Comparison

Google Erased 13 Proxy Brands in One Move: Inside the IPIDEA Takedown

Google's 2026 takedown named 13 proxy brands under IPIDEA: 922Proxy, PIA S5, IP2World and more, built on hijacked home devices. What it means for buyers.

HProxy Team · ·Updated July 21, 2026 ·12 min read
HProxy. Comparison

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.65/GB, pay as you go.

See plans & pricing

On January 28, 2026, Google took down thirteen proxy brands at once. Not thirteen scattered scam sites: thirteen names that show up on real shortlists when people shop for residential proxies, among them 922Proxy, PIA S5 Proxy, IP2World, ABC Proxy and LunaProxy. Google's Threat Intelligence Group named all of them as a single operation it calls IPIDEA, took the storefronts to court, and started using Android's built-in Play Protect to pull the code that fed the network off people's devices. The reason one action could hit thirteen brands is the whole story: they were never really thirteen companies. They were one operation wearing thirteen logos, and the pool behind all of them was built, in large part, out of hijacked home devices.

We run a residential proxy network, so a case like this is close to home. A residential proxy is only ever as clean as the way its IPs were sourced, and IPIDEA is what the industry looks like when nobody asks that question until a takedown answers it for them. Here is what Google actually did, which thirteen brands it names, how ordinary phones and smart-TV boxes ended up in the pool, and what it changes if any of these names are on your shortlist.

What Google actually did on January 28, 2026

Google's Threat Intelligence Group (GTIG, the team that studies nation-state and criminal hacking) published its disruption of IPIDEA on January 28, 2026, with news coverage following the next day. This was not a quiet blog post. Google took the cluster's online storefronts to court so the operators cannot legally market or distribute the service, disabled the Google accounts the network used for command and control (the "C2," meaning the servers that direct infected devices), and turned on Play Protect, Android's built-in security, to warn about and remove apps that carry IPIDEA's code. Google named Lumen's Black Lotus Labs and other researchers as partners in the work.

The scale is the part worth sitting with. This was one of the larger residential proxy networks on the market, the kind that sells access to millions of "real" home IP addresses for scraping, ad verification and similar work, and Google counted a lot of criminal demand flowing through it.

On the device count, be precise, because the exact figure moves depending on who is counting. Google described the cleanup in the millions of Android devices; reporting on the operation put it closer to 9 million. Either way, the shape is the same: a pool numbering in the millions, made of other people's hardware, rented out by the gigabyte.

The 13 brands, and the one operator behind them

Here is why "thirteen brands, one takedown" is not a contradiction. Google's list is a mix of proxy storefronts and free VPN apps, and they split cleanly into two jobs. The proxy brands are the shop window, where you pay for access. The VPN brands are the way in, the free apps that quietly enrolled the exit nodes in the first place. Both halves answer to the same operators, who incorporated the pieces behind a set of Hong Kong shell companies so that no single name sits over the whole thing.

One operator, 13 brands

Google's January 28, 2026 disruption named all 13 as a single operation, incorporated behind Hong Kong shell companies. A fourteenth brand, Aman VPN, came pre-installed on uncertified TV set-top boxes.

IPIDEAthe hub the whole cluster runs on

Signed by five Hong Kong shells: Lingyun MDT Infotech, Prince Legend, Mars Brothers, Firenet and Datalabs

Sold to you as residential proxies

The storefronts. Same pool, same operator, different logos.

Ipideaipidea.io
922Proxythe 911 S5 heir
PIA S5 ProxyMars Brothers
IP2WorldLingyun MDT
ABC ProxyPrince Legend
LunaProxyMars Brothers
360Proxynot Qihoo 360
Cherry Proxy
PyProxy
TabProxy

Shipped as free VPNs, the way onto devices

Free apps and pre-installed boxes that quietly enrolled the exit nodes.

Door VPN
Galleon VPN
Radish VPN
Aman VPNpre-installed on set-top boxes

Fed by four SDKs: Castar, Earn, Hex and Packet. Google found Hex and Castar are the same code, rebranded.

Laid out as a table, the same thirteen look less like competitors and more like a product catalog. The domains are Google's; the corporate and pool details come from tracing each brand's own filings and marketing.

BrandDomainSold asWhat it traces to
Ipideaipidea.ioResidential proxiesThe hub the cluster is named for
922Proxy922proxy.comResidential proxiesMarketed openly as the 911 S5 replacement
PIA S5 Proxypiaproxy.comSOCKS5 residential proxiesMars Brothers Limited (Hong Kong), founded 2022
IP2Worldip2world.comResidential proxiesHongkong Lingyun MDT Infotech Limited
ABC Proxyabcproxy.comResidential proxiesPrince Legend Limited, a Wan Chai shell address
LunaProxylunaproxy.comResidential proxiesMars Brothers Limited (Hong Kong)
360Proxy360proxy.comResidential proxiesUnrelated to Qihoo 360, the name is borrowed
Cherry Proxycherryproxy.comResidential proxiesClaims 80M+ IPs, Hong Kong based
PyProxypyproxy.comResidential proxiesA known Kowloon shell mailing address
TabProxytabproxy.comResidential proxiesClaims 200M+ IPs
Door VPNdoorvpn.comFree VPNA delivery app for the SDKs
Galleon VPNgalleonvpn.comFree VPNA delivery app for the SDKs
Radish VPNradishvpn.comFree VPNA delivery app for the SDKs

Aman VPN is the fourteenth name. It did not need an app-store download at all, because it arrived pre-installed on uncertified TV set-top boxes, the cheap streaming boxes people plug in without a second thought. That is a supply-chain route: the exit node was in the living room before the box was ever switched on.

How a free app turned a smart TV into a proxy

The mechanism is worth understanding, because it is the same one behind nearly every botnet-sourced proxy pool. It runs on an SDK, a software development kit, which is just a code package a developer drops into an app to add a feature. Here the "feature" was turning the user's device into someone else's proxy. Google tied four SDKs to IPIDEA: Castar, Earn, Hex and Packet, and it found that Hex and Castar were the same product under two names.

The developer got paid. These SDKs were marketed to app makers as a way to monetize an app without ads, and Castar's own developer pitch advertised payouts of up to roughly 500 dollars per thousand installs, promising the code runs silently and the user will not notice. That is the engine. A free flashlight app, a free VPN, or a game with a hundred thousand daily users becomes a steady income stream for its developer and a steady supply of fresh home IPs for the network, and the person holding the phone is never asked. Once the SDK is installed, the device can quietly act as a residential proxy exit node, and every scrape, fake ad impression and login attempt a customer pushes through it comes out wearing that household's real IP address.

Google found the code across the full range of consumer hardware: more than 600 Android apps, 3,075 distinct Windows binaries, and, most telling, smart-TV platforms including LG's webOS. Security reporting has also tied the same infrastructure to other botnets such as BadBox 2.0. That breadth is why a single provider could offer millions of "real" IPs: the pool was assembled from real people's phones, PCs and televisions, most of whom had no idea they were part of it.

Why the brand names sound oddly familiar

Notice how many of these names lean on trust you have already given to someone else. 360Proxy shares its number with Qihoo 360, a large and legitimate Chinese cybersecurity company, and it is not owned by them: the resemblance is the point. PIA S5 Proxy echoes the initials of a well-known consumer VPN. ABC Proxy and Cherry Proxy reach for the friendliest, most generic words available. This is a deliberate pattern, not a coincidence. A name that borrows familiarity buys a few seconds of misplaced confidence, which is often all it takes for someone comparing a dozen tabs to assume a brand is bigger and safer than it is. When you see a proxy brand named after something you already trust, treat the name as marketing, not as evidence.

This is the 911 S5 pattern, playing out again

If IPIDEA feels like something you have read before, that is because you have. It is the newest link in a documented chain, and the chain matters more than any single brand in it.

One model, one arrest at a time: how the pool keeps coming back

2014 to 2022

911 S5 runs on roughly 19 million hijacked Windows PCs. The FBI later calls it likely the largest botnet ever.

July 2022

911 S5 goes dark within days of KrebsOnSecurity naming its operator, Yunhe Wang.

2022 to 2024

CloudRouter reboots the same network. Researchers find reused 911 S5 components inside it.

May 2024

Wang is arrested and sanctioned and the domains are seized. 922Proxy and the IPIDEA cluster move into the gap.

January 28, 2026

Google disrupts IPIDEA and its 13 brands. The pattern's biggest chapter so far, not its last.

The tell is 922Proxy itself, which did not even hide the lineage. It marketed itself as the replacement for 911 S5, right down to the number. We took the original apart in what happened to 911 S5, and the same shape shows up in the West too: the NetNut botnet takedown was a Nasdaq-listed company accused of renting out two million hijacked smart TVs. Different countries, different corporate wrappers, identical product: real consumer devices, turned into exit nodes, rented to whoever pays.

Are they actually gone?

Here is the honest part, and it is the part most takedown coverage skips. Google erased the storefronts, but it did not erase the network, and those are not the same thing. The domains carry warnings now, the lawsuits will slow the marketing, and Play Protect is pulling the apps. What does not vanish on takedown day is the infrastructure underneath: the millions of already-infected devices, the roughly 7,400 command servers that reassign themselves daily, the SDK code sitting in apps and boxes people have not updated, and the shell companies that can incorporate a fresh brand in an afternoon.

Security researchers put it plainly after the action: killing a brand is not the same as killing a network. The residential-proxy-from-a-botnet model has now survived 911 S5, survived CloudRouter, and will very likely outlive the IPIDEA name too, because the demand did not go anywhere and the supply is measured in millions of devices that are still plugged in. Expect a successor, probably within months, probably under a name that sounds trustworthy. That is not cynicism. It is the pattern the timeline above keeps drawing.

What to do if you bought from any of these brands

Two things are true at once if your tooling pointed at one of these thirteen. First, the service is degraded or broken: the storefronts are seized and the network is disrupted, so the endpoints you relied on stopped behaving on January 28. Second, and more lasting, the IPs you were renting are burned. More than 550 threat-actor groups ran through this same pool in a single week, so to every fraud-detection system on the internet, your traffic has been sharing an address with theirs. Any account or scraper tied to that traffic may already be flagged, and we walk through how that flagging works in how websites detect proxies.

The wrong move is to grab the nearest cheap "residential" replacement, because that is exactly how you land in the next IPIDEA. The right move is to change the question you ask a provider, and our how to vet a proxy provider guide is that question list.

  • Ask how the pool is sourced, in plain words. A provider that sources residential IPs through consented, disclosed opt-in can say so directly. Vagueness is itself the answer.
  • Be suspicious of "free residential." Honestly sourced residential bandwidth costs real money. When it is free, the device owner is usually the one paying without knowing it, which is the whole trap we take apart in free residential proxies.
  • Verify the IPs you are handed. Our free proxy checker makes a real connection through a proxy and reports the exit location, the anonymity grade, and the network the IP actually belongs to, so a hijacked or blacklisted address shows itself before you trust it.
  • Look up the brand's ties before you buy. A brand new, friendly-sounding name with an offshore shell behind it and a pool size that would make it the biggest in the world is the exact profile on this list.

Where HProxy fits

We wrote this for the same reason we wrote who owns your proxy provider: the sourcing question is the one a clean provider should welcome and a dirty one will dodge. HProxy is independent, and we would rather compete on being able to tell you where our residential IPs come from than on a headline pool number we cannot stand behind. Our residential proxies are $0.65/GB pay as you go with no KYC and a balance that does not expire, and you can inspect the network first: run the free proxy checker against anything, and browse the live free proxy list to see exactly what we show and how we label it. If you want the definition underneath all of this, what is a residential proxy covers where the value really comes from, and why the sourcing is the product.

Sources

Frequently asked questions

What is IPIDEA?
IPIDEA is a residential proxy operation, and researchers and Google use the name for a cluster of 13 proxy and VPN brands run by the same actors, including 922Proxy, PIA S5 Proxy, IP2World, ABC Proxy and LunaProxy. On January 28, 2026, Google's Threat Intelligence Group disrupted it, took the storefronts to court, and began using Play Protect to remove the apps that fed it. Google described it as one of the largest malicious proxy networks in the world, built largely from hijacked home devices.
Which proxy brands did Google take down in the IPIDEA action?
Google named 13: Ipidea (ipidea.io), 360Proxy, 922Proxy, ABC Proxy, Cherry Proxy, IP2World, LunaProxy, PIA S5 Proxy, PyProxy and TabProxy on the proxy side, plus three VPN brands, Door VPN, Galleon VPN and Radish VPN. A fourteenth brand, Aman VPN, came pre-installed on uncertified TV set-top boxes as another way onto devices. All of them trace back to the same operators through a set of Hong Kong shell companies.
Is it safe to use 922Proxy, PIA S5, IP2World or the other brands now?
Treat them as burned. Setting aside the legal and ethical problem of a pool allegedly built from hijacked devices, Google says more than 550 separate threat-actor groups from China, North Korea, Iran and Russia ran traffic through this network in a single week in January 2026. Any IP you rent there shares its reputation with that traffic, so fraud-detection systems flag it before your request lands. The storefronts were also taken to court and the SDKs are being removed from devices by Play Protect.
How did IPIDEA turn ordinary devices into proxies?
Through bundled SDKs, which are code packages a developer drops into an app. Google tied four to the network: Castar, Earn, Hex and Packet. A developer added one to a free app or VPN in exchange for payment, and once installed the code quietly turned the phone, PC or smart-TV box into a residential proxy exit node. Google found the SDKs in more than 600 Android apps and 3,075 Windows binaries, and on uncertified set-top boxes that shipped with the payload already inside.
Are these proxy brands really gone for good?
No, and that is the honest catch. Google took down the storefronts, sued to stop marketing and distribution, and is removing the SDK apps, but a brand is not a network. The infected devices, the shell companies, and the SDK code already in the wild do not disappear because a domain does. The residential-proxy-from-a-botnet model has survived every prior takedown by re-emerging under a new name, so the useful move is not to chase the next cheap brand but to change how you judge a provider.
How do I know my own residential proxies are not sourced like this?
Ask the provider how the pool is sourced and treat a vague answer as the answer. Consented, disclosed opt-in is the standard to look for, and free residential almost always means someone's device is the unwitting supplier. You can also run any IP you are given through a proxy checker to see the real network behind it and whether it already carries a bad reputation.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires.

47M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup