Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Blog

US Sanctions Three Chinese Nationals Over 911 S5 Botnet as DOJ Dismantles Proxy Network

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The United States took two linked actions against the 911 S5 cybercrime operation in May 2024: the Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned three Chinese nationals and three Thailand-based companies on May 28, and the Justice Department announced Yunhe Wang’s arrest and an international infrastructure-seizure operation on May 29.

911 S5 was not simply a conventional VPN. According to Treasury and DOJ, it was a malware-powered residential-proxy network that allegedly used compromised Windows computers to route customers’ traffic through innocent people’s residential internet connections.

What 911 S5 was

A botnet is a network of compromised computers controlled or used by an operator. A residential proxy service sells the ability to make internet traffic appear to originate from residential IP addresses. 911 S5 allegedly combined both models:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. People were encouraged to install free VPN software, including programs identified by the government as MaskVPN and DewVPN.
  2. The software allegedly installed or enabled malware on Windows computers and turned them into traffic relays.
  3. 911 S5 aggregated the computers’ residential IP addresses into a proxy pool.
  4. Paying customers could route traffic through selected compromised devices, making activity appear to come from victims’ homes or businesses.

That distinction matters. The VPN branding was reportedly the lure; the alleged business was the unauthorized use and sale of access to compromised residential connections. This does not mean every free VPN is malicious, or that every user of MaskVPN or DewVPN was necessarily compromised.

The alleged flow was:

Free VPN installation → compromised computer becomes a relay → residential IP enters the proxy pool → customer routes traffic through the victim’s connection.

Who Treasury sanctioned

Person or entity Alleged role or basis for designation
Yunhe Wang Treasury identified Wang as the primary administrator of 911 S5. DOJ charged him with creating and operating the botnet and deploying malware.
Jingping Liu Treasury identified Liu as an alleged co-conspirator involved in laundering proceeds. The alleged process included converting cryptocurrency payments through over-the-counter vendors and moving funds into accounts held by Liu.
Yanni Zheng Treasury said Zheng acted as Wang’s power of attorney and conducted payments, business transactions, and real-estate purchases on Wang’s behalf.
Spicy Code Company Limited Thailand-based company Treasury said was owned or controlled by Wang.
Tulip Biz Pattaya Group Company Limited Thailand-based company Treasury said was owned or controlled by Wang.
Lily Suites Company Limited Thailand-based company Treasury said was owned or controlled by Wang.

Treasury’s announcement did not describe Liu and Zheng as technical administrators in the same way it described Wang. Their alleged roles were principally financial, transactional, or representative.

What the OFAC sanctions mean

OFAC designations are financial and regulatory measures, not criminal convictions. In general, property and property interests of the designated people and companies that are in the United States, or in the possession or control of U.S. persons, must be blocked and reported to OFAC. U.S. persons are generally prohibited from dealing in that blocked property or conducting transactions involving the designated parties, including transactions that pass through the United States.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sanctions can restrict access to U.S. banks, payment channels, and assets while making it harder for designated parties to move or use money internationally. They operate alongside, rather than replace, the criminal case against Wang.

Wang’s arrest and the infrastructure takedown

DOJ said Wang was arrested on May 24, 2024. The indictment alleged that he received approximately $99 million from selling access to hijacked IP addresses between 2018 and July 2022. Wang was charged in connection with creating and operating 911 S5 and deploying malware.

DOJ also said the coordinated operation:

  • Seized 23 domains and more than 70 servers.
  • Seized approximately $30 million in assets and identified another approximately $30 million in forfeitable property.
  • Targeted both the historical 911 S5 infrastructure and an attempted successor service called CloudRouter.io.
  • Involved authorities and assistance from the United States, Singapore, Thailand, and Germany, as well as the FBI, OFAC, Defense Criminal Investigative Service, Commerce Department’s Office of Export Enforcement, DOJ’s Criminal Division, Chainalysis, Shadowserver Foundation, and Microsoft.

The action was therefore more than a financial designation or a routine domain seizure. It combined an arrest, asset tracing, server and domain seizures, and an attempt to prevent the service from being rebuilt under a new name.

Rank #2
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

How large was 911 S5?

DOJ said compromised computers were located in nearly 200 countries and were associated with more than 19 million unique IP addresses, including 613,841 U.S. IP addresses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“19 million unique IP addresses” should not be read as proof that 19 million computers were continuously infected at the same time. IP addresses can change, and the government’s wording describes addresses associated with the compromised infrastructure rather than a precise count of simultaneously active machines.

DOJ said Wang operated approximately 150 dedicated servers worldwide, about 76 of them leased from U.S.-based providers.

How the network allegedly enabled fraud

Residential IP addresses can look more like ordinary household or business connections than data-center traffic. That may help a criminal customer evade geographic restrictions, reputation checks, or fraud-detection systems. The proxy network allegedly gave customers a way to hide the true origin of their activity behind someone else’s connection.

