreign adversaries and compromises classified communication channels.
Telecommunications
DSL and broadband infrastructure exploitation enables large-scale proxy networks, undermining network integrity and facilitating unauthorized traffic routing for malicious purposes.
Financial Services
Residential proxy networks facilitate financial fraud through anonymous payment systems and virtual credit cards, enabling money laundering and bypassing banking regulations.
Sources
- DSLRoot, Proxies, and the Threat of ‘Legal Botnets’https://krebsonsecurity.com/2025/08/dslroot-proxies-and-the-threat-of-legal-botnets/Verified
- Infrawatch Uncovers Belarusian-Run Residential Proxy Network Inside U.S. Homeshttps://securityonline.info/infrawatch-uncovers-belarusian-run-residential-proxy-network-inside-u-s-homes/Verified
- Belarus-Linked DSLRoot Proxy Network Deploys Hardware in U.S. Residences, Including Military Homeshttps://blog.netmanageit.com/belarus-linked-dslroot-proxy-network-deploys-hardware-in-u-s-residences-including-military-homes/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
CNSF controls—especially Zero Trust Segmentation, East-West Traffic Security, Egress Policy Enforcement, Threat Detection, and Multicloud Visibility—could have disrupted proxy onboarding, restricted lateral movement, blocked unauthorized command channels, detected anomalies, and prevented residential IP abuse, thereby constraining the operation of 'legal botnets'.
Control: Zero Trust Segmentation
Mitigation: Restricted onboarding of untrusted hardware or unauthorized network connections.
Control: Threat Detection & Anomaly Response
Mitigation: Detection of abnormal privilege elevation or unauthorized service installation.
Control: East-West Traffic Security
Mitigation: Prevented illicit scanning and device-to-device communication.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked unapproved outbound communication and custom C2 channels.
Control: Cloud Firewall (ACF)
Mitigation: Detected and blocked high-risk or abnormal outbound traffic patterns.
Real-time identification and quarantine of abused network paths.
Impact at a Glance
Affected Business Functions
- Network Security
- Data Privacy
- Regulatory Compliance
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive personal and organizational data due to unauthorized access through compromised residential proxy networks.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation and microsegmentation to strictly separate trusted workloads and block unauthorized third-party hardware or software deployment.
- • Implement strict egress filtering and Cloud Firewall controls to prevent outbound connections to known proxy management domains and suspicious destinations.
- • Continuously monitor internal east-west traffic with anomaly detection to spot enumeration, unauthorized scanning, or lateral movement attempts.
- • Enable Threat Detection & Anomaly Response capabilities to quickly identify unusual process execution, service installations, or encrypted C2 channels.
- • Maintain centralized visibility and policy enforcement across hybrid and cloud environments to rapidly detect, investigate, and quarantine endpoints or segments showing signs of proxy misuse or compromise.



