Comparison

Inside the IPIDEA Cluster: How IP2World and PIA S5 Proxy Share One Hidden Network

IPIDEA runs IP2World, PIA S5 Proxy and a dozen storefronts on one pool through Hong Kong shells. Here is the shared infrastructure and how it was built.

HProxy Team · ·Updated July 21, 2026 ·12 min read
HProxy. Comparison

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.65/GB, pay as you go.

See plans & pricing

Shop for residential proxies long enough and two names keep surfacing: IP2World and PIA S5 Proxy. They look like separate premium brands. IP2World sells rotating residential IPs with clean docs and country targeting. PIA S5 Proxy sells SOCKS5 residential access with a name that sounds like a VPN you already trust. Pick one over the other and you feel like you made a choice. You did not. They are two storefronts wired to the same pool, run by the same operators, incorporated behind the same set of Hong Kong shell companies. The umbrella that ties them together is called IPIDEA, and on January 28, 2026 Google took the whole thing apart.

We told the news of that takedown in Google erased 13 proxy brands in one move: what Google did, which thirteen brands it named, and why one action could hit so many at once. This piece is the companion to that one. It is not the headline, it is the anatomy: how the cluster is actually built as a business, who sits behind IP2World and PIA S5 specifically, and how the pool underneath them was assembled out of other people's devices. We run a competing residential network, so we have a reason to get this right rather than sensational. The honest version is more useful than a conspiracy: it is a hub, a handful of shells, and a supply chain, and once you can see the shape, the marketing reads very differently.

One hub, many storefronts

The cluster is built hub and spoke. IPIDEA is the hub: the shared residential pool and the operators who run it. The brands are spokes: shop windows where you pay. Google's Threat Intelligence Group (GTIG, the team that studies nation-state and criminal hacking) named ten proxy storefronts on the proxy side, plus a set of free VPN apps that did a different job entirely, which we come back to below. Laid out from the hub, the "competitors" resolve into a product catalog.

The point of the map is not that there are a lot of brands. It is that the arrows all run to one place. When a buyer splits traffic across "two providers" for redundancy and picks IP2World and PIA S5, they are buying the same exit nodes twice. When a review site ranks IP2World against LunaProxy, it is refereeing a race between one operator's own runners. The brand layer exists to multiply the storefronts, spread the risk, and let the same pool be sold ten times to a buyer who thinks they are comparing rivals.

The five Hong Kong shells that sign the code

Here is how the brand layer stays deniable. The operators did not incorporate one company called IPIDEA that owns ten proxy sites. They incorporated a spread of small Hong Kong limited companies, and each one signs the software and stands behind a brand or two, so no single legal name sits over the whole cluster. Google identified the shells the hard way: from the cryptographic certificates used to sign the SDK code and the Windows binaries. A certificate is a signature, and the same signatures kept resolving to the same handful of Hong Kong entities.

Hong Kong shellStorefront it stands behindWhat the address tells you
Hongkong Lingyun MDT Infotech LimitedIP2WorldA Hong Kong company filing, no real operating office
Mars Brothers LimitedPIA S5 Proxy and LunaProxyRegistered in Shuen Wan, a New Territories area, not a commercial district
Prince Legend LimitedABC ProxyThe Phoenix, 23 Luard Road, Wan Chai, a known virtual-office address
Firenet LimitedCode-signing entity, no public storefront namedHong Kong
Datalabs LimitedCode-signing entity, no public storefront namedHong Kong

Read the second row twice, because it is the whole argument in one line. Mars Brothers Limited stands behind both PIA S5 Proxy and LunaProxy. Those are marketed as two separate residential providers, with their own sites, pricing pages and support. They are signed by one shell registered in a coastal residential area of the New Territories, the kind of address a real network operator does not use and a mailbox company does. That is not a smoking gun on its own. Shell addresses are legal and common. It becomes evidence when you stack it with everything else: the shared pool Google documented, and the shared plumbing underneath.

IP2World and PIA S5, up close

Take the two brands the task of buying actually puts in front of you.

IP2World presents as a mainstream residential and rotating-proxy service, the sort of brand that shows up in "best residential proxy" listicles. Its corporate trail runs to Hongkong Lingyun MDT Infotech Limited. Nothing about the storefront tells you it shares a pool with nine other names, because nothing is supposed to.

