Compromised iot devices sold as residential proxy is pretty hot right now: https://thehackernews.com/2024/03/themoon-botnet-resurfaces-exploiting.html?m=1
Those are targeting Linux routers and iot devices though. However, esp32 had vulnerabilities in the past such as the fatal fury attack, though it requires physical access to execute.