Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇨🇳 CN

IPIDEA

Also known asIPidea

IPIDEA is described in the provided content as a Chinese company operating a large residential proxy network by compromising consumer devices and turning them into proxy or exit nodes. The content states that IPIDEA installs malicious code through applications and games, free VPN apps, SDK integrations offered to developers, fake Windows and Android applications, and software preinstalled on low-cost Android TV streaming devices. Once infected, devices relay network traffic, help conceal the true origin of malicious activity behind residential IP addresses, and can participate in distributed denial-of-service attacks. The content says IPIDEA marketed itself as a legitimate proxy service provider while investigations and reports indicated its network was used for questionable and malicious purposes. Reported SDK packages associated with IPIDEA include Castar, Earn, Hex, and Packet SDK. The content also states that researchers identified more than 3,000 Windows files and 600 Android applications tied to the scheme, including fake software impersonating OneDrive Sync and Windows Update. No additional aliases or sub-groups beyond IPIDEA are directly provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇫🇮 Finland

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics16 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1189
Drive-by Compromise
T1195×2
Supply Chain Compromise
T1195.002
Compromise Software Supply Chain
TA0002
Execution
1 technique
T1204
User Execution
T1204.002
Malicious File
TA0005
Stealth
2 techniques
T1027
Obfuscated Files or Information
T1036×2
Masquerading
TA0008
Lateral Movement
1 technique
T1210
Exploitation of Remote Services
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.003×4
Multi-hop Proxy
T1105
Ingress Tool Transfer
T1568
Dynamic Resolution
TA0040
Impact
2 techniques
T1498×2
Network Denial of Service
T1499
Endpoint Denial of Service
ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

kyberturvallisuuskeskus alertsNews
Mar 20, 2026
Kyberturvallisuuskeskuksen viikkokatsaus - 12/2026 | Kyberturvallisuuskeskus

Operates a large residential proxy network by turning consumer devices into proxies via malicious code hidden in apps, games, SDKs, or preinstalled on low-cost Android TV devices; infected devices are used to relay traffic and participate in DDoS attacks.

Read more
kyberturvallisuuskeskus alertsNews
Mar 18, 2026
IPIDEA - Kotilaitteita hyödyntävä välityspalveluverkko | Kyberturvallisuuskeskus

Operates a malicious proxy network by infecting consumer devices, including via trojanized apps, fake software, SDK-based monetization schemes, and preinstalled malware on cheap Android TV streaming devices; infected devices are used as exit nodes, to relay traffic, mask malicious activity, and participate in DDoS attacks.

Read more
kyberturvallisuuskeskus alertsNews
Mar 18, 2026
IPIDEA - Kotilaitteita hyödyntävä välityspalveluverkko | Traficom

Operates a malicious proxy network by infecting consumer devices, including via trojanized apps, fake software, SDK-based monetization schemes, and preinstalled malware on cheap Android TV streaming devices; infected devices are used as exit nodes, to relay traffic, mask malicious activity, and participate in DDoS attacks.

Read more
security affairsNews
Feb 2, 2026
Security Affairs newsletter Round 561 by Pierluigi Paganini - INTERNATIONAL EDITION

Mentioned in the context of Google targeting it as part of a crackdown on global residential proxy networks.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping16

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.