Why are they suddenly cheaper than they were before?
Massive rise in botnets that focus on targeting cloud VPSes instead of IoT devices and exploiting shit TV boxes with residential proxy SDKs installed which people can exploit to connect to the proxy devices themselves by connecting to 0.0.0.0:5555. It allows skids to get hundreds of thousands of devices for only a couple hundred dollars of bandwidth without having to mass scan the Internet.
There is at least 6,000,000 vulnerable devices from these residential proxy networks which can easily be exploited because 67% of these chink TVs have no authentication at all so you can just log in and hack the device.
Aisuru/Kimwolf was the biggest offender of using both methods to spread their botnet.
According to Dort (the main person behind Aisuru/Kimwolf) in an email, he admitted to having 36,600,000+ devices on his botnet.
He also admits in the same email that he was using his botnet to distribute CSAM through SFTP and Torrents.
It doesn't help at all that the botnet was ran by a whole group of people, most of them being troons or pedos:
Zerlokk/oliking800 (Oliver Bates, canadian furry), Snow (Phillip Hanover, a 15 year old troon from Germany), and Dort (Jacob Butler, canadian pedo).
All of their doxxes were known by the feds for months and yet they waited months to stop it.