Gen reports 20.8 million blocked attacks associated with residential proxy networks

· Original article ↗

Summary

Gen telemetry recorded 20.8 million blocked attacks associated with residential proxy networks from January to mid-September 2026, led by phishing. The study also found concentrated provider footprints, varied threat profiles and limited consumer understanding.

Key points

  • Gen blocked 20.8 million distinct attacks associated with the studied networks; phishing led with 5.15 million observations, followed by 1.26 million involving malvertising. Threat categories can overlap.
  • Telemetry identified software linked to 18 providers on active Windows systems; Bright Data, Hola and NetNut made up about 94% of the observed provider footprint. The data is not a census of all residential proxy endpoints.
  • Threat profiles varied by provider: some were more associated with phishing and malvertising, while others showed more droppers, file infectors, worms or trojans.
  • Attack geography did not match installation geography: India had the most blocked attacks, while the United States ranked tenth for observed installations but fourth for blocked attacks.
  • After the FBI seized domains associated with NetNut and Alarum announced a temporary service pause, Gen still observed NetNut-associated software on about 474,000 active Windows systems in September, but no corresponding proxy traffic.
  • In a survey of 1,000 US adults, only 8.8% correctly identified how residential proxies work; 17.2% said they currently use an app that rewards bandwidth sharing, and 76.5% said they would be concerned about third parties routing traffic through their home connection.
  • The findings show malicious activity using residential proxy infrastructure, but do not establish that providers generated or knowingly enabled it. The study covers Gen-protected Windows systems and US survey respondents, not the entire ecosystem or global population.

Article Details

Publisher
Gen Digital
Report Period
Installation telemetry: 2026-09-01 to 2026-09-15; blocked attacks: January to mid-September 2026; US survey: July 2026.
Scope
Gen-protected Windows systems with identifiable residential proxy software, blocked attacks associated with studied provider ecosystems, and a survey of US adults. Installation figures do not cover all residential proxy endpoints.
Sample Size
1,000 US adults surveyed; installation sample size not disclosed.
Key Statistics
  • Gen blocked 20.8 million distinct attacks associated with residential proxy provider ecosystems between January and mid-September 2026.
  • Bright Data, Hola and NetNut accounted for approximately 94% of the active provider footprint observed in Gen's September Windows telemetry.
  • Phishing accounted for more than 5.15 million provider-category attack observations. Threat classifications overlap and cannot be added to obtain a total.
  • Only 8.8% of surveyed US adults both claimed some understanding of residential proxies and selected the correct definition.
  • After the behavior was explained, 76.5% of surveyed US adults said they would be very or somewhat concerned about third parties routing traffic through their home connection.
Recommendations
  • Customers buying residential access should examine how endpoints were sourced and what network controls are in place.
  • Providers should demonstrate how endpoints are sourced, what users agreed to, how abuse is detected, and what happens when controls fail.
  • Explain bandwidth-sharing requests to consumers in language that makes clear that third-party traffic can use their home IP address.
  • Make provider claims about consent, customer vetting and abuse prevention independently testable.

Vendors

Bright DataThe residential proxy footprint we observe is highly concentrated. Bright Data, Hola and NetNut account for around 94% of the active provider footprint in our Windows telemetry, although their geographic distributionsByteLixirGenthe paying proxy customer is not the same person as the consumer whose device or connection is being used. Gen participated in the working group that produced the draft.HolaThe residential proxy footprint we observe is highly concentrated. Bright Data, Hola and NetNut account for around 94% of the active provider footprint in our Windows telemetry, although their geographic distributionsHoneygainapproximately 664,000, and NetNut with around 474,000. After those three, the numbers fall quickly: Honeygain was at about 68,000 active users and Infatica at roughly 56,000, while no other provider in our currentInfatica474,000. After those three, the numbers fall quickly: Honeygain was at about 68,000 active users and Infatica at roughly 56,000, while no other provider in our current dataset reached 11,000.IPRoyalLGThat wider ecosystem is not theoretical. In 2026, researchers at Spur examined more than 6,000 apps for LG webOS and Samsung Tizen smart TVs and found residential proxy SDKs in roughly a third of them. LG and SamsungMicroleaves / ShifterNetNutThe residential proxy footprint we observe is highly concentrated. Bright Data, Hola and NetNut account for around 94% of the active provider footprint in our Windows telemetry, although their geographic distributionsPacketStreamSamsungis not theoretical. In 2026, researchers at Spur examined more than 6,000 apps for LG webOS and Samsung Tizen smart TVs and found residential proxy SDKs in roughly a third of them. LG and Samsung subsequentlySOAXTraffMonetizerTuxlerattacks affecting 51,271 users. NetNut was associated with 789,668 attacks affecting 663,426 users, Tuxler with 571,810 attacks across 19,184 users, and Hola with 406,415 across 170,577 users.VerizonSome residential ISP agreements, for example, explicitly restrict this kind of sharing. Verizon's current Fios terms state that subscribers may not resell, re-provision or rent the service, or allow third parties

Products

Countries

ArgentinaBelgiumBrazilapproximately 294,000 active user observations. Vietnam followed at around 177,000, Ukraine at 132,000, Brazil at 131,000 and the Philippines at 97,000. The United States ranked tenth, at approximately 56,000.Dominican RepublicFranceBrazil followed at roughly 1.50 million, Vietnam at 1.32 million, the United States at 1.14 million and France at just under 990,000. The next group included the Philippines, Indonesia, Poland, Spain and Ukraine.IndiaThe geography is just as interesting. India had the largest combined residential proxy footprint in our snapshot, with approximately 294,000 active user observations. Vietnam followed at around 177,000, Ukraine atIndonesiaStates at 1.14 million and France at just under 990,000. The next group included the Philippines, Indonesia, Poland, Spain and Ukraine.KazakhstanMexicoNetherlandsPhilippinesuser observations. Vietnam followed at around 177,000, Ukraine at 132,000, Brazil at 131,000 and the Philippines at 97,000. The United States ranked tenth, at approximately 56,000.Polandat 1.14 million and France at just under 990,000. The next group included the Philippines, Indonesia, Poland, Spain and Ukraine.South KoreaSpainmillion and France at just under 990,000. The next group included the Philippines, Indonesia, Poland, Spain and Ukraine.ThailandUkraineour snapshot, with approximately 294,000 active user observations. Vietnam followed at around 177,000, Ukraine at 132,000, Brazil at 131,000 and the Philippines at 97,000. The United States ranked tenth, atUnited KingdomUnited Statesof malicious activity does not simply mirror the geography of residential proxy installations. The United States ranked only 10th in our September snapshot of active residential proxy software, with around 56,000UzbekistanVietnamresidential proxy footprint in our snapshot, with approximately 294,000 active user observations. Vietnam followed at around 177,000, Ukraine at 132,000, Brazil at 131,000 and the Philippines at 97,000. The

Related Articles