PIA S5 Proxy is more revealing, starting with the name. "PIA" echoes Private Internet Access, one of the best-known consumer VPNs, and buys a few seconds of misplaced confidence from anyone skimming a dozen tabs. There is no connection between the two. The "S5" is SOCKS5, the proxy protocol (a general-purpose relay that carries any TCP traffic, not just web requests). Behind the name sits Mars Brothers Limited, founded in 2022, registered in Kowloon and Shuen Wan, the same shell that stands behind LunaProxy. PIA S5 marketed itself hard as a cheap SOCKS5 residential pool, which is exactly what a botnet-sourced network is good at supplying in volume.

How do we know the two are one back-end and not just two brands with coincidentally offshore paperwork? The plumbing. In our own DNS checks, the cluster's domains sat on the same infrastructure: piaproxy.com, lunaproxy.com, pyproxy.com and ipidea.net all resolved through Alibaba's DNS service, the same nameserver family, which is the sort of shared operational detail independent competitors do not have in common. Google's court filing supplied the rest by naming all of them as one operation. Shared shell, shared DNS, shared pool, shared takedown. That is four overlaps, three documented by Google and one we checked ourselves, and independent rivals do not overlap four ways.

How the pool was actually built

A residential proxy is only ever as clean as the way its IPs were sourced, so the real question about IP2World or PIA S5 is not "how big is the pool," it is "whose devices are in it." For this cluster, the answer is documented, and it is not consented opt-in.

The pool was filled with SDKs. An SDK (software development kit) is a code package a developer drops into an app to add a feature. Here the "feature" was turning the user's device into someone else's proxy. Google tied four SDKs to IPIDEA, named Castar, Earn, Hex and Packet, and found they share so much code and command infrastructure that they trace back to one operation rather than four independent products. The developer who embedded one got paid. Castar's own pitch to app makers advertised payouts as high as roughly 500 dollars per thousand impressions, promised the code runs silently, and told developers the user would not notice. That payout is the engine of the whole cluster: a free flashlight app or game with a hundred thousand daily users becomes a steady income stream for its developer and a steady supply of fresh home IPs for IPIDEA, and the person holding the phone is never asked.

The free VPN apps in the cluster, Door VPN, Galleon VPN and Radish VPN, were not really products. They were the delivery vehicle: the way onto devices. A fourth name, Aman VPN, did not even need a download, because it shipped pre-installed on uncertified TV set-top boxes, the cheap streaming boxes people plug in without a second thought. The exit node was in the living room before the box was switched on. Google found the code across the full range of consumer hardware: more than 600 Android apps, 3,075 distinct Windows binaries, and smart-TV platforms including LG's webOS. That breadth is how a single operator could advertise millions of "real" IPs across ten storefronts. The pool was assembled from real people's phones, PCs and televisions, most of whom had no idea they were part of it.

The pool numbers that give the game away

The storefronts advertise their pool sizes loudly, and the numbers themselves are a tell once you line them up. Here is what four of the cluster's brands claim.

Treat every one of those numbers as marketing, not measurement, because vendors across this market inflate pool claims as a matter of routine. But grant them for a second and the arithmetic breaks. Four sibling brands, each claiming 80 to 200 million residential IPs, would add up to more than half a billion unique home addresses controlled by one operator, which would make IPIDEA several times larger than the entire legitimate residential-proxy industry combined. That is not possible, so one of two things is true: the numbers are wildly inflated, or the "separate" pools are the same pool counted over and over. Both are true at once. The overlapping, round, implausible claims are not four independent networks bragging. They are one network wearing four price tags. When you see a brand-new brand claiming a pool that would make it the biggest in the world, the size is the warning, not the selling point.

Why this cluster exists at all

IPIDEA did not invent this model, it inherited it. The residential-proxy-from-a-botnet business has a documented lineage, and 922Proxy, sitting right there in the cluster, did not even hide it: it marketed itself as the replacement for 911 S5, the botnet the FBI once called likely the largest ever, down to the echo in the number. We traced that whole chain, from 911 S5 through CloudRouter to the IPIDEA cluster, in what happened to 911 S5, and the Western mirror image of it, a Nasdaq-listed company accused of renting out hijacked smart TVs, in the NetNut botnet takedown. Different countries, different corporate wrappers, one product.

The pattern is not just anecdote, it is measured. In 2022, researchers published "An Extensive Study of Residential Proxies in China" at the ACM Conference on Computer and Communications Security, one of the field's top venues. Studying more than nine million residential proxy IPs, they found that over 80 percent of the Chinese ones had carried at least one malicious traffic flow in a single year, and that most were invisible to Western threat intelligence. IPIDEA is that finding with a storefront and a checkout page.

