Kill one, spawn many
"Destroy to protect." The cyber industry has been applying this doctrine for sixteen years. In 2026, the data allows us to measure its outcome.
In five months, Google, Microsoft, Europol and the DOJ dismantled five of the world's largest proxy networks, botnets and phishing platforms. IPIDEA: 550 threat groups observed in a single week, several million devices neutralised¹. Tycoon 2FA: 62% of phishing blocked by Microsoft, 330 domains seized². SocksEscort: 369,000 IP addresses across 163 countries³. Aisuru, Kimwolf, JackSkid and Mossad: over 3 million compromised devices, 315,000 attributed DDoS attacks⁴. The industry applauds. Press releases speak of "significant degradation."
Nobody asks what comes next.
What comes next is a timeline the press releases don't cover. And that timeline tells a different story from the keynotes.
The premise
The disruption doctrine rests on an economic argument: raising the attacker's cost reduces the volume of attacks. Sandra Joyce, VP of Google Threat Intelligence Group, formalised it in a keynote at RSAC 2026 in March⁵. Passive defence is no longer enough. Adversaries must be actively disrupted, their infrastructure dismantled, their return on investment compressed. The US political framework follows suit: the One Big Beautiful Bill Act allocates one billion dollars to offensive cyber operations. Several bills introduced in 2025 seek to revive letters of marque — the Scam Farms Marque and Reprisal Authorization Act against cybercriminals, another against the cartels. All remain in committee⁶.
Google operates the infrastructure adversaries exploit: Android, Gmail, Chrome, DNS, the cloud. Google can therefore evict them. The reasoning holds. It assumes the adversary, once evicted, disappears.
Microsoft has been testing this model since 2010 with its Digital Crimes Unit⁷. Sixteen years and dozens of operations later, cybercrime has increased every year, without exception. If the premise worked, we would observe an inflection somewhere. We observe the opposite. In April 2026, Barracuda published its annual botnet landscape review: 2025 was simultaneously the year of the greatest disruption victories and the strongest growth in cybercriminal activity⁸. Disruption and acceleration, at the same time.
The facts
January 2026. Google dismantles IPIDEA, one of the world's largest residential proxy networks¹. Court-authorised action on C2 domains, coordination with Cloudflare, Spur and Lumen's Black Lotus Labs, removal of over 600 Android applications via Play Protect. The available device pool drops by several million.
At the same time, the Kimwolf network survives independently. Kimwolf was not merely feeding IPIDEA with 2 million infected Android devices⁹. According to the Lumen Defender Threatscape 2026 report, Kimwolf operators were exploiting a vulnerability in IPIDEA that enabled LAN pivoting: an actor would purchase residential proxy access, jailbreak it, pivot into the local network and recruit other devices into the botnet¹⁰. Kimwolf was a parasite of IPIDEA. Google destroyed the host. The parasite mutated into an autonomous organism.
A month later, the Aeternum botnet appears¹¹. Its C2 runs through the Polygon blockchain. Domain seizures, the primary legal tool of takedowns, are structurally ineffective against this architecture. Aeternum is not a remnant of IPIDEA. It is a product of the post-IPIDEA era, designed to withstand the methods that worked in January.
Early March. Coordinated Europol/Microsoft takedown of Tycoon 2FA². 330 domains seized. An unquestionable operational victory. But the primary operator (identified in Pakistan) remains at large. Stolen credentials continue to circulate. Microsoft quantifies the aftermath itself: Tycoon phishing drops 15% for the rest of the month, then rebounds by the third week, with domains shifting to .RU (over 41% of the pool by the end of March) and leaving Cloudflare¹².
Second week of March. Lumen documents KadNap, a network of 14,000 ASUS routers resold as residential proxies¹³. The malware had been operating since August 2025 — five months before IPIDEA's fall — on a distinct lineage. While Google was dismantling one network, another was growing on edge devices, beyond the reach of the operation. The proxy supply regenerates in parallel with the takedowns, not in reaction to them, on a substrate harder to map, seize and attribute.
Same week. US authorities dismantle SocksEscort³. 369,000 IP addresses. 163 countries.
March 19. The DOJ, together with Canada and Germany, dismantles four botnets simultaneously: Aisuru, Kimwolf, JackSkid and Mossad⁴. Over 3 million compromised devices. Kimwolf, the parasite that had survived IPIDEA's fall in January, had in the meantime tripled its bot count in a single week and launched attacks reaching 30 terabits per second¹⁰. It took two months to dismantle it in turn. By then, it had already served its purpose: demonstrating that destroying the host only accelerates the parasite's evolution.
Five major dismantlements in five months. The total population of proxy networks has not decreased.
Publishing is teaching
Every disruption operation publishes technical intelligence. Indicators of compromise, C2 architecture, SDK signatures, detailed modus operandi. The intention is defensive: enabling the community to protect itself.
The effect is educational: enabling the adversary to correct its mistakes.
For IPIDEA, Google exposed the tier-1/tier-2 architecture, the 7,400 identified servers, the SDK distribution domains, the 13 brands operated from the same infrastructure¹. The next residential proxy operator has a complete course on what not to replicate. Don't centralise SDKs. Don't reuse the same domains for C2 and marketing. Don't go through the Play Store. Don't operate thirteen brands from the same backend.
What is exposed will no longer be exploitable. The yield of each technical intelligence publication is declining by construction: it closes the window it documents.
The script was written
In April 2025, Sekoia TDR and Orange Cyberdefense published a joint report on the residential proxy market¹⁴. Two of their conclusions directly illuminate subsequent events.
First, the market's apparent fragmentation masked a real consolidation. Providers presented as independent shared the same legal entities, the same server infrastructure, the same crypto wallets. Intel 471 confirmed: 922 S5 Proxy, ABC S5 Proxy and PIA S5 Proxy displayed the same Ethereum address on their respective sites¹⁵. IPIDEA operated 13 brands from the same architecture. The fragmentation was a façade. The reality was an opaque oligopoly.
Then, the most prescient conclusion. Sekoia wrote in plain terms that the market is "so fragmented that no single provider is a major-enough actor worth tackling. One malicious going down would only mean cyber actors would move on to any of the numerous other providers"¹⁴.
Google did exactly what Sekoia described as ineffective. The result matches what Sekoia predicted: demand redistributed.
With an additional side effect. By striking an interconnection node that masked a hidden consolidation, Google replaced it with real fragmentation this time. Market opacity increased, not decreased. This is the balloon effect documented in criminology for thirty years: dismantle a cartel, traffic doesn't decrease, it redistributes into smaller structures that are harder to monitor.
Survivors are the most resistant
Industrial-scale disruption pressure selects. Commodity actors — those dependent on shared, cheap infrastructure — fall. Those left standing resist, by definition, the methods that eliminated their predecessors.
Lumen, which operates one of the world's largest internet backbones, documented the mechanism in its 2026 Defender Threatscape Report¹⁰. Over four months, Black Lotus Labs participated in disrupting more than 550 C2 nodes linked to Aisuru and Kimwolf. Operators reacted within hours, sometimes minutes, standing up replacement servers and triggering mass malware re-downloads across the botnet. The report concludes that the speed and scale of Kimwolf's recovery cycles show how future botnets will evolve under pressure: rebuilding faster than defenders can respond.
Resistance isn't only on the infrastructure side. On March 17, a campaign of 1.5 million messages hits 179,000 organisations across 43 countries, orchestrating three phishing platforms at once: Tycoon 2FA, Kratos and EvilTokens¹². The operator no longer depends on a single provider; it spreads its traffic across interchangeable kits. Dismantling one of them displaces nothing — the client was already on the others. Redundancy is no longer a reaction to the takedown; it is built in ahead of time.
Aeternum and its blockchain C2¹¹ takes the logic a step further. HONESTCUE¹⁶, the first documented malware that outsources its own code generation to a commercial LLM, another step further still. Static analysis and signatures become inadequate against code generated dynamically on each execution. Infrastructure disruption does not touch the malware factory itself.
