Comparison

Shifter Was Microleaves: The Proxy Brand That Rebranded After a Botnet Past

Shifter.io used to be Microleaves, a proxy service Kaspersky flagged as a trojan and that leaked its own users in 2022. Here is the sourced history and why a rebrand does not reset a network's origins.

HProxy Team · ·Updated July 19, 2026 ·5 min read
HProxy. Comparison

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.65/GB, pay as you go.

See plans & pricing

Shop for residential proxies long enough and you will meet Shifter, a long-running provider with a clean, modern website. What that website does not mention is that Shifter used to be Microleaves, a service with one of the messier histories in the industry: antivirus vendors flagged its software as a trojan, its origins trace to commercializing installs on strangers' Windows machines, and in 2022 it accidentally leaked its own customer database to the world. This is the sourced story of that rebrand, and why a new name is the easiest thing in this business to buy.

We run a competing proxy network and track the lineage of every rival, not to throw mud but because origin is a real spec. A rebrand changes the logo. It does not change how a network was originally built, and Microleaves-to-Shifter is the cleanest example of why that distinction matters.

Where Microleaves came from

Microleaves surfaced around 2012 to 2013 as a proxy service that routed customer traffic through millions of Microsoft Windows computers. According to KrebsOnSecurity, the brand started by commercializing installs, building one of the early peer-to-peer residential proxy networks essentially by turning software installs on ordinary PCs into a rentable pool.

The marketing was enormous and the reality was smaller. On BlackHatWorld in November 2013, the operator advertised "26 million SOCKS residential proxies," and by late 2013 the pitch had grown to 31 million residential IPs. Microleaves later claimed to control 20 to 30 million IPs at any time. Independent measurement told a different story: by 2022, Spur.us tracked roughly 250,000 proxies a day on the network. Inflated pool claims are a theme worth remembering the next time a provider quotes you a headline IP count.

The trojan classification

The detail that says the most is how security software treated Microleaves' own client. Kaspersky classified it as "Trojan-Proxy.Win64.Microleaves," and noted that while running, these trojans "pose as Microsoft Windows Update." Software that disguises itself as a Windows Update while quietly turning a machine into a proxy node is not a consented, opt-in supplier. It is the botnet model with a billing page, the same shape we documented in the NetNut takedown and what happened to 911 S5.

Acidut, and the sale to Taiwan

The people behind the brand are part of why it needed a new name. Reporting traces Microleaves to an original founder described as a man from India, after which it was run by Alexandru Florea of Romania. Florea used the handle "Acidut," which, per Intel 471 as cited by Krebs, had an active presence across almost a dozen money-making and cybercrime forums from 2010 to 2017, including BlackHatWorld, Hackforums, and Carder.pro.

In 2019, Microleaves was sold to Super Tech Ventures, a Taiwan-based private equity firm, which installed new leadership (a CEO named Wang Wei) and rebranded the service to Shifter.io. So the Shifter you see today is Microleaves under new ownership and a new name, three steps removed from its forum-era origins but built on the same network lineage.

The 2022 breach: a proxy service leaks itself

The most revealing moment came in July 2022, when a website vulnerability exposed Microleaves' entire user database, including customer payment data and how much each user had spent. Krebs reported the exposed records indicated more than $11.7 million in direct payments over the service's lifetime, along with a view of its most active, highest-spending customers.

Sit with the irony. A service whose entire value proposition is anonymity, that sells the ability to hide who and where you are, left its own customer list and payment history open to anyone who looked. If a provider cannot secure its own front door, the promises it makes about protecting your traffic deserve real skepticism.

Why a rebrand does not reset the clock

None of this means Shifter today operates the way Microleaves did a decade ago. Ownership changed, leadership changed, and a modern service can be run very differently from its origins. The point is narrower and more useful: a rebrand is the cheapest reputation repair in this industry, and it is extremely common. We mapped how often proxy brands change names, merge, and hide under holding companies in who owns your proxy provider, where Smartproxy-becoming-Decodo and a chain of Oxylabs acquisitions show the same churn in the mainstream tier.

So the right question is never "is the brand new and shiny." It is "how is the residential pool sourced today, and will the provider tell me plainly." A history like Microleaves' does not automatically condemn the current service, but it absolutely raises the bar for how clearly that service should be able to answer the sourcing question.

How to judge a provider with a past

  • Look up the brand's former names. A quick search for "was [provider] previously called" often surfaces a rebrand, and the old name is where the history lives.
  • Read how the pool is sourced today, in the provider's own words. Consented, disclosed opt-in should be stated plainly. Silence or word-salad is the answer.
  • Verify the IPs you are given. Our free proxy checker makes a real connection through a proxy and reports the exit location, anonymity grade, and the network the IP actually belongs to.
  • Weight the sourcing story over the branding. A slick site is not evidence of clean IPs. The supply chain is, and that is exactly what are free proxies safe and free residential proxies dig into.

The honest takeaway

Microleaves becoming Shifter is not proof of present-day wrongdoing, and we are not claiming it is. It is proof of something more broadly useful: in the proxy world, the name on the door is the easiest thing to change and the least informative thing to trust. What matters is how the network was built and how it is sourced now, and a brand with a trojan-flagged, breach-exposed past should have to be more transparent about that, not less.

We started HProxy on the opposite bet: that being plainly answerable about who we are and where our IPs come from is a feature worth competing on. Our residential proxies are $0.65/GB pay as you go with no KYC, you can inspect the network first with the free proxy checker and free proxy list, and we would rather win on the sourcing question than dodge it with a new logo.

Sources

Frequently asked questions

Is Shifter the same as Microleaves?
Yes. Shifter.io is the rebranded name of Microleaves, a proxy service that ran from around 2012 to 2013 onward. It was renamed Shifter after the Taiwan-based private equity firm Super Tech Ventures acquired it in 2019. Same network lineage, new brand.
Why did Microleaves rebrand to Shifter?
Microleaves carried heavy baggage. Antivirus vendors classified its software as a trojan, its origins were tied to commercializing installs on Windows PCs, and its founder-era operator was active on cybercrime forums. A clean brand name distances a service from that history, but it does not change how the network was originally built.
Was Microleaves a botnet?
Its origins look like one. Security reporting describes Microleaves as starting around 2012 by commercializing installs, routing customer traffic through millions of Windows computers, and Kaspersky flagged its software as 'Trojan-Proxy.Win64.Microleaves,' noting it posed as a Microsoft Windows Update while running. It advertised tens of millions of residential IPs, far more than independent measurements ever confirmed active.
What was the 2022 Microleaves breach?
In July 2022, a website vulnerability exposed Microleaves' entire user database, including customer payment data and how much each user had spent. KrebsOnSecurity reported the exposed records indicated more than $11.7 million in direct payments over the service's life. It is a rare public look inside a proxy service's books, and it happened by accident.
Who ran Microleaves?
Reporting traces the brand to an original founder described as a man from India, after which it was run by Alexandru Florea of Romania, who used the handle 'Acidut' across cybercrime forums from 2010 to 2017. In 2019 the service was sold to Super Tech Ventures, a Taiwan-based private equity firm, which rebranded it to Shifter.
Does a proxy rebrand mean the service is clean now?
Not by itself. A new name, owner, and website can accompany genuine changes, but they can also just bury an origin story. The question that actually matters is unchanged: how is the residential pool sourced today, and can the provider tell you plainly? Judge the current sourcing, not the logo.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires.

47M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup