Google announced that together with other companies they managed to "hit" IPIDEA, which is described as one of the largest residential proxy networks.

The company took legal action to remove dozens of domains used for device control and traffic proxying. IPIDEA’s website is no longer accessible. It claimed to be the “world’s leading IP proxy provider” with over 6.1 million daily IP addresses and 69,000 new IP addresses daily.
“Residential proxy networks have become a ubiquitous tool for everything from high-level espionage to massive criminal schemes,” said John Hultquist, principal analyst at Google Threat Intelligence Group (GTIG). “By routing traffic through an individual’s home internet connection, attackers can hide in plain sight while infiltrating corporate environments. By eliminating the infrastructure used to operate the IPIDEA network, we have essentially pulled the rug out from under a global market that sold access to millions of compromised consumer devices.”
See also: Criminals seize and resell AI infrastructure
Exploitation by hackers and malicious activities
Google noted that, this month alone, IPIDEA's proxy infrastructure was used by over 550 individual threat groups with various motivations (cybercrime, espionage, and APTs groups), from countries including China, North Korea, Iran, and Russia.
The malicious activities included accessing victims' SaaS environments , on-premises infrastructure , and password spray attacks .

In an analysis published earlier this month, Synthient revealed that threat actors behind the botnet/Kimwolf were exploiting security vulnerabilities in residential proxy services, such as IPIDEA, to transmit malicious commands to vulnerable Internet of Things (IoT) devices behind firewalls within local networks (to spread malware).
Malware that turns consumer devices into proxy endpoints is hiding inside apps and games pre-installed on unbranded Android TV streaming boxes. As a result, infected devices relay malicious traffic and participate in DDoS attacks.
While residential proxy networks allow traffic to be routed through IP addresses owned by internet service providers (ISPs), they also provide cover for malicious actors seeking to hide the origin of their malicious activities. “To do this, residential proxy network operators need code running on consumer devices to register them with the network as exit nodes,” GTIG explained.
See also: eScan: Compromised update server pushed malicious update
“These devices either come preloaded with proxy software or connect to the proxy network when users unknowingly download apps with proxy code embedded in them. Some users may knowingly install this software on their devices because they have been promised 'monetizing' their spare bandwidth“.
Residential proxy networks: IPIDEA was aiding malicious activities
Google's threat team said that IPIDEA has become notorious for facilitating operation of several botnets the , including the China-based BADBOX 2.0

In July 2025, Google filed a lawsuit against 25 unnamed individuals or entities in China for allegedly operating the botnet and its associated residential proxy infrastructure. It also noted that proxy applications from IPIDEA not only routed traffic through the exit node device but also sent traffic to the device with the aim of compromising it, posing serious risks to consumers whose devices may have been included in the proxy network, either knowingly or unknowingly.
The proxy network that powered IPIDEA was a collection of several well-known residential proxy brands:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Ipidea (ipidea[.]io)
- 360 Proxy (360proxy[.]com)
- 922 Proxy (922proxy[.]com)
- ABC Proxy (abcproxy[.]com)
- Cherry Proxy (cherryproxy[.]com)
- Door VPN (doorvpn[.]com)
- Galleon VPN (galleonvpn[.]com)
- IP 2 World (ip2world[.]com)
- Luna Proxy (lunaproxy[.]com)
- PIA S5 Proxy (piaproxy[.]com)
- PY Proxy (pyproxy[.]com)
- Radish VPN (radishvpn[.]com)
- Tab Proxy (tabproxy[.]com)
“The same parties that control these brands also control various domains associated with Software Development Kits (SDKs) for residential proxies,” Google said. “These SDKs are not intended to be installed or run as standalone applications, but are intended to be integrated into existing applications.”
See also: SolarWinds: Critical RCE vulnerabilities in Web Help Desk
These SDKs are marketed to third-party developers as a way to monetize their Android, Windows, iOS, and WebOS applications. Developers who integrate the SDKs into their applications are paid by IPIDEA per download. This, in turn, turns a device that installs these applications into a node for the proxy network. The names of the SDKs controlled by IPIDEA administrators are listed below:
- Castar SDK (castarsdk[.]com)
- Earn SDK (earnsdk[.]io)
- Hex SDK (hexsdk[.]com)
- Packet SDK (packetsdk[.]com)
The SDKs have significant similarities in their command and control (C2) infrastructure and code structure. They follow a two-tier C2 system where infected devices contact a Tier One server to retrieve a set of Tier Two nodes to connect to. The application then initiates communication with the Tier Two server to periodically look for payloads to proxy through the device. Google’s analysis found that there are approximately 7,400 Tier Two servers.

In addition to proxy services, IPIDEA administrators have been found to control domains that offer free VPN tools, which are also designed to connect to the proxy network as an exit node that integrates either the Hex or Packet SDK. The names of the VPN services are as follows:
- Galleon VPN (galleonvpn[.]com)
- Radish VPN (radishvpn[.]com)
- Aman VPN (defunct)
To address the threat, Google said it has updated Google Play Protect to automatically warn users about apps containing IPIDEA code. For certified Android devices, the system will automatically remove these malicious apps and block any future attempts to install them.
