Shop for residential proxies long enough and two names keep surfacing: IP2World and PIA S5 Proxy. They look like separate premium brands. IP2World sells rotating residential IPs with clean docs and country targeting. PIA S5 Proxy sells SOCKS5 residential access with a name that sounds like a VPN you already trust. Pick one over the other and you feel like you made a choice. You did not. They are two storefronts wired to the same pool, run by the same operators, incorporated behind the same set of Hong Kong shell companies. The umbrella that ties them together is called IPIDEA, and on January 28, 2026 Google took the whole thing apart.
We told the news of that takedown in Google erased 13 proxy brands in one move: what Google did, which thirteen brands it named, and why one action could hit so many at once. This piece is the companion to that one. It is not the headline, it is the anatomy: how the cluster is actually built as a business, who sits behind IP2World and PIA S5 specifically, and how the pool underneath them was assembled out of other people's devices. We run a competing residential network, so we have a reason to get this right rather than sensational. The honest version is more useful than a conspiracy: it is a hub, a handful of shells, and a supply chain, and once you can see the shape, the marketing reads very differently.
One hub, many storefronts
The cluster is built hub and spoke. IPIDEA is the hub: the shared residential pool and the operators who run it. The brands are spokes: shop windows where you pay. Google's Threat Intelligence Group (GTIG, the team that studies nation-state and criminal hacking) named ten proxy storefronts on the proxy side, plus a set of free VPN apps that did a different job entirely, which we come back to below. Laid out from the hub, the "competitors" resolve into a product catalog.
The point of the map is not that there are a lot of brands. It is that the arrows all run to one place. When a buyer splits traffic across "two providers" for redundancy and picks IP2World and PIA S5, they are buying the same exit nodes twice. When a review site ranks IP2World against LunaProxy, it is refereeing a race between one operator's own runners. The brand layer exists to multiply the storefronts, spread the risk, and let the same pool be sold ten times to a buyer who thinks they are comparing rivals.
The five Hong Kong shells that sign the code
Here is how the brand layer stays deniable. The operators did not incorporate one company called IPIDEA that owns ten proxy sites. They incorporated a spread of small Hong Kong limited companies, and each one signs the software and stands behind a brand or two, so no single legal name sits over the whole cluster. Google identified the shells the hard way: from the cryptographic certificates used to sign the SDK code and the Windows binaries. A certificate is a signature, and the same signatures kept resolving to the same handful of Hong Kong entities.
| Hong Kong shell | Storefront it stands behind | What the address tells you |
|---|---|---|
| Hongkong Lingyun MDT Infotech Limited | IP2World | A Hong Kong company filing, no real operating office |
| Mars Brothers Limited | PIA S5 Proxy and LunaProxy | Registered in Shuen Wan, a New Territories area, not a commercial district |
| Prince Legend Limited | ABC Proxy | The Phoenix, 23 Luard Road, Wan Chai, a known virtual-office address |
| Firenet Limited | Code-signing entity, no public storefront named | Hong Kong |
| Datalabs Limited | Code-signing entity, no public storefront named | Hong Kong |
Read the second row twice, because it is the whole argument in one line. Mars Brothers Limited stands behind both PIA S5 Proxy and LunaProxy. Those are marketed as two separate residential providers, with their own sites, pricing pages and support. They are signed by one shell registered in a coastal residential area of the New Territories, the kind of address a real network operator does not use and a mailbox company does. That is not a smoking gun on its own. Shell addresses are legal and common. It becomes evidence when you stack it with everything else: the shared pool Google documented, and the shared plumbing underneath.
IP2World and PIA S5, up close
Take the two brands the task of buying actually puts in front of you.
IP2World presents as a mainstream residential and rotating-proxy service, the sort of brand that shows up in "best residential proxy" listicles. Its corporate trail runs to Hongkong Lingyun MDT Infotech Limited. Nothing about the storefront tells you it shares a pool with nine other names, because nothing is supposed to.
PIA S5 Proxy is more revealing, starting with the name. "PIA" echoes Private Internet Access, one of the best-known consumer VPNs, and buys a few seconds of misplaced confidence from anyone skimming a dozen tabs. There is no connection between the two. The "S5" is SOCKS5, the proxy protocol (a general-purpose relay that carries any TCP traffic, not just web requests). Behind the name sits Mars Brothers Limited, founded in 2022, registered in Kowloon and Shuen Wan, the same shell that stands behind LunaProxy. PIA S5 marketed itself hard as a cheap SOCKS5 residential pool, which is exactly what a botnet-sourced network is good at supplying in volume.
How do we know the two are one back-end and not just two brands with coincidentally offshore paperwork? The plumbing. In our own DNS checks, the cluster's domains sat on the same infrastructure: piaproxy.com, lunaproxy.com, pyproxy.com and ipidea.net all resolved through Alibaba's DNS service, the same nameserver family, which is the sort of shared operational detail independent competitors do not have in common. Google's court filing supplied the rest by naming all of them as one operation. Shared shell, shared DNS, shared pool, shared takedown. That is four overlaps, three documented by Google and one we checked ourselves, and independent rivals do not overlap four ways.
How the pool was actually built
A residential proxy is only ever as clean as the way its IPs were sourced, so the real question about IP2World or PIA S5 is not "how big is the pool," it is "whose devices are in it." For this cluster, the answer is documented, and it is not consented opt-in.
The pool was filled with SDKs. An SDK (software development kit) is a code package a developer drops into an app to add a feature. Here the "feature" was turning the user's device into someone else's proxy. Google tied four SDKs to IPIDEA, named Castar, Earn, Hex and Packet, and found they share so much code and command infrastructure that they trace back to one operation rather than four independent products. The developer who embedded one got paid. Castar's own pitch to app makers advertised payouts as high as roughly 500 dollars per thousand impressions, promised the code runs silently, and told developers the user would not notice. That payout is the engine of the whole cluster: a free flashlight app or game with a hundred thousand daily users becomes a steady income stream for its developer and a steady supply of fresh home IPs for IPIDEA, and the person holding the phone is never asked.
The free VPN apps in the cluster, Door VPN, Galleon VPN and Radish VPN, were not really products. They were the delivery vehicle: the way onto devices. A fourth name, Aman VPN, did not even need a download, because it shipped pre-installed on uncertified TV set-top boxes, the cheap streaming boxes people plug in without a second thought. The exit node was in the living room before the box was switched on. Google found the code across the full range of consumer hardware: more than 600 Android apps, 3,075 distinct Windows binaries, and smart-TV platforms including LG's webOS. That breadth is how a single operator could advertise millions of "real" IPs across ten storefronts. The pool was assembled from real people's phones, PCs and televisions, most of whom had no idea they were part of it.
The pool numbers that give the game away
The storefronts advertise their pool sizes loudly, and the numbers themselves are a tell once you line them up. Here is what four of the cluster's brands claim.
Treat every one of those numbers as marketing, not measurement, because vendors across this market inflate pool claims as a matter of routine. But grant them for a second and the arithmetic breaks. Four sibling brands, each claiming 80 to 200 million residential IPs, would add up to more than half a billion unique home addresses controlled by one operator, which would make IPIDEA several times larger than the entire legitimate residential-proxy industry combined. That is not possible, so one of two things is true: the numbers are wildly inflated, or the "separate" pools are the same pool counted over and over. Both are true at once. The overlapping, round, implausible claims are not four independent networks bragging. They are one network wearing four price tags. When you see a brand-new brand claiming a pool that would make it the biggest in the world, the size is the warning, not the selling point.