The iOS exploit kit Coruna completes the picture¹⁷. Built at nation-state grade, it now proliferates into crypto theft. The boundary between government tools, commercial surveillance and mass cybercrime has dissolved. Disruption cleans up the visible background noise and pushes the real threat into the shadows. We eliminate what we knew how to detect. We select for what we don't.
Reconstitution is measured in hours
The disruption industry measures what it does, not what it produces. Domains seized, devices cleaned, groups identified: activity metrics.
Victory press releases don't measure what reconstitutes behind them. When someone does, the result contradicts the doctrine. In February 2025, a peer-reviewed study did exactly that. An academic team, funded by the European Research Council, tracked the largest takedown ever conducted against booters — those DDoS-for-hire services sold for a few dollars a month. The operation, run by the FBI, the NCA and the Dutch Police, seized 62 domains in two waves between December 2022 and May 2023, made arrests, and deployed decoy sites to deter customers. The analysis combines several sources, including real traffic captured on the seized domains¹⁸.
Over half the booters in the first wave returned online within a median of 19 hours. All those in the second wave returned, with a median of 42 hours. Operators seized in both waves reinstalled their service the second time within one hour: they were prepared. On attack volume, the first wave produced a 20–40% drop, statistically significant, absorbed within six weeks before the volume climbed back above its starting point. The same duration as the 2018 takedown.
The same study places the episode in a lineage. The Conficker worm was neutralised over fifteen years ago; millions of machines remained infected years later. Two years after the VPNFilter disruption, routers were still compromised. The LockBit ransomware reappeared one week after the international operation that struck it. Across unrelated cases, reconstitution is the rule.
On the vendor side, the infostealer market tells the same story. In May 2025, Microsoft, the FBI and Europol seized 2,300 domains linked to Lumma Stealer¹⁹. Indicators of compromise dropped to 57 on takedown day, rose to 287 the next day, reached 457 a week later, above pre-takedown levels²⁰. Trend Micro documented the migration to Russian hosting providers less willing to cooperate²¹. By February 2026, Lumma was operating at full scale again²². The largest infostealer takedown in history was absorbed within weeks.
The cost of disruption is borne once by the disruptor. The cost of reconstitution is distributed across hundreds of actors adapting in parallel. The cost of re-attribution is borne by every defender, including those who lack the disruptor's visibility.
The study delivers one last result, the most decisive. Everywhere, infrastructure seizure produced a short-lived effect. What durably changed practices was the influence component: decoy sites deployed by police, targeted ads, presence on forums — enough to instil a perception of risk in customers. Yet it is infrastructure seizure, the ephemeral half, that Google industrialises and sells. The half that lasts is not for sale, and remains beyond the reach of anyone who is not a state.
The cycle closes
Google disrupts observable infrastructure. Attackers fragment and become harder to trace. Google publishes a report showing threats are growing more sophisticated. Google sells the necessity of its global visibility as the only answer. Dependency increases. The cycle begins again²³.
No conspiracy here. An emergent property of a system where the disruptor is also the vendor of the solution to the problem it helps worsen. Sandra Joyce said it herself at RSAC: the private sector runs the very infrastructure adversaries exploit, which gives it visibility government agencies sometimes lack⁵. This is true. It is also a sales pitch. The two coexist.
When you're not Google
For an organisation that does not operate a global cloud platform, a dominant mobile OS, a search engine, an email service with 1.8 billion users and a planetary DNS network, the disruption doctrine has a concrete consequence²⁴.
Before IPIDEA's dismantlement, your teams could identify the network's exit nodes, add them to blocklists, correlate suspicious activity transiting through known infrastructure. Afterwards, malicious traffic flows through networks you don't know, from devices you can't map, with patterns you haven't yet observed. Observable background noise has been replaced by invisible background noise.
For a defence-sector SME, a hospital, a local government, a mid-size industrial company, the balance sheet is negative. The threat has not decreased. Visibility over the threat has decreased. And the only entity that retains that visibility is the one that caused the fragmentation.
The right scale
Disrupting the attacker inside your network — hunting their presence, understanding their lateral movement, cutting their access, documenting their TTPs — produces a controlled local effect. Cost is proportional to your size. The benefit accrues directly to you.
Disrupting the attacker at internet scale — dismantling their infrastructure, fragmenting their networks, publishing their methods — produces an effect whose benefits are captured by those with global visibility, and whose costs are distributed across everyone else.
The first approach is accessible. The second is a luxury paid for in dependency.
What I don't know
The counterfactual is unverifiable. It is possible that without disruption, attack volumes would be even higher. No data settles the question.
Reconstitution and the short-lived effect, however, are now measured. The study cited above does it systematically, free of any commercial interest; Microsoft on Tycoon, Lumen on Kimwolf, Lumu and Trend Micro on Lumma document it case by case. But the study covers the booter market — the cheap, shared low end — and explicitly excludes organised and state-sponsored crime. For IPIDEA and Aeternum, reconstitution evidence remains indirect: chronological appearance, temporal correlation. Direct causation — "this takedown produced this successor" — is not formally demonstrated.
The main blind spot remains. The degradation of attribution and the loss of visibility for defenders who did not take part in the takedown are a deduction, not a measurement. We can now quantify the speed of reconstitution; nobody publishes data on what fragmentation costs those who suffer it without having caused it. That absence is itself a result: the doctrine is applied without measuring its effect on non-participating defenders.
Conclusion
Sixteen years of takedowns. Cybercrime has never been more industrialised, fragmented, resilient. The problem may not be the execution of the doctrine. The problem may be the doctrine itself.
Twentieth article in a series on Western cybersecurity's failures:
- Article 1 : La vulnérabilité de la gestion des vulnérabilités
- Article 2 : La dépendance européenne aux standards américains
- Article 3 : Les États, architectes cachés du marché noir des vulnérabilités
- Article 4 : L'IA ou l'effondrement du modèle défensif occidental
- Article 5 : Desert Power — survivre sans l'Empire
- Article 6: I Am Altering the Deal
- Article 7: The Last Channel
- Article 8: Lord of Cyber War
- Article 9: The digital hawks
- Article 10: They Live... we sleep
- Article 11: Soylent Green
- Article 12: Ghost in the Binary
- Article 13: Now You See Me
- Article 14: The Prestige
- Article 15: Pitch Black
- Article 16: The Thing That Should Not Be
- Article 17: Status: clean
- Article 18: The Leopard
- Article 19: The Usual Suspects
Sources
¹ Google Cloud Blog / GTIG, "Disrupting the World's Largest Residential Proxy Network," January 29, 2026. https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network
² Microsoft On the Issues, "How a global coalition disrupted Tycoon 2FA," March 4, 2026. Europol, "Global Phishing Service Platform Taken Down," March 2026. https://blogs.microsoft.com/on-the-issues/2026/03/04/how-a-global-coalition-disrupted-tycoon/ https://www.europol.europa.eu/media-press/newsroom/news/global-phishing-service-platform-taken-down-in-coordinated-public-private-action
³ The Hacker News, "Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries," March 14, 2026. TechCrunch, "Law enforcement shuts down botnet made of tens of thousands of hacked routers," March 12, 2026. https://thehackernews.com/2026/03/authorities-disrupt-socksescort-proxy.html https://techcrunch.com/2026/03/12/law-enforcement-shuts-down-botnet-made-of-tens-of-thousands-of-hacked-routers/
⁴ CyberScoop, "Justice Department disrupts botnet networks that hijacked 3 million devices," March 20, 2026. Cybersecurity Dive, "US, allies move to dismantle four high-volume IoT botnets," March 2026. Krebs on Security, "Feds Disrupt IoT Botnets Behind Huge DDoS Attacks," March 2026. https://cyberscoop.com/botnet-disruption-aisuru-kimwolf-jackskid-mossad/ https://www.cybersecuritydive.com/news/botnet-takedown-operation-us-canada-germany/815309/ https://krebsonsecurity.com/2026/03/feds-disrupt-iot-botnets-behind-huge-ddos-attacks/
