Russian Researchers Uncover a 14,000-Node Botnet That Has Operated Since 2011
Researchers at Solar 4RAYS have identified ProxyCB, a large-scale cyberattack platform that has been operating largely unnoticed since 2011. The botnet's infrastructure now spans about 14,000 Russian IP addresses.

The botnet came to light in 2025 during an investigation into a cybersecurity incident affecting a major client. Analysts noticed that requests followed the same patterns while originating from constantly changing sources, and the bots increasingly mimicked the behavior of real users. Further analysis showed that ProxyCB is a full-fledged ecosystem with its own control panel, dedicated data transmission channels, and server-side core. Over the years, access to the platform has reportedly been sold on dark web marketplaces for password-cracking campaigns, data theft, artificial traffic generation, and spam distribution. Researchers also found links to TeamSpy, a hacking group known for covert attacks carried out through the legitimate remote-access software TeamViewer.
The researchers recommend that organizations closely monitor incoming traffic characteristics and deploy modern bot-mitigation technologies to detect and block similar threats.








































