Residential Proxy SDKs Are Quietly Draining Ad Budgets

Article Objective:
Help marketers understand how residential proxy SDKs supply bot traffic from real consumer IPs, how it inflates clicks, leads and geo-targeted spend, and how to detect and block it.
Estimated Read Time:

A growing share of the bot traffic hitting marketing sites no longer comes from data centers. It arrives through phones, smart TVs and home PCs whose owners installed an app that quietly bundled a residential proxy SDK. This article explains how that supply chain works, what recent investigations have uncovered, and what it means for your clicks, leads and attribution data.

What a residential proxy SDK is and why app developers embed it

A residential proxy network sells access to IP addresses that belong to ordinary households. A customer sends a request to the proxy provider, and the provider routes it out through someone's home connection, so the destination website sees a consumer ISP address instead of a cloud server.

Those home connections have to come from somewhere. Increasingly, they come from a software development kit (SDK) that app developers add to their own products. The pitch to developers is simple: embed our library, and we pay you. In exchange, every device that installs the app can become an "exit node" that relays other people's traffic.

Investigators have documented this model across many types of software:

  • Mobile apps and games, especially free ones looking for revenue beyond ads.
  • Free VPN apps, where relaying traffic can look like a normal part of what the app does.
  • Desktop software for Windows and other platforms.
  • Android TV boxes and other connected devices, sometimes with proxy code installed before they ever reach the buyer.

Some SDK programs show users a consent prompt. Many implementations reviewed by researchers either did not, or did so in language most people would not understand. That gap is the heart of the problem.

What investigators have found

This is not a new idea, but the evidence has piled up quickly. Here are the findings that matter most for marketers.

Academic research: millions of IPs and unclear consent

In one of the first large studies, researchers presenting at IEEE Security & Privacy 2019 identified about 6 million residential proxy IPs across more than 230 countries and 52,000 ISPs. Despite providers' claims that hosts join willingly, the authors found that many proxies ran on likely compromised hosts, including Internet of Things (IoT) devices.

A follow-up study at NDSS 2021, "Your Phone is My Proxy: Detecting and Understanding Mobile Proxy Networks", looked specifically at mobile SDKs. The researchers found 1,701 Android APKs, belonging to 963 apps, that integrated proxy SDKs, with at least 300 million installations in total. When study participants were shown the apps' actual consent dialogs, 72% rated them "Not at all clear" about turning the phone into a web proxy. Most relevant to advertisers: the researchers reported that suspected advertising fraud was the largest category of traffic they saw relayed through these devices.

HUMAN Security: PROXYLIB and BADBOX 2.0

In March 2024, HUMAN's Satori team described PROXYLIB and the LumiApps SDK, which turned phones running 28 free VPN apps into proxy nodes. LumiApps marketed itself as an alternative to showing ads and paid developers based on how much traffic flowed through users' devices. Although its documentation included a sample disclosure dialog, HUMAN did not find that dialog in any of the apps in the wild. Google removed all 28 apps from Google Play.

A year later, HUMAN reported on BADBOX 2.0, a backdoor on more than 1 million off-brand Android devices. The same operation ran residential proxy services alongside programmatic ad fraud and click fraud; at its peak, the hidden-ads scheme alone generated 5 billion fraudulent bid requests a week. In June 2025, the FBI issued a public service announcement on BADBOX 2.0 warning that compromised streaming devices, projectors and picture frames were being folded into residential proxy services used for malicious activity.

Google's disruption of IPIDEA

The clearest picture of the SDK economy came in January 2026, when Google Threat Intelligence Group published its account of disrupting IPIDEA, which it described as one of the largest residential proxy networks. Key details:

  • IPIDEA offered SDKs to developers across mobile and desktop platforms and paid them, usually per download, once the SDK was embedded.
  • Google identified more than 600 apps and 3,075 unique Windows executables carrying the code, plus free VPN apps that provided real VPN service while also enrolling devices as exit nodes.
  • Enrollment happened without clear disclosure to users and was not the app's primary function.
  • In a single seven-day period, Google observed more than 550 threat groups using IPIDEA exit nodes.

Google said its actions, including Google Play Protect warning users about and removing apps with the code, cut the operators' device pool by millions. Around the same time, Krebs on Security traced how the Kimwolf botnet abused proxy software on Android TV boxes, with researchers noting that such proxy IPs start funneling traffic linked to ad fraud, account takeover attempts and mass scraping.

Why residential proxies break IP-based bot blocking

Most basic traffic filters rely on IP reputation. They block known data center ranges, hosting providers and addresses on abuse lists. That works against cheap bots running on cloud servers. It fails against residential proxies for three reasons:

  1. The IP belongs to a real household. It sits in a consumer ISP's address space, often shared by legitimate users behind the same connection. Blocking it outright risks blocking real customers.
  2. The IPs rotate constantly. Pools run into the millions, so a single address may carry fraudulent traffic for minutes and then move on before any blocklist catches up.
  3. Location can be chosen. Trend Micro's research on residential proxies as a cybercrime enabler notes that attackers can pick home IPs "within a vicinity that is plausible for benign traffic," and lists ad fraud and click fraud among the main use cases.

This matters because automated traffic is already the majority of the web. The 2025 Imperva Bad Bot Report found that bots made up 51% of all web traffic in 2024, and malicious bots 37%. The more sophisticated share of that traffic is exactly what residential proxies are built to disguise. For a broader view of the threat landscape, see our overview of 2026 bot threats to the marketing stack.

What residential proxy traffic does to your marketing budget

For paid media and marketing ops teams, residential proxy traffic shows up in the numbers you report on every week.

Inflated clicks and impressions

Bots routed through home IPs can click search and social ads, load display impressions and trigger video views. Because the traffic looks like it comes from consumers, it is less likely to be filtered as invalid traffic (IVT) before you are billed. Our guide on how ad fraud works covers the economics in more detail.

Geo-targeting fraud

If you only pay for clicks in Chicago or leads in Germany, a proxy customer can simply rent exit nodes in Chicago or Germany. Geo-targeting settings and location reports then confirm the traffic is "local," even when the operator is on another continent. Location stops being a useful fraud signal on its own.

Fake leads that look real

Form-filling bots on residential IPs submit leads with plausible names, local area codes and ISP-matched locations. Those leads flow into your CRM, consume sales time, and can be counted as conversions that tell ad platforms to find more of the same.

Polluted attribution and bidding signals

Once fake sessions carry UTM parameters and conversion events, they skew channel performance. A campaign can look efficient because bots are completing cheap conversions, and automated bidding will shift budget toward it. Clean marketing attribution depends on knowing which sessions were human in the first place.

How to detect residential proxy traffic

No single signal identifies a residential proxy. Detection works best when several independent signals are combined:

  • Behavioral signals. Mouse movement, scroll depth, time between events, and form-completion speed often differ between scripts and people, regardless of IP.
  • IP-to-device consistency. Check whether the time zone, language settings, device type and browser fingerprint fit the IP's claimed location and connection type. A desktop browser set to one country, arriving from a mobile carrier IP in another, deserves a closer look.
  • Session and network patterns. Watch for many sessions from rotating IPs that share the same fingerprint, or IPs that appear briefly across unrelated sites and disappear.
  • Residential proxy classification. Dedicated intelligence can flag IPs recently observed acting as proxy exit nodes, even when they sit on consumer ISPs.
  • Downstream quality. Compare lead-to-opportunity rates, bounce rates and on-site engagement by campaign, placement and region. Sudden local "wins" with no pipeline behind them are a warning sign.

Also expect more automation that is not malicious. AI assistants and agents browse on behalf of real people, and some use proxies too. We explain how to tell them apart in agentic AI traffic: the good and the bad.

A checklist to protect your ad spend

  1. Stop treating IP reputation as sufficient. Keep data center blocking, but add behavioral and device-consistency checks on top.
  2. Segment reports by traffic quality, not just channel. Review conversion rates for flagged versus clean sessions per campaign.
  3. Audit geo-targeted campaigns. Compare lead quality by region with what sales actually closes. Tighten or pause regions that produce volume without revenue.
  4. Protect forms. Add server-side validation, rate limits and bot checks on lead forms, and stop sending unverified leads back to ad platforms as conversions.
  5. Keep evidence for refunds. Export visitor-level logs of suspicious clicks so you can support invalid-click claims with ad platforms.
  6. Review publisher and placement lists. Exclude apps, sites and placements that repeatedly send proxy-heavy traffic.

The bottom line, and how Ðeny helps

Ðeny classifies marketing site traffic in real time. Its Intelligence Hub sorts visits into Clean, Good Bot, Residential Proxy, IVT, Out-of-Geo and AI Agent categories, and rolls them into a Traffic Health Score from A to F with AI summaries. UTM Breakdown shows which channels are sending proxy traffic, and Ðeny Bot Shield can block it before it counts against your budget. Enterprise Data provides the visitor-level logs and exports you need for audits and refund requests. Deployment is a one-line script. See the full Ðeny feature overview.

Residential proxy SDKs have turned millions of consumer devices into cover for automated traffic, often with little meaningful consent from the people who own them. For marketers, that means "real" consumer IPs are no longer proof of real consumers. Teams that combine behavioral, device and proxy signals will keep their budgets and their data clean. To see how much of your own traffic comes through residential proxies, request a Ðeny demo.

Receive better insights, in your inbox
Subscribe to Deny's insights & news.
Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Start protecting your funnel today

Put Ðeny to work from day one, and your boss will thank you.

$79/month
Cancel anytime
Credit card required
Get Started