⁵ Nextgov/FCW, "Google launches threat disruption unit, stops short of calling it 'offensive'," March 23, 2026. RSAC 2026 keynote Sandra Joyce, "Activate Industry!: Moving Beyond Defense to Disruption and Active Defense." https://www.nextgov.com/cybersecurity/2026/03/google-launches-threat-disruption-unit-stops-short-calling-it-offensive/412321/ https://www.rsaconference.com/library/video/rsac-2026-quick-look-activate-industry
⁶ See in this series: "Lord of Cyber War" (letters of marque, privatisation of cyber operations). Scam Farms Marque and Reprisal Authorization Act of 2025 (H.R. 4988), introduced by Representative David Schweikert on August 15, 2025, referred to the House Committee on Foreign Affairs, zero cosponsors, status "Introduced" to date. Cartel version of the same mechanism: Cartel Marque and Reprisal Authorization Act of 2025 (H.R. 1238 / S. 3567). CyberScoop, "Google previews cyber 'disruption unit' as U.S. government mulls more offensive options," August 27, 2025. https://www.congress.gov/bill/119th-congress/house-bill/4988 https://cyberscoop.com/google-cybersecurity-disruption-unit-active-defense-hack-back/
⁷ Lawfare / Seriously Risky Business, "Google Sharpens Its Cyber Knife," September 5, 2025 — citing the Microsoft DCU precedent since 2010 and Google's first two operations (Glupteba 2021, BadBox 2.0 July 2025). Microsoft, "The DCU helps the law move at the speed of cybercrime." https://www.lawfaremedia.org/article/google-sharpens-its-cyber-knife
⁸ Barracuda Networks, "Top threat trends of the 2025 botnet landscape," April 13, 2026 — "2024 was a year of both disruption and acceleration for botnet-driven threats. [...] Overall botnet activity continued to grow in scale and intensity." https://blog.barracuda.com/2026/04/13/top-threat-trends-of-the-2025-botnet-landscape
⁹ The Hacker News, "Kimwolf Android Botnet Infects Over 2 Million Devices," January 2026. Cybersecurity News, "Mirai-Based Botnets Evolve Into Massive DDoS and Proxy Abuse Threat," March 25, 2026 — "Despite the takedown efforts, these botnets continue to adapt and find new ways to stay operational." https://cybersecuritynews.com/mirai-based-botnets-evolve-into-massive-ddos/
¹⁰ Lumen Technologies / Black Lotus Labs, "2026 Defender Threatscape Report," April 7, 2026 — 550+ Aisuru/Kimwolf C2 nodes disrupted over four months. Recovery in hours/minutes. Kimwolf tripled in one week, attacks reaching 30 Tbps. IPIDEA vulnerability exploited for LAN pivoting. Network World, "Lumen: Upstream network visibility is enterprise security's new front line," April 9, 2026. Help Net Security, "Cybercriminals move deeper into networks, hiding in edge infrastructure," April 8, 2026. https://ir.lumen.com/news/news-details/2026/Lumen-Unveils-2026-Defender-Threatscape-Report-Upstream-Network-Visibility-is-the-New-Front-Line-of-Cyber-Defense/default.aspx https://www.networkworld.com/article/4156541/lumen-upstream-network-visibility-is-enterprise-securitys-new-front-line.html https://www.helpnetsecurity.com/2026/04/08/large-botnets-campaigns-attack-activity/
¹¹ The Hacker News, "Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown," February 26, 2026 — C2 on Polygon smart contracts, $200/build, $4,000/full source, built-in anti-analysis. https://thehackernews.com/2026/02/aeternum-c2-botnet-stores-encrypted.html
¹² Microsoft Threat Intelligence, "Email threat landscape Q1 2026: trends and insights," April 30, 2026 — Tycoon 2FA reconstitution curve (-15% then rebound by the third week, TLD migration to .RU exceeding 41% of the pool by the end of March, departure from Cloudflare). March 17 multi-PhaaS campaign: 1.5 million messages, 179,000 organisations, 43 countries, simultaneous orchestration of Tycoon 2FA, Kratos and EvilTokens. https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/
¹³ The Hacker News, "KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet," March 2026. https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html
