/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US and global partners dismantle the 911 S5 proxy botnet, “likely the world's largest botnet ever”, linked to 19M+ IPs, and arrest its alleged administrator

US government seizes 911 S5 operation and takes it offline Associated Press : International Authorities Arrest Man Allegedly Behind 'Likely the World's Largest Botnet Ever' Xinghui Kok / Reuters : US DOJ says Chinese national arrested on malware charges in international operation Sujita Sinha / Interesting Engineering : 'World's largest botnet': US nabs Chinese man who hacked 19 million PCs Eduard Kovacs / SecurityWeek : Massive 911 S5 Botnet Dismantled, Chinese Mastermind Arrested James Coker / Infosecurity : US-Led Operation Takes Down World's Largest Botnet Proactive : US dismantles 'world's largest botnet ever' that infected 19mln IP addresses Paul Hill / Neowin : US Department of Justice smashes 911 S5 botnet run by Chinese national Duncan Riley / SiliconANGLE : Department of Justice claims to have taken down a large botnet with 19M unique IP address The Hacker News : U.S. Dismantles World's Largest 911 S5 Botnet, with 19 Million Infected Devices Michael Kan / PCMag : US Arrests Chinese Citizen Behind Malicious VPNs That Infected Millions Sergiu Gatlan / BleepingComputer : The US Treasury sanctions three Chinese nationals and three Thailand-based companies linked to a botnet controlling residential proxy service “911 S5” Mastodon: BrianKrebs / @briankrebs@infosec.exchange : Cloudrouter homepage now features seizure notice from DOJ  —  [image] BrianKrebs / @briankrebs@infosec.exchange : The DOJ just announced they indicted and arrested Wang, the alleged owner of the 911 S5 botnet (aka 911[.]re).  —  https://www.justice.gov/...  “Since 2014, 911 S5 allegedly enabled cybercriminals to bypass financial fraud detection systems and steal billions of dollars from financial institutions, credit card issuers, and federal lending programs. … X: @gi7w0rm : One of the biggest residential proxy botnets, which infected over 19 Mio unique IPs, has been seized by Law Enforcement. The main admin was arrested and the service taken down. This was probably one of the top 3 global proxy nets for comiting crimes of all sorts. Huge win 👌🥳 @bocbotch : @FBI Nice excuse for insider fraud? Pavel Kravchenko / @d4rkr4bb1t47 : @TheJusticeDept Oh good, I'm still waiting for those child abuse websites in Miami, LV and New York to be dealt with. Lynda Edwards / @lynda555e : There are times the wheels of justice turn too slowly but busting this network of China's is impressive. It was involved in crimes from child exploitation to unemployment fraud Andrew Thompson / @imposecost : 911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation A court-authorized international law enforcement operation led by the U.S. Justice Department disrupted a botnet used to commit cyber attacks, large-scale fraud, child exploitation, @fbi : Today, the DOJ announced the arrest of a Chinese national who amassed millions of hijacked residential IP addresses and facilitated billions of dollars in unemployment and pandemic relief fraud. Learn about the investigation by the #FBI and its partners: https://www.justice.gov/... @statecdp : The United States is designating three PRC nationals for activities associated with a malicious botnet known as 911 S5, which resulted in widespread cyber-enabled fraud and billions of dollars lost. Learn more: https://home.treasury.gov/... Arieh Kovler / @ariehkovler : Quite the scalp for @briankrebs who exposed Yunhe Wang as one of the creators of this network back in 2022. Matthew Miller / @statedeptspox : The United States is sanctioning three PRC nationals associated with malicious cyber activity and three entities owned or controlled by one of them. We will continue to act against cybercriminals who seek to exploit our financial system. Arieh Kovler / @ariehkovler : Quite the scalp for @briankrebs who exposed Yunhe Wang as one of the creators of this network back in 2022. @frauhodl : I wonder why they called it “911 S5”-Botnet? - IXXI = 911 = Jesuits - YunHe Wang @xhacknews : 📡 #Botnet The 911 S5 botnet, which hijacked over 19 million IP addresses, has been dismantled in an international operation, and its administrator arrested. This was one of the top three proxy networks used globally for criminal activities. A major victory! #CyberSecurity @chainalysis : Today, the DOJ announced the arrest of Yunhe Wang for his role as administrator of the 911 S5 botnet, one day after Wang was sanctioned by OFAC. Learn how investigators equipped with Chainalysis used cutting edge blockchain analysis techniques to analyze Wang's activities here. Michael Ron Bowling / @mrbcyber : Largest botnet ever taken down by FBI. The network was used for fraud, stalking, bomb threats and child exploitation. Note, this system would have been very useful for CCP foreign interference operations. @fbidenver : #FBIDenver worked this case with @FBIDallas and many other partners, as listed in the DOJ news release https://twitter.com/... @7trg6 : Let This Sink In - 911 S5 Botnet: Cyber Attacks, Fraud, Child Exploitation, Harassment, ID Theft 200 countries- 19 million IP addresses “...provided paying customers with access to proxied IP addresses associated with the infected devices” Ex: $5.9 billion unemployment (US) @fbilasvegas : Protect against 911s5, a residential proxy service which compromised over 19 million IP addresses globally and caused billions of dollars in losses. Learn how the #FBI and partners disrupted the botnet to remove 911s5's applications from your devices #PSA https://www.ic3.gov/... [image] Hoa Paul Duong / @econmccausland : @StateDeptSpox Simple question. So is your job to lie blatantly to the international press and the American people? Tav / @tayesuave : @TheJusticeDept A Chinese national used Botnets and siphoned billions of dollars through multiple IP addresses. I wonder who all is connected with these crimes, its simply not a one-man operation. @thejusticedept : 911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation Botnet Infected Over 19M IP Addresses to Enable Billions of Dollars in Pandemic and Unemployment Fraud, and Access to Child Exploitation Materials 🔗: https://www.justice.gov/... [video] @780thc : Treasury Sanctions a Cybercrime Network Associated with the 911 S5 Botnet @USTreasury | https://home.treasury.gov/... @itspawan_kumar : The DOJ arrested YunHe Wang, a 35-year-old Chinese national, who was charged with operating the 911 S5 botnet. Wang faces a maximum of 65 years in prison if convicted on all counts, including conspiracy to commit computer fraud, wire fraud, and money laundering. @blacklotuslabs : Another bad day for botnet operators! Group behind CloudRouter and the old 911 S5 proxy botnets arrested! https://www.justice.gov/.... Our tracking of CloudRouter bot traffic shows interdiction was underway in early April #911s5 #botnet #infosec #crimeware #cloudburst [image] @thejusticedept : 911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation; Botnet Infected Over 19M IP Addresses to Enable Billions of Dollars in Pandemic and Unemployment Fraud, and Access to Child Exploitation Materials 🔗: [video] Alexander Leslie / @aejleslie : 👀 🚨 “Today, [OFAC] designated three individuals, Yunhe Wang, Jingping Liu, and Yanni Zheng, for their activities associated with the malicious botnet tied to the residential proxy service known as 911 S5."https://home.treasury.gov/ ... Forums: r/technology : US arrests man allegedly behind enormous botnet that enabled cyberattacks and fraud

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The takedown follows U.S. Treasury action a day earlier against people and companies tied to 911 S5, linking financial sanctions to a broader effort to disable the service’s operating infrastructure. The case also extends the enforcement playbook used in the Qakbot disruption, where authorities infiltrated and dismantled a botnet used by ransomware groups.

What distinguishes this case is the residential-proxy layer: infected devices were turned into apparently ordinary consumer IP addresses that customers could rent. Seizing Cloudrouter-associated infrastructure therefore targets both the botnet’s control plane and the service that monetized it.

First-order effects

  • 911 S5’s paying customers lose access to its proxied residential IP pool as the seized infrastructure takes the service offline; Yunhe Wang faces U.S. criminal allegations alongside the earlier sanctions action.
  • Investigators gain an opportunity to analyze seized infrastructure and financial activity; Chainalysis’ work tied to the announcement illustrates how blockchain tracing can support attribution and asset-focused enforcement.

Second-order effects

  • Criminal users that relied on 911 S5 for concealment must seek replacement proxy capacity or alter their operations, while legitimate platforms may see less abuse routed through the service’s former IP pool.
  • The combined sanctions, arrest, and seizure raise the cost for operators of monetized botnets: infrastructure, payments, and named intermediaries can each become enforcement targets rather than isolated points of failure.

Third-order effects

  • If cross-border seizures and financial tracing continue to be paired, botnet enforcement may increasingly focus on dismantling the commercial services built on compromised devices—not only removing malware from endpoints.
  • The pattern points toward more international operations against shared cybercrime infrastructure, though displacement to other proxy providers remains a material limitation without sustained disruption of replacement networks.

The trend: Cybercrime enforcement is moving toward coordinated disruption of the infrastructure, financial flows, and service layers that turn compromised devices into scalable illicit businesses.