Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Google Disrupts IPIDEA Proxy Network 

One of the largest residential proxy networks, IPIDEA enrolled devices through SDKs for mobile and desktop.

Proxy disrupted

Google on Wednesday announced the disruption of IPIDEA, believed to be one of the largest residential proxy networks worldwide.

IPIDEA’s operators used software development kits (SDKs) and proxy software that developers embedded in their mobile and desktop applications, and which enrolled users’ devices into the network.

The IPIDEA takedown, Google says, involved both legal action against control and proxy domains, and sharing intelligence on the SDKs and proxy software used in the operation.

According to Google, the disruption reduced “the available pool of devices for the proxy operators by millions”, causing “significant degradation of IPIDEA’s proxy network and business operations”.

“Because proxy operators share pools of devices using reseller agreements, we believe these actions may have downstream impact across affiliated entities,” Google notes.

The threat actors behind IPIDEA were controlling over a dozen independent proxy and VPN brands, as well as domains related to SDKs for residential proxies.

Advertisement. Scroll to continue reading.

Providing Android, iOS, Windows, and WebOS support, the SDKs were marketed as monetization means for developers, who were paid by IPIDEA’s operators, usually on a per-download basis.

Once the applications were installed, the SDKs turned users’ devices into exit nodes for the proxy network, typically without their knowledge.

“While many residential proxy providers state that they source their IP addresses ethically, our analysis shows these claims are often incorrect or overstated. Many of the malicious applications we analyzed in our investigation did not disclose that they enrolled devices into the IPIDEA proxy network,” Google says.

IPIDEA, Google says, controlled Castar SDK, Earn SDK, Hex SDK, and Packet SDK, and used a two-tier infrastructure system, where devices would connect to a domain to receive data on the tier two nodes to connect to.

While the SDKs had different tier one domains, they all used a shared pool of approximately 7,400 tier two servers. The number of tier two nodes would change daily, based on demand.

IPIDEA also controlled VPN applications that provided the expected functionality but also enrolled devices into the proxy network. The identified apps include Galleon VPN, Radish VPN, and Aman VPN.

Google identified 3,075 unique Windows PE file hashes and more than 600 Android applications connecting to tier one domains.

Google and its partners took legal action to take down the command-and-control (C&C) domains used by the proxy network, as well as domains that the threat actors used for marketing purposes. It also added policies to Google Play Protect to remove IPIDEA SDKs from certified Android devices.

“We’ve worked closely with other firms, including Spur and Lumen’s Black Lotus Labs to understand the scope and extent of residential proxy networks and the bad behavior they often enable. We partnered with Cloudflare to disrupt IPIDEA’s domain resolution, impacting their ability to command and control infected devices and market their products,” Google notes.

Related: RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement

Related: Kimwolf Android Botnet Grows Through Residential Proxy Networks

Related: $29 Million Worth of Bitcoin Seized in Cryptomixer Takedown

Related: Google Says Chinese ‘Lighthouse’ Phishing Kit Disrupted Following Lawsuit

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.