What it means if IP2World or PIA S5 is on your shortlist

Two things are true at once if your tooling pointed at either brand. First, the service is degraded or broken: the storefronts were taken to court on January 28, the Google accounts the network used to steer infected devices were disabled, and Play Protect is removing the SDK apps. Second, and more lasting, the IPs are burned. More than 550 threat-actor groups ran through this same pool in a single week, so to every fraud-detection system on the internet, your traffic has been sharing an address with theirs. Any account or scraper tied to it may already be flagged, and we walk through how that flagging works in how websites detect proxies.

The wrong move is to grab the nearest cheap "residential" replacement, because that is exactly how you land in the next cluster. The right move is to change the question you ask a provider.

  • Ask how the pool is sourced, in plain words. A network built on consented, disclosed opt-in can say so directly. Vagueness is itself the answer.
  • Distrust a pool that appeared overnight. You rent millions of residential IPs, you do not build them in a year. A brand-new name with a world-beating pool number rented that pool from somewhere.
  • Look past the name. PIA S5 is not Private Internet Access and 360Proxy is not Qihoo 360. A friendly or borrowed name is marketing, not evidence.
  • Verify the IPs you are handed. Our free proxy checker makes a real connection through a proxy and reports the exit location, the anonymity grade and the network the IP actually belongs to, so a hijacked or blacklisted address shows itself before you trust it.

Where HProxy fits

We wrote this for the same reason we wrote who owns your proxy provider: the sourcing question is the one a clean network welcomes and a dirty one dodges. HProxy is independent, not part of any cluster, and we would rather compete on being able to tell you where our residential IPs come from than on a headline pool number we cannot stand behind. Our residential proxies are $0.65/GB pay as you go with no KYC and a balance that does not expire, and you can inspect the network before you trust any of this: run the free proxy checker against anything, and browse the live free proxy list to see exactly what we show and how we label it. If you want the definition underneath all of this, what is a residential proxy covers why the sourcing is the product.

Sources

Frequently asked questions

What is the IPIDEA cluster?
IPIDEA is the hub behind a group of residential proxy storefronts that look independent but run on one shared pool. Google's Threat Intelligence Group named the group on January 28, 2026 and disrupted it: IP2World, PIA S5 Proxy, LunaProxy, ABC Proxy, 922Proxy, 360Proxy, Cherry Proxy, PyProxy, TabProxy and Ipidea.io on the proxy side, plus free VPN apps used to enroll devices. The pieces were incorporated behind five Hong Kong shell companies so no single name sits over the whole thing.
Are IP2World and PIA S5 Proxy the same company?
They are two storefronts on the same network. IP2World is tied to the Hong Kong shell Hongkong Lingyun MDT Infotech Limited. PIA S5 Proxy is tied to Mars Brothers Limited, which also signs LunaProxy. Google's January 2026 disruption named all of them as one operation, and their infrastructure overlaps down to a shared DNS provider. So comparing IP2World against PIA S5 is comparing two labels on one pool, not two rivals.
Is PIA S5 Proxy related to Private Internet Access, the VPN?
No. The name echoes the well-known Private Internet Access VPN, but there is no connection. It is a name-borrowing trick that runs through the whole cluster: 360Proxy leans on Qihoo 360, ABC Proxy and Cherry Proxy reach for friendly generic words. PIA S5 refers to SOCKS5, the proxy protocol, and traces to the Mars Brothers Hong Kong shell.
How was the IPIDEA pool sourced?
Through SDKs, code packages bundled into free apps, free VPNs and pre-loaded TV set-top boxes. Google tied four to the cluster: Castar, Earn, Hex and Packet, which share so much code and control infrastructure they trace to one operation. Once installed, the SDK quietly turned a phone, PC or smart TV into a residential exit node. Google found the code in more than 600 Android apps and 3,075 Windows binaries, and Castar's own developer pitch advertised payouts as high as roughly 500 dollars per thousand impressions.
Is it safe to buy from IP2World or PIA S5 Proxy now?
Treat them as burned. The storefronts were taken to court, the SDKs are being removed by Play Protect, and Google counted more than 550 threat-actor groups running through this pool in a single week. Any IP you rent there shares its reputation with that traffic, so fraud systems flag it before your request lands.
Will the IPIDEA cluster come back?
Probably, under new names. A brand is not a network. The five shell companies, the millions of already-infected devices and the SDK code in the wild do not vanish when a domain does. The model survived 911 S5 and CloudRouter before this, so the useful move is to change how you judge a provider rather than chase the next cheap brand.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires.

47M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup