IPIDEA is identified in the content as a China-based company operating a large residential proxy network. Google and partners disrupted IPIDEA in January 2026, and the content states that at its peak it was one of the largest networks of its kind. The reporting describes IPIDEA as converting consumer devices into proxy nodes by installing malicious code, including via applications and games, free VPN applications, SDK-based integrations, fake Windows and Android applications, and software preinstalled on low-cost Android TV streaming devices. Named SDK packages associated with the activity include Castar, Earn, Hex, and Packet SDK. When installed, the malware turns devices into exit nodes that relay network traffic, conceal the true origin of activity behind residential IP addresses, and can also direct infected devices to participate in DDoS attacks. The content also states that researchers identified more than 3,000 Windows files and 600 Android applications tied to the scheme, including fake software impersonating OneDrive Sync and Windows Update. IPIDEA marketed itself as a legitimate proxy service provider and used SDK tools to attract developers, but investigations and reports cited in the content indicate the network was used for questionable and malicious purposes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Another residential proxy botnet referenced as part of broader disruption efforts related to the same problem space.
A China-based proxy network cited as a similar network previously disrupted by Google and partners.
Another malicious proxy network previously disrupted by Google and referenced as part of the broader interconnected residential proxy ecosystem.
Operates a large residential proxy network by turning consumer devices into proxies via malicious code hidden in apps, games, SDKs, or preinstalled on low-cost Android TV devices; infected devices are used to relay traffic and participate in DDoS attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.