Shop for residential proxies long enough and you will meet Shifter, a long-running provider with a clean, modern website. What that website does not mention is that Shifter used to be Microleaves, a service with one of the messier histories in the industry: antivirus vendors flagged its software as a trojan, its origins trace to commercializing installs on strangers' Windows machines, and in 2022 it accidentally leaked its own customer database to the world. This is the sourced story of that rebrand, and why a new name is the easiest thing in this business to buy.
We run a competing proxy network and track the lineage of every rival, not to throw mud but because origin is a real spec. A rebrand changes the logo. It does not change how a network was originally built, and Microleaves-to-Shifter is the cleanest example of why that distinction matters.
Where Microleaves came from
Microleaves surfaced around 2012 to 2013 as a proxy service that routed customer traffic through millions of Microsoft Windows computers. According to KrebsOnSecurity, the brand started by commercializing installs, building one of the early peer-to-peer residential proxy networks essentially by turning software installs on ordinary PCs into a rentable pool.
The marketing was enormous and the reality was smaller. On BlackHatWorld in November 2013, the operator advertised "26 million SOCKS residential proxies," and by late 2013 the pitch had grown to 31 million residential IPs. Microleaves later claimed to control 20 to 30 million IPs at any time. Independent measurement told a different story: by 2022, Spur.us tracked roughly 250,000 proxies a day on the network. Inflated pool claims are a theme worth remembering the next time a provider quotes you a headline IP count.
The trojan classification
The detail that says the most is how security software treated Microleaves' own client. Kaspersky classified it as "Trojan-Proxy.Win64.Microleaves," and noted that while running, these trojans "pose as Microsoft Windows Update." Software that disguises itself as a Windows Update while quietly turning a machine into a proxy node is not a consented, opt-in supplier. It is the botnet model with a billing page, the same shape we documented in the NetNut takedown and what happened to 911 S5.
Acidut, and the sale to Taiwan
The people behind the brand are part of why it needed a new name. Reporting traces Microleaves to an original founder described as a man from India, after which it was run by Alexandru Florea of Romania. Florea used the handle "Acidut," which, per Intel 471 as cited by Krebs, had an active presence across almost a dozen money-making and cybercrime forums from 2010 to 2017, including BlackHatWorld, Hackforums, and Carder.pro.
In 2019, Microleaves was sold to Super Tech Ventures, a Taiwan-based private equity firm, which installed new leadership (a CEO named Wang Wei) and rebranded the service to Shifter.io. So the Shifter you see today is Microleaves under new ownership and a new name, three steps removed from its forum-era origins but built on the same network lineage.
The 2022 breach: a proxy service leaks itself
The most revealing moment came in July 2022, when a website vulnerability exposed Microleaves' entire user database, including customer payment data and how much each user had spent. Krebs reported the exposed records indicated more than $11.7 million in direct payments over the service's lifetime, along with a view of its most active, highest-spending customers.
Sit with the irony. A service whose entire value proposition is anonymity, that sells the ability to hide who and where you are, left its own customer list and payment history open to anyone who looked. If a provider cannot secure its own front door, the promises it makes about protecting your traffic deserve real skepticism.
Why a rebrand does not reset the clock
None of this means Shifter today operates the way Microleaves did a decade ago. Ownership changed, leadership changed, and a modern service can be run very differently from its origins. The point is narrower and more useful: a rebrand is the cheapest reputation repair in this industry, and it is extremely common. We mapped how often proxy brands change names, merge, and hide under holding companies in who owns your proxy provider, where Smartproxy-becoming-Decodo and a chain of Oxylabs acquisitions show the same churn in the mainstream tier.
So the right question is never "is the brand new and shiny." It is "how is the residential pool sourced today, and will the provider tell me plainly." A history like Microleaves' does not automatically condemn the current service, but it absolutely raises the bar for how clearly that service should be able to answer the sourcing question.
How to judge a provider with a past
- Look up the brand's former names. A quick search for "was [provider] previously called" often surfaces a rebrand, and the old name is where the history lives.
- Read how the pool is sourced today, in the provider's own words. Consented, disclosed opt-in should be stated plainly. Silence or word-salad is the answer.
- Verify the IPs you are given. Our free proxy checker makes a real connection through a proxy and reports the exit location, anonymity grade, and the network the IP actually belongs to.
- Weight the sourcing story over the branding. A slick site is not evidence of clean IPs. The supply chain is, and that is exactly what are free proxies safe and free residential proxies dig into.
The honest takeaway
Microleaves becoming Shifter is not proof of present-day wrongdoing, and we are not claiming it is. It is proof of something more broadly useful: in the proxy world, the name on the door is the easiest thing to change and the least informative thing to trust. What matters is how the network was built and how it is sourced now, and a brand with a trojan-flagged, breach-exposed past should have to be more transparent about that, not less.
We started HProxy on the opposite bet: that being plainly answerable about who we are and where our IPs come from is a feature worth competing on. Our residential proxies are $0.65/GB pay as you go with no KYC, you can inspect the network first with the free proxy checker and free proxy list, and we would rather win on the sourcing question than dodge it with a new logo.
Sources
- KrebsOnSecurity, "Breach Exposes Users of Microleaves Proxy Service" (July 2022): Microleaves origins, IP claims, Spur.us measurement, Kaspersky trojan classification, Acidut/Alexandru Florea, Super Tech Ventures sale and Shifter rebrand, the breach and $11.7M+ figure
- KrebsOnSecurity, Acidut tag and Shifter.io tag (reporting history)
- Proxyway, In-depth Shifter Review (current Shifter product context)