IPIDEA is a China-linked malicious residential proxy botnet/network that covertly uses compromised consumer devices to relay traffic through residential IP addresses. Reporting in the provided content describes it as a residential proxy botnet whose devices are secretly used to relay malicious traffic and to hide the activities of multiple threat actors. Google and partners disrupted the IPIDEA proxy network in January 2026, including through a court order targeting domains linked to the botnet. The content states that Google characterized IPIDEA at its peak as one of the largest networks of its kind and cited its disruption as part of a broader effort to dismantle resilient, interconnected malicious residential proxy ecosystems. High-confidence details in the content do not specify additional technical infection vectors, malware families, or concrete IOCs beyond domains linked to the botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
In January 2026, Synthient published research showing that multiple new large DDoS botnets had grown rapidly by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners and infecting other Android-based devices behind the user’s firewall.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-linked residential proxy network referenced as another example of a disrupted proxy ecosystem similar to the one involving Popa/NetNut.
A previously disrupted proxy network mentioned as a related precedent to the NetNut/Popa takedown.
Another malicious residential proxy network referenced as an earlier disruption and described as a main competitor to NetNut in the residential proxy ecosystem.
A similar large residential proxy network cited for comparison and operational overlap in takedown strategy discussions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.