DOJ estimated that approximately 560,000 fraudulent unemployment-insurance claims originated from compromised IP addresses and that confirmed fraudulent unemployment-insurance losses exceeded $5.9 billion. It also said more than 47,000 Economic Injury Disaster Loan applications originated from compromised IP addresses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those figures require careful interpretation. An application originating from a compromised IP address is evidence about the apparent network origin, not proof that the 911 S5 operators personally submitted every application or that every dollar associated with those addresses was caused by the botnet. Treasury used the broader formulation that the botnet contributed to the loss of billions of dollars to the U.S. government, including through fraudulent CARES Act-related applications. The $5.9 billion figure is the more specific DOJ estimate for confirmed fraudulent unemployment-insurance losses.

Rank #3
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

DOJ said customers also used the service in alleged financial fraud, identity theft, credit-card fraud, cyberstalking, harassment, bomb threats, threats of harm, child-exploitation offenses, illegal exportation of goods, and efforts to circumvent fraud-detection systems. Treasury said 911 S5-associated IP addresses were linked to bomb threats made across the United States in July 2022.

The alleged money trail

According to Treasury, customers primarily paid in cryptocurrency. The alleged proceeds were converted into U.S. dollars through over-the-counter vendors and transferred through accounts associated with Liu. Treasury also alleged that accounts in Liu’s name were used to acquire luxury real estate for Wang.

The sanctions and forfeiture actions targeted the financial infrastructure supporting the alleged operation, while the criminal case addressed Wang’s alleged conduct. DOJ stated that an indictment is an allegation and that Wang is presumed innocent unless proven guilty beyond a reasonable doubt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline

  • 2014–2015: Government and investigative accounts place the alleged beginning of the operation in this period.
  • 2015–July 2022: Investigative reporting described the sale of access to compromised Windows computers.
  • July 2022: KrebsOnSecurity reported on the service’s shutdown after a breach and identified Wang as its apparent owner or manager. Treasury also said associated IP addresses were linked to U.S. bomb threats that month.
  • Late 2022: Public reporting described a reappearance under the Cloud Router or CloudRouter name.
  • May 24, 2024: DOJ said Wang was arrested.
  • May 28, 2024: OFAC sanctioned the three individuals and three Thailand-based companies.
  • May 29, 2024: DOJ publicly announced the dismantling and arrest.

For investigative background on the service’s earlier shutdown and distribution model, see KrebsOnSecurity’s reporting and its 2022 investigation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Could an ordinary person’s IP address have been involved?

Yes, according to the alleged delivery model. A person could have installed software believing it was a legitimate free VPN while the computer was used as a relay for someone else’s traffic. Their IP address could then appear in records associated with fraud or other abuse even though the resident did not conduct that activity.

Possible warning signs include an unfamiliar VPN application, unexpected VPN adapters or network services, unexplained upload traffic, unusual CPU, memory, or bandwidth use, security alerts involving suspicious installers, or sudden IP-reputation problems and account-security challenges. None of these symptoms proves 911 S5 infection; many unrelated software, network, or account problems can produce similar signs.

What suspected victims should do

  1. Check installed applications, browser extensions, VPN profiles, and network adapters for software you do not recognize.
  2. Run a scan with reputable, updated security software and install pending operating-system updates.
  3. Remove suspicious software only after saving relevant evidence, such as installer names, alerts, dates, and account notifications.
  4. Change important passwords from a device you trust, enable multifactor authentication, and contact financial institutions if accounts show unauthorized activity.
  5. Use the FBI’s 911 S5 resource page for official victim-identification and remediation information.

A clean scan today cannot prove that a computer was never infected, and the takedown of servers does not automatically clean every endpoint that may previously have been compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the operation accomplished—and what it did not prove

The seizure of domains, servers, and assets disrupted the known 911 S5 infrastructure and the alleged CloudRouter.io successor. International cooperation was important because the operators, servers, victims, customers, payment flows, and affected IP addresses crossed multiple jurisdictions.

But “dismantled” does not mean every historical infection was remediated or that no copycat residential-proxy network could emerge. The eventual criminal-court outcome, the exact number of compromised devices rather than unique IP addresses, and the extent to which individual customer activity can be attributed to particular people are separate questions.

The broader lesson is practical: an IP address identifies the apparent network origin of activity, not necessarily the person behind it. Residential IP reputation can be weaponized against innocent households, and software advertised as a free VPN can conceal a very different business model when its distribution, permissions, ownership, or behavior is opaque.

For the official designations, see Treasury’s OFAC announcement. For the arrest, charges, seizures, and government estimates, see DOJ’s announcement.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
Network Security, Firewalls, and VPNs: . (Issa)
Network Security, Firewalls, and VPNs: . (Issa)
New Chapter on detailing network topologies; Increased coverage on device implantation and configuration
$60.87
SaleBestseller No. 3

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.