¹⁴ Sekoia.io TDR & Orange Cyberdefense World Watch, "Unveiling the depths of Residential Proxies providers," April 2025 — "The market is so fragmented that no single provider is a major-enough actor worth tackling. One malicious going down would only mean cyber actors would move on to any of the numerous other providers." https://blog.sekoia.io/unveiling-the-depths-of-residential-proxies-providers/
¹⁵ Intel 471, "A Look at the Residential Proxy Market," August 2025 — 922 S5 Proxy, ABC S5 Proxy and PIA S5 Proxy sharing the same Ethereum address. https://www.intel471.com/blog/a-look-at-the-residential-proxy-market
¹⁶ Google Cloud Blog / Sandra Joyce, "Recent advances in how threat actors use AI tools," November 2025 — HONESTCUE, dynamic code generation via commercial LLM. https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-recent-advances-in-how-threat-actors-use-ai-tools
¹⁷ iVerify, "Coruna: Inside the Nation-State-Grade iOS Exploit Kit We've Been Tracking," March 2026. BleepingComputer, "Spyware-Grade Coruna iOS Exploit Kit Now Used in Crypto Theft Attacks," March 2026. https://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking
¹⁸ Anh V. Vu, John Kristoff, Ben Collier, Richard Clayton, Daniel R. Thomas, Alice Hutchings (Universities of Cambridge, Illinois Chicago, Edinburgh, Strathclyde), "Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services," USENIX Security Symposium 2025, arXiv:2502.04753, February 7, 2025 — peer-reviewed study, funded by the European Research Council. Median reconstitution of 19h (first wave, 52% of booters) and 42h (second wave, 100%), 1h for operators seized twice. DDoS volume drop of 20–40%, significant on UDP amplification attacks, absorbed within six weeks. Influence component (decoy sites, ads, forum presence) credited with the durable effect. Conficker, VPNFilter, LockBit (Operation Cronos) precedents cited in discussion. https://arxiv.org/abs/2502.04753
¹⁹ Microsoft Digital Crimes Unit, "Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool," May 21, 2025 — 2,300 domains seized, 394,000 machines infected over two months. Dark Reading, "Lumma Stealer Takedown Reveals Sprawling Operation," May 21, 2025. Cybersecurity Dive, "Microsoft leads international takedown of Lumma Stealer," May 21, 2025. https://www.cybersecuritydive.com/news/microsoft-takedown-lumma-stealer/748727/
²⁰ Lumu Technologies, "Advisory Alert: Lumma Stealer Rebounds After Takedown," November 2025 — IoCs: 57 on May 21, 287 on May 22, 457 on May 28. https://lumu.io/blog/lumma-stealer-rebounds/
²¹ Trend Micro, "Back to Business: Lumma Stealer Returns with Stealthier Methods," July 22, 2025 — migration to Russian hosting, discreet distribution channels, targeted accounts back to pre-takedown levels by June-July. SecurityWeek, "Lumma Stealer Malware Returns After Takedown Attempt," July 23, 2025. https://www.trendmicro.com/en_us/research/25/g/lumma-stealer-returns.html https://www.securityweek.com/lumma-stealer-malware-returns-after-takedown-attempt/
²² Hunter Strategy, "LummaStealer Resurgence After 2025 Infrastructure Disruption," February 18, 2026 — "Activity began recovering within weeks, and by late 2025 and early 2026, campaigns were again increasing globally." Bitdefender / BusinessStory, "Previously-hobbled Lumma Stealer has returned with lures that are hard to resist," February 2026. https://blog.hunterstrategy.net/lummastealer-resurgence-after-2025-infrastructure-disruption/
²³ See in this series: "Soylent Green" (vendor self-attribution bias, commercial threat cycle) and "AI and the collapse of the Western defensive model" (offensive/defensive imbalance).
²⁴ See in this series: "Pitch Black" (European dependence on American vulnerability infrastructure). The disruption doctrine reinforces this dependence: disruption capacity is concentrated among US infrastructure operators. Europe has neither the legal framework, nor the institutional mandate, nor the operational visibility to conduct equivalent disruption operations. NIS2 provides nothing of the sort. ANSSI does not have this mandate.