Still not sure about the "who" question, but here's the scale of money changing hands:
> Residential proxies are everywhere, so why did proxy DDoS attacks mostly come from the U.S.? The answer is money. If you are committing fraud or circumventing content restrictions, a Russian IP address gets geo-blocked instantly. A fresh U.S. residential IP address (especially one behind carrier-grade NAT and harder to block individually) is “gold.” Customers pay up to $95 to lease a single U.S. residential IP address for 2 weeks (versus $0.30 for an Eastern European IP). Compare that to your own ARPU per subscriber and sit with it for a second. When an individual IP is worth more than the customer relationship behind it, you don’t have a technical problem. You have a market problem.[1]
1: https://www.nokia.com/blog/one-year-later-the-residential-pr...
if they pay 190/mo to proxy, i should just sell my ip direct -> profit i pay less than half that for fiber , should get a few more isp accounts, and rake it in.
Here is the fun part, the same companies invests millions of dollars to protect its infrastructure and services from scrapers/bots AND they also invest millions of dollars to circumvent the bots, captchas and rate limits.
Unfortunately you cant have it both ways which makes it hard problem to solve for everyone