- The move to "low and slow" botnet tactics
- Why your traditional defenses aren't enough
- IP-based blocking is defunct
- Real-world examples of WAF and static-rules failure - and the fallout
- Moving to intent-based detection
- The DataDome advantage: Multi-layered AI detection
- Stop malicious botnets jumping your digital defenses
You might think your organization is adequately protected by the WAF and rate limiting you deploy, but think again. Legacy botnets rely on thousands of requests firing from a handful of data center IP addresses and are therefore easy to block with static rules, but modern distributed botnets operate very differently. These digital menaces use high-reputation residential proxy networks and rotate millions of IP addresses across infected smartphones, IoT devices, and compromised home routers (as well as opt-in proxy apps that sell user bandwidth) to look like legitimate human traffic.
Why does this matter? Residential proxies act as effective camouflage for botnets, inheriting trust from ISPs, blending into legitimate traffic patterns, and bypassing static rules. To keep your enterprise safe from a potentially catastrophic botnet attack, you need to change your defense tactics.
The move to "low and slow" botnet tactics
In the past, botnets' usual technique was to hammer endpoints, but this is no longer the case. The botnets of today, however, drip-feed malicious traffic into your system. Attack patterns now typically incorporate a single request per IP every five to fifteen minutes, thousands of unique IPs per minute, and distributed account takeover attempts across a vast IP pool. Credential stuffing may be spread across literally millions of devices, or inventory scalping disguised as normal browsing. This MO is the exact opposite of a volumetric DDoS. It's quiet, patient, and designed to slip past your threshold-level defenses before you even realize there's a problem.

Why your traditional defenses aren't enough
Legacy WAF logic focuses on blocking IPs that send more than 100 requests per minute, repeated login failures from the same IP, and known bad IP ranges. But this logic can easily break when residential IPs are rotated constantly, each IP sends almost no traffic, and reputation databases mark them as legitimate. Your rate-limiting defense doesn't kick in because it doesn't see anything "off", while your WAF treats this malicious traffic as if it emanates from real human users.
These rules assume attackers reuse IPs, but the problem is, modern botnets never do. In essence, a distributed botnet can execute hundreds of thousands of nefarious actions without triggering your rate-limiting or tripping your WAF rules.
IP-based blocking is defunct
IP-based blocking is, today, not fit for purpose because IPs are no longer stable identifiers, and residential proxies inherit a "good" reputation, meaning these markers aren't reliable. Botnets, determined to cause as much digital mischief as possible, rotate IPs faster than blocklists can update, and attackers mimic real human browsing behavior with alarming accuracy. On top of this, threshold rules can't detect distributed patterns.
There's a growing industry consensus that a shift is required: from IP-based to intent-based defenses. These techniques include:
- Intent modelling - analyzing what a user is trying to do.
- Behavioral telemetry - collecting tiny behavioral signals.
- Device fingerprinting - examining software and hardware characteristics.
- Cross-request correlation - linking subtle behavioral cues across multiple sessions.
- Velocity analysis across identities - measuring the speed and timing of actions.
- Anomaly detection at scale - spotting deviations from normal behavior.
Modern botnets exploit blind spots mercilessly, blending into legitimate traffic so effectively that legacy WAFs don't even realize an attack is in progress. With malicious agents continuing to weaponize residential proxies, it's only systems able to interpret intent that can protect themselves and fight back.
Real-world examples of WAF and static-rules failure - and the fallout
The limitations of WAF and rate-limiting defenses aren't an abstract issue, and recent years have seen disastrous consequences. For example, a mid-sized retailer was targeted by a residential proxy botnet that initiated credential stuffing attacks across thousands of household IPs. As each IP sent only a small number of requests, the company's WAF and rate limits never triggered because the traffic was low and slow. The consequences were dire, with tens of thousands of dollars in fraud losses racked up, and analyst workload quadrupling during the attack. Further, customer experience was severely impacted due to account lockouts, affecting brand trust and reputation.
Meanwhile, a wide-ranging campaign using Popa and NetNut residential proxies attacked multiple industries (including healthcare, hospitality, and retail) to launch scraping and credential stuffing attacks. The problem was that WAFs reliant on IP reputation failed because the IPs appeared legitimate, so detection took days as the distributed traffic looked normal and harmless. As a consequence, a five- to seven-figure loss was incurred from account takeover and fraud, and SLA exposure went through the roof as IoT devices were used as proxy endpoints during the attack.
Yet another business recently experienced repeated malicious traffic routed via residential proxies that its WAF and static-based rules didn't identify. IP-reputation-only defenses were entirely bypassed, and rate limits imposed per IP were useless as each IP only sent minimal traffic. Making matters even more complicated, the business's WAF generated up to 50% more false investigations, which overwhelmed analysts.
Moving to intent-based detection
Intent-based detection is a security approach that looks at what the user is trying to do rather than where the request came from. It replaces IP-based rules with contextual, behavioral, and telemetry-focused analysis to reveal whether an action is automated or emanates from a real human user.
In the modern world of digital security, intent is king, because while bots can spoof IPs, they can't perfectly spoof human behavior across millions of devices. The result? Distributed botnets are exposed immediately.
The DataDome advantage: Multi-layered AI detection
DataDome's botnet prevention tool solves the problem of residential proxies not triggering your WAF and rate-limiting safeguards. It looks at:
- Microbehaviors like scroll velocity, mouse movements, and timing irregularities that bots find it hard to mimic, meaning it can identify automation even if an IP appears clean.
- Navigation patterns, evaluating how users move through your site to identify sequences that distributed botnets replicate across a huge number of rotating residential IPs.
- Browser integrity, with DataDome checking for signs of automation frameworks, tampering, or headless browser artefacts.
- Device signals, inspecting software and hardware fingerprints to sniff out the sort of inconsistencies that are typical of botnet traffic, even when each request comes from a different device profile.
- Latency anomalies, such as timing deviations that reveal automation, to catch bots that intentionally slow down requests and blend with human traffic.
- Hidden telemetry, collecting and correlating subtle signals that bots can't fully replicate across large residential proxy networks.
- Trillions of daily signals, with DataDome's AI engine processing a vast volume of intent data to instantly flag botnets no matter how widely traffic is distributed.
Further, DataDome's system evaluates signals lightning fast, with a processing time of under two minutes. This ensures bot detection occurs before pages are loaded without slowing down and annoying legitimate users.
Stop malicious botnets jumping your digital defenses
In today's world, WAFs and rate-limiting are no longer enough to protect your system from malicious botnets using residential proxies that don't trigger any alarm bells. For the best protection (and peace of mind), you need a solution like DataDome that instantly identifies distributed botnets without relying on blacklists and static rules. As a result, modern botnets' camouflage is stripped away, your WAF's blind spots disappear, and your users are protected without the addition of latency or friction.
