Google Dismantles World’s Largest IPIDEA Residential Proxy Network In Major Takedown

Google Threat Intelligence Group (GTIG) led a major operation this week to disrupt IPIDEA, identified as the world’s largest residential proxy network.

This network powered cybercrime, espionage, and botnets by hijacking millions of consumer devices worldwide.

IPIDEA routed malicious traffic through residential IP addresses from everyday users’ devices. Attackers used these proxies to hide activities like password sprays, SaaS breaches, and infrastructure hacks.

GTIG tracked over 550 threat groups from China, North Korea, Iran, and Russia exploiting IPIDEA exit nodes in just one week this January.

The takedown involved three key actions. First, Google seized domains controlling proxy traffic and device enrollment.

Second, GTIG shared intelligence on IPIDEA’s SDKs with platforms, law enforcement, and researchers for broad enforcement.

These SDKs embedded in apps silently turned devices into exit nodes. Third, Google Play Protect now detects and blocks IPIDEA-laden apps on Android, warning users and preventing installs.

Results hit hard. Google estimates millions fewer devices available to IPIDEA operators. Reseller agreements mean impacts ripple to affiliates, shrinking the shared proxy pool. GTIG’s analysis showed IPIDEA fueled botnets like BadBox 2.0, Aisuru, and Kimwolf.

Residential proxies differ from data center ones by using real ISP-assigned IPs from homes and small businesses.

Operators infect devices via trojanized apps, preloaded malware on cheap hardware like set-top boxes, or “bandwidth sharing” lures.

Users risk IP blacklisting, network exposure, and inbound attacks as traffic flows through their gear.

IPIDEA masked 13 brands: 360 Proxy, 922 Proxy, ABC Proxy, Cherry Proxy, Door VPN, Galleon VPN, IP2World, Ipidea, Luna Proxy, PIA S5 Proxy, PY Proxy, Radish VPN, and Tab Proxy.

Advertising from PacketSDK, part of the IPIDEA proxy network (Source: Google Cloud)

All shared backend control. SDKs like Castar, Earn, Hex, and Packet drove growth, marketed to developers for “monetization” per download.

These SDKs worked across Android, Windows, iOS, and WebOS. Apps hid proxy code behind utilities, games, or VPNs. GTIG found over 600 Android apps and 3,075 Windows binaries linking to IPIDEA domains.

The network used a two-tier C2 system. Tier One domains handled initial check-ins with device info like OS, serial, and keys. Responses listed Tier Two IPs for task polling.

Devices sent JSON payloads to connect ports, received proxy jobs like “proxy www.google.com:443,” then relayed unmodified traffic.

Two-tier C2 system (Source: Google Cloud)

Infrastructure overlapped heavily. PacketSDK used api-seed.packetsdk.[xyz|net|io]. CastarSDK hit dispatch1.hexsdk.com and hashed domains.

EarnSDK tied to BadBox domains like holadns.com. All funneled to ~7,400 shared Tier Two servers globally.

GTIG confirmed risks. Proxy apps scanned local networks, exposed home devices to the internet, and bypassed firewalls. Many apps skipped consent disclosures.

Partners amplified the blow. Cloudflare blocked domain resolution. Spur and Lumen’s Black Lotus Labs aided scope analysis. Google took down marketing sites and enforced Play policies.

CVE and IOC Table

TypeIndicatorDescription
Domainpacketsdk.ioPacketSDK Tier One C2
Domainhexsdk.comHexSDK redirects to Castar
Domain0aa0cf0637d66c0d.comEarnSDK Tier One
SHA256aef34f14456358db91840c416e55acc7d10185ff2beb362ea24697d7cdad321fPacket SDK DLL
SHA256b0726bdd53083968870d0b147b72dad422d6d04f27cd52a7891d038ee83aef5bAPK with Packet SDK
SHA25659cbdecfc01eba859d12fbeb48f96fe3fe841ac1aafa6bd38eff92f0dcfd4554Radish VPN EXE
CertHONGKONG LINGYUN MDT INFOTECH LIMITEDSigned malware cert

Google urges caution on “share bandwidth” apps and unverified hardware. Stick to certified Android devices with Play Protect. Platforms must vet SDKs; providers prove ethical sourcing.

This strike exposes residential proxies as a gray market enabling global threats. Industry collaboration is key to shrink their footprint.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories