Google Threat Intelligence Group (GTIG) led a major operation this week to disrupt IPIDEA, identified as the world’s largest residential proxy network.
This network powered cybercrime, espionage, and botnets by hijacking millions of consumer devices worldwide.
IPIDEA routed malicious traffic through residential IP addresses from everyday users’ devices. Attackers used these proxies to hide activities like password sprays, SaaS breaches, and infrastructure hacks.
GTIG tracked over 550 threat groups from China, North Korea, Iran, and Russia exploiting IPIDEA exit nodes in just one week this January.
The takedown involved three key actions. First, Google seized domains controlling proxy traffic and device enrollment.
Second, GTIG shared intelligence on IPIDEA’s SDKs with platforms, law enforcement, and researchers for broad enforcement.
These SDKs embedded in apps silently turned devices into exit nodes. Third, Google Play Protect now detects and blocks IPIDEA-laden apps on Android, warning users and preventing installs.
Results hit hard. Google estimates millions fewer devices available to IPIDEA operators. Reseller agreements mean impacts ripple to affiliates, shrinking the shared proxy pool. GTIG’s analysis showed IPIDEA fueled botnets like BadBox 2.0, Aisuru, and Kimwolf.
Residential proxies differ from data center ones by using real ISP-assigned IPs from homes and small businesses.
Operators infect devices via trojanized apps, preloaded malware on cheap hardware like set-top boxes, or “bandwidth sharing” lures.
Users risk IP blacklisting, network exposure, and inbound attacks as traffic flows through their gear.
IPIDEA masked 13 brands: 360 Proxy, 922 Proxy, ABC Proxy, Cherry Proxy, Door VPN, Galleon VPN, IP2World, Ipidea, Luna Proxy, PIA S5 Proxy, PY Proxy, Radish VPN, and Tab Proxy.

All shared backend control. SDKs like Castar, Earn, Hex, and Packet drove growth, marketed to developers for “monetization” per download.
These SDKs worked across Android, Windows, iOS, and WebOS. Apps hid proxy code behind utilities, games, or VPNs. GTIG found over 600 Android apps and 3,075 Windows binaries linking to IPIDEA domains.
The network used a two-tier C2 system. Tier One domains handled initial check-ins with device info like OS, serial, and keys. Responses listed Tier Two IPs for task polling.
Devices sent JSON payloads to connect ports, received proxy jobs like “proxy www.google.com:443,” then relayed unmodified traffic.
.webp)
Infrastructure overlapped heavily. PacketSDK used api-seed.packetsdk.[xyz|net|io]. CastarSDK hit dispatch1.hexsdk.com and hashed domains.
EarnSDK tied to BadBox domains like holadns.com. All funneled to ~7,400 shared Tier Two servers globally.
GTIG confirmed risks. Proxy apps scanned local networks, exposed home devices to the internet, and bypassed firewalls. Many apps skipped consent disclosures.
Partners amplified the blow. Cloudflare blocked domain resolution. Spur and Lumen’s Black Lotus Labs aided scope analysis. Google took down marketing sites and enforced Play policies.
CVE and IOC Table
| Type | Indicator | Description |
|---|---|---|
| Domain | packetsdk.io | PacketSDK Tier One C2 |
| Domain | hexsdk.com | HexSDK redirects to Castar |
| Domain | 0aa0cf0637d66c0d.com | EarnSDK Tier One |
| SHA256 | aef34f14456358db91840c416e55acc7d10185ff2beb362ea24697d7cdad321f | Packet SDK DLL |
| SHA256 | b0726bdd53083968870d0b147b72dad422d6d04f27cd52a7891d038ee83aef5b | APK with Packet SDK |
| SHA256 | 59cbdecfc01eba859d12fbeb48f96fe3fe841ac1aafa6bd38eff92f0dcfd4554 | Radish VPN EXE |
| Cert | HONGKONG LINGYUN MDT INFOTECH LIMITED | Signed malware cert |
Google urges caution on “share bandwidth” apps and unverified hardware. Stick to certified Android devices with Play Protect. Platforms must vet SDKs; providers prove ethical sourcing.
This strike exposes residential proxies as a gray market enabling global threats. Industry collaboration is key to shrink their footprint.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.