I thought that hacked machines usually used not as proxies for traffic from origin attack hosts but rather than large fleet of cheap throwaway attacking traffic origins themselves.
There's a used to be fashionable definition "fog computing" for using computer resources like that. Except it criminals used this approach before definition emerged.
And as an attacker you couldn't care less about latency when you schedule a job of scanning bunch of ip addresses for vulnerabilities to one of thousands throwaway hacked home pcs in your fleet.