On January 28, 2026, Google took down thirteen proxy brands at once. Not thirteen scattered scam sites: thirteen names that show up on real shortlists when people shop for residential proxies, among them 922Proxy, PIA S5 Proxy, IP2World, ABC Proxy and LunaProxy. Google's Threat Intelligence Group named all of them as a single operation it calls IPIDEA, took the storefronts to court, and started using Android's built-in Play Protect to pull the code that fed the network off people's devices. The reason one action could hit thirteen brands is the whole story: they were never really thirteen companies. They were one operation wearing thirteen logos, and the pool behind all of them was built, in large part, out of hijacked home devices.
We run a residential proxy network, so a case like this is close to home. A residential proxy is only ever as clean as the way its IPs were sourced, and IPIDEA is what the industry looks like when nobody asks that question until a takedown answers it for them. Here is what Google actually did, which thirteen brands it names, how ordinary phones and smart-TV boxes ended up in the pool, and what it changes if any of these names are on your shortlist.
What Google actually did on January 28, 2026
Google's Threat Intelligence Group (GTIG, the team that studies nation-state and criminal hacking) published its disruption of IPIDEA on January 28, 2026, with news coverage following the next day. This was not a quiet blog post. Google took the cluster's online storefronts to court so the operators cannot legally market or distribute the service, disabled the Google accounts the network used for command and control (the "C2," meaning the servers that direct infected devices), and turned on Play Protect, Android's built-in security, to warn about and remove apps that carry IPIDEA's code. Google named Lumen's Black Lotus Labs and other researchers as partners in the work.
The scale is the part worth sitting with. This was one of the larger residential proxy networks on the market, the kind that sells access to millions of "real" home IP addresses for scraping, ad verification and similar work, and Google counted a lot of criminal demand flowing through it.
On the device count, be precise, because the exact figure moves depending on who is counting. Google described the cleanup in the millions of Android devices; reporting on the operation put it closer to 9 million. Either way, the shape is the same: a pool numbering in the millions, made of other people's hardware, rented out by the gigabyte.
The 13 brands, and the one operator behind them
Here is why "thirteen brands, one takedown" is not a contradiction. Google's list is a mix of proxy storefronts and free VPN apps, and they split cleanly into two jobs. The proxy brands are the shop window, where you pay for access. The VPN brands are the way in, the free apps that quietly enrolled the exit nodes in the first place. Both halves answer to the same operators, who incorporated the pieces behind a set of Hong Kong shell companies so that no single name sits over the whole thing.
One operator, 13 brands
Google's January 28, 2026 disruption named all 13 as a single operation, incorporated behind Hong Kong shell companies. A fourteenth brand, Aman VPN, came pre-installed on uncertified TV set-top boxes.
Signed by five Hong Kong shells: Lingyun MDT Infotech, Prince Legend, Mars Brothers, Firenet and Datalabs
Sold to you as residential proxies
The storefronts. Same pool, same operator, different logos.
Shipped as free VPNs, the way onto devices
Free apps and pre-installed boxes that quietly enrolled the exit nodes.
Fed by four SDKs: Castar, Earn, Hex and Packet. Google found Hex and Castar are the same code, rebranded.
Laid out as a table, the same thirteen look less like competitors and more like a product catalog. The domains are Google's; the corporate and pool details come from tracing each brand's own filings and marketing.
| Brand | Domain | Sold as | What it traces to |
|---|---|---|---|
| Ipidea | ipidea.io | Residential proxies | The hub the cluster is named for |
| 922Proxy | 922proxy.com | Residential proxies | Marketed openly as the 911 S5 replacement |
| PIA S5 Proxy | piaproxy.com | SOCKS5 residential proxies | Mars Brothers Limited (Hong Kong), founded 2022 |
| IP2World | ip2world.com | Residential proxies | Hongkong Lingyun MDT Infotech Limited |
| ABC Proxy | abcproxy.com | Residential proxies | Prince Legend Limited, a Wan Chai shell address |
| LunaProxy | lunaproxy.com | Residential proxies | Mars Brothers Limited (Hong Kong) |
| 360Proxy | 360proxy.com | Residential proxies | Unrelated to Qihoo 360, the name is borrowed |
| Cherry Proxy | cherryproxy.com | Residential proxies | Claims 80M+ IPs, Hong Kong based |
| PyProxy | pyproxy.com | Residential proxies | A known Kowloon shell mailing address |
| TabProxy | tabproxy.com | Residential proxies | Claims 200M+ IPs |
| Door VPN | doorvpn.com | Free VPN | A delivery app for the SDKs |
| Galleon VPN | galleonvpn.com | Free VPN | A delivery app for the SDKs |
| Radish VPN | radishvpn.com | Free VPN | A delivery app for the SDKs |
Aman VPN is the fourteenth name. It did not need an app-store download at all, because it arrived pre-installed on uncertified TV set-top boxes, the cheap streaming boxes people plug in without a second thought. That is a supply-chain route: the exit node was in the living room before the box was ever switched on.
How a free app turned a smart TV into a proxy
The mechanism is worth understanding, because it is the same one behind nearly every botnet-sourced proxy pool. It runs on an SDK, a software development kit, which is just a code package a developer drops into an app to add a feature. Here the "feature" was turning the user's device into someone else's proxy. Google tied four SDKs to IPIDEA: Castar, Earn, Hex and Packet, and it found that Hex and Castar were the same product under two names.
The developer got paid. These SDKs were marketed to app makers as a way to monetize an app without ads, and Castar's own developer pitch advertised payouts of up to roughly 500 dollars per thousand installs, promising the code runs silently and the user will not notice. That is the engine. A free flashlight app, a free VPN, or a game with a hundred thousand daily users becomes a steady income stream for its developer and a steady supply of fresh home IPs for the network, and the person holding the phone is never asked. Once the SDK is installed, the device can quietly act as a residential proxy exit node, and every scrape, fake ad impression and login attempt a customer pushes through it comes out wearing that household's real IP address.
Google found the code across the full range of consumer hardware: more than 600 Android apps, 3,075 distinct Windows binaries, and, most telling, smart-TV platforms including LG's webOS. Security reporting has also tied the same infrastructure to other botnets such as BadBox 2.0. That breadth is why a single provider could offer millions of "real" IPs: the pool was assembled from real people's phones, PCs and televisions, most of whom had no idea they were part of it.
Why the brand names sound oddly familiar
Notice how many of these names lean on trust you have already given to someone else. 360Proxy shares its number with Qihoo 360, a large and legitimate Chinese cybersecurity company, and it is not owned by them: the resemblance is the point. PIA S5 Proxy echoes the initials of a well-known consumer VPN. ABC Proxy and Cherry Proxy reach for the friendliest, most generic words available. This is a deliberate pattern, not a coincidence. A name that borrows familiarity buys a few seconds of misplaced confidence, which is often all it takes for someone comparing a dozen tabs to assume a brand is bigger and safer than it is. When you see a proxy brand named after something you already trust, treat the name as marketing, not as evidence.
This is the 911 S5 pattern, playing out again
If IPIDEA feels like something you have read before, that is because you have. It is the newest link in a documented chain, and the chain matters more than any single brand in it.
One model, one arrest at a time: how the pool keeps coming back
911 S5 runs on roughly 19 million hijacked Windows PCs. The FBI later calls it likely the largest botnet ever.
911 S5 goes dark within days of KrebsOnSecurity naming its operator, Yunhe Wang.
CloudRouter reboots the same network. Researchers find reused 911 S5 components inside it.
Wang is arrested and sanctioned and the domains are seized. 922Proxy and the IPIDEA cluster move into the gap.
Google disrupts IPIDEA and its 13 brands. The pattern's biggest chapter so far, not its last.
The tell is 922Proxy itself, which did not even hide the lineage. It marketed itself as the replacement for 911 S5, right down to the number. We took the original apart in what happened to 911 S5, and the same shape shows up in the West too: the NetNut botnet takedown was a Nasdaq-listed company accused of renting out two million hijacked smart TVs. Different countries, different corporate wrappers, identical product: real consumer devices, turned into exit nodes, rented to whoever pays.
Are they actually gone?
Here is the honest part, and it is the part most takedown coverage skips. Google erased the storefronts, but it did not erase the network, and those are not the same thing. The domains carry warnings now, the lawsuits will slow the marketing, and Play Protect is pulling the apps. What does not vanish on takedown day is the infrastructure underneath: the millions of already-infected devices, the roughly 7,400 command servers that reassign themselves daily, the SDK code sitting in apps and boxes people have not updated, and the shell companies that can incorporate a fresh brand in an afternoon.
Security researchers put it plainly after the action: killing a brand is not the same as killing a network. The residential-proxy-from-a-botnet model has now survived 911 S5, survived CloudRouter, and will very likely outlive the IPIDEA name too, because the demand did not go anywhere and the supply is measured in millions of devices that are still plugged in. Expect a successor, probably within months, probably under a name that sounds trustworthy. That is not cynicism. It is the pattern the timeline above keeps drawing.
What to do if you bought from any of these brands
Two things are true at once if your tooling pointed at one of these thirteen. First, the service is degraded or broken: the storefronts are seized and the network is disrupted, so the endpoints you relied on stopped behaving on January 28. Second, and more lasting, the IPs you were renting are burned. More than 550 threat-actor groups ran through this same pool in a single week, so to every fraud-detection system on the internet, your traffic has been sharing an address with theirs. Any account or scraper tied to that traffic may already be flagged, and we walk through how that flagging works in how websites detect proxies.
The wrong move is to grab the nearest cheap "residential" replacement, because that is exactly how you land in the next IPIDEA. The right move is to change the question you ask a provider, and our how to vet a proxy provider guide is that question list.
- Ask how the pool is sourced, in plain words. A provider that sources residential IPs through consented, disclosed opt-in can say so directly. Vagueness is itself the answer.
- Be suspicious of "free residential." Honestly sourced residential bandwidth costs real money. When it is free, the device owner is usually the one paying without knowing it, which is the whole trap we take apart in free residential proxies.
- Verify the IPs you are handed. Our free proxy checker makes a real connection through a proxy and reports the exit location, the anonymity grade, and the network the IP actually belongs to, so a hijacked or blacklisted address shows itself before you trust it.
- Look up the brand's ties before you buy. A brand new, friendly-sounding name with an offshore shell behind it and a pool size that would make it the biggest in the world is the exact profile on this list.
Where HProxy fits
We wrote this for the same reason we wrote who owns your proxy provider: the sourcing question is the one a clean provider should welcome and a dirty one will dodge. HProxy is independent, and we would rather compete on being able to tell you where our residential IPs come from than on a headline pool number we cannot stand behind. Our residential proxies are $0.65/GB pay as you go with no KYC and a balance that does not expire, and you can inspect the network first: run the free proxy checker against anything, and browse the live free proxy list to see exactly what we show and how we label it. If you want the definition underneath all of this, what is a residential proxy covers where the value really comes from, and why the sourcing is the product.
Sources
- Google Threat Intelligence Group, disruption of the IPIDEA residential proxy network (January 28, 2026): the 13 brands and domains, the five Hong Kong shell entities, the four SDKs (Castar, Earn, Hex, Packet), 600+ Android apps, 3,075 Windows PE hashes, 550+ threat groups in a 7-day window, ~7,400 tier-2 C2 servers, set-top boxes and Aman VPN
- Google, consumer-facing note on the IPIDEA action (storefront takedown, court action, Play Protect removal)
- Help Net Security, IPIDEA proxy network disrupted (January 29, 2026)
- The Hacker News, Google disrupts IPIDEA (January 2026)
- Cybernews, Smartproxy.org and IPIDEA botnet IP overlap (why a brand takedown does not end the network)
- KrebsOnSecurity, Treasury sanctions creators of the 911 S5 proxy botnet (911 S5 to CloudRouter to 922Proxy lineage, Yunhe Wang)
- U.S. Department of the Treasury, sanctions announcement on the 911 S5 operators (May 2024)