Why this cluster exists at all
IPIDEA did not invent this model, it inherited it. The residential-proxy-from-a-botnet business has a documented lineage, and 922Proxy, sitting right there in the cluster, did not even hide it: it marketed itself as the replacement for 911 S5, the botnet the FBI once called likely the largest ever, down to the echo in the number. We traced that whole chain, from 911 S5 through CloudRouter to the IPIDEA cluster, in what happened to 911 S5, and the Western mirror image of it, a Nasdaq-listed company accused of renting out hijacked smart TVs, in the NetNut botnet takedown. Different countries, different corporate wrappers, one product.
The pattern is not just anecdote, it is measured. In 2022, researchers published "An Extensive Study of Residential Proxies in China" at the ACM Conference on Computer and Communications Security, one of the field's top venues. Studying more than nine million residential proxy IPs, they found that over 80 percent of the Chinese ones had carried at least one malicious traffic flow in a single year, and that most were invisible to Western threat intelligence. IPIDEA is that finding with a storefront and a checkout page.
What it means if IP2World or PIA S5 is on your shortlist
Two things are true at once if your tooling pointed at either brand. First, the service is degraded or broken: the storefronts were taken to court on January 28, the Google accounts the network used to steer infected devices were disabled, and Play Protect is removing the SDK apps. Second, and more lasting, the IPs are burned. More than 550 threat-actor groups ran through this same pool in a single week, so to every fraud-detection system on the internet, your traffic has been sharing an address with theirs. Any account or scraper tied to it may already be flagged, and we walk through how that flagging works in how websites detect proxies.
The wrong move is to grab the nearest cheap "residential" replacement, because that is exactly how you land in the next cluster. The right move is to change the question you ask a provider.
- Ask how the pool is sourced, in plain words. A network built on consented, disclosed opt-in can say so directly. Vagueness is itself the answer.
- Distrust a pool that appeared overnight. You rent millions of residential IPs, you do not build them in a year. A brand-new name with a world-beating pool number rented that pool from somewhere.
- Look past the name. PIA S5 is not Private Internet Access and 360Proxy is not Qihoo 360. A friendly or borrowed name is marketing, not evidence.
- Verify the IPs you are handed. Our free proxy checker makes a real connection through a proxy and reports the exit location, the anonymity grade and the network the IP actually belongs to, so a hijacked or blacklisted address shows itself before you trust it.
Where HProxy fits
We wrote this for the same reason we wrote who owns your proxy provider: the sourcing question is the one a clean network welcomes and a dirty one dodges. HProxy is independent, not part of any cluster, and we would rather compete on being able to tell you where our residential IPs come from than on a headline pool number we cannot stand behind. Our residential proxies are $0.65/GB pay as you go with no KYC and a balance that does not expire, and you can inspect the network before you trust any of this: run the free proxy checker against anything, and browse the live free proxy list to see exactly what we show and how we label it. If you want the definition underneath all of this, what is a residential proxy covers why the sourcing is the product.
Sources
- Google Threat Intelligence Group, disruption of the IPIDEA residential proxy network (January 28, 2026): the named brands and domains, the five Hong Kong shell entities (Lingyun MDT, Mars Brothers, Prince Legend, Firenet, Datalabs) identified from code-signing certificates, the four SDKs (Castar, Earn, Hex, Packet) with Hex and Castar as one product, 600+ Android apps, 3,075 Windows binaries, LG webOS, set-top boxes and Aman VPN, and 550+ threat groups in a 7-day window
- Google, consumer-facing note on the IPIDEA action (storefront takedown, court action, Play Protect removal)
- Help Net Security, IPIDEA proxy network disrupted (January 29, 2026)
- The Hacker News, Google disrupts IPIDEA (January 2026)
- Cybernews, Smartproxy.org and IPIDEA botnet IP overlap (why a brand takedown does not end the network)
- Mingshuo Yang, Yunnan Yu et al., "An Extensive Study of Residential Proxies in China", ACM CCS 2022 (9M+ residential proxy IPs studied, 80%+ of Chinese ones carried malicious traffic in a year)
- KrebsOnSecurity, Treasury sanctions creators of the 911 S5 proxy botnet (the 911 S5 to CloudRouter to 922Proxy lineage)