Hacker NewsNewsTech News

Google’s IPIDEA Disruption Did Not Stay Down as Trackers Counted the Proxy Pool Climbing Back Past a Million Addresses

Google Shuts Down IPIDEA Proxy Network to Protect Millions of Android Users Worldwide

Google said in late January 2026 that it had pulled the rug out from under IPIDEA, one of the largest residential proxy networks in the world. Eight months later a threat-intelligence shop was counting the rug back on the floor. On September 4, Team Cymru Research published an intel brief saying the operators rebuilt from near zero starting in April and were near full operation by August. The firm said it was tracking 1,021,627 IP addresses tied to IPIDEA, and that the backconnect layer used to manage the nodes had climbed from the post-hit crater to 6,713 active tier-2 controllers, against about 7,400 before the disruption. Most of those controllers, the brief said, sat on Chinese hyperscale cloud in Singapore and Hong Kong. A takedown that does not stay down is not a failure of the press release. It is the business model.

The AEGIS Alliance is keeping that rebuild as the point, not the January victory lap. Residential proxies are other people’s phones, routers, television sticks, and set-top boxes rented out as exit nodes. The pitch to a device owner is a few dollars for unused bandwidth, or no pitch at all. The pitch to a buyer is a home internet address that will not trip the filters banks and social networks keep for data-center ranges. In one seven-day window in January, Google Threat Intelligence Group said more than 550 tracked threat groups used IPIDEA exits, including crews attributed to China, North Korea, Iran, and Russia. That number was never a club. It was a price list.

What Google actually switched off

The January action, described on the Google post and the longer Cloud threat-intelligence write-up, was legal and technical at once. GTIG and partners went after command domains, storefronts, and the software-development kits that enrolled devices, then sought court orders so the next landing page would have a name to serve. Play Protect was updated to warn Android users, strip apps known to carry the IPIDEA kit, and block new installs on certified devices. John Hultquist, GTIG’s chief analyst, said residential proxies had become a tool “for everything from high-end espionage to massive criminal schemes,” and that routing through a home connection let attackers “hide in plain sight.” Reuters added the inventory: at least 13 residential-proxy brands went offline in the same action, with more than 600 Android applications and 3,075 unique Windows files tied to the command infrastructure. Google said the available pool dropped by millions of devices.

Some of those apps were sideloaded. Some rode in through software that promised a VPN, a cleaner phone, or a small monthly payment. IPIDEA had advertised itself as a leading proxy provider with millions of daily addresses. Google has also tied the network’s reputation to botnets including BADBOX 2.0, and in July 2025 it sued 25 unnamed defendants in China over that botnet and the proxy layer around it. The honest version of a bandwidth-sharing market exists. The version GTIG described treated consent as optional and the device as inventory. Once the kit is on the box, the owner is not a customer. The owner is a route. A researcher who tested endpoints before the hit, Antoine Vastel, reported more than 16 million unique addresses answering as part of the network in the prior 30 days. Millions removed is a real cost. It is not the same sentence as gone.

The hallway had a second door

On July 2, 2026, GTIG, the FBI, IRS Criminal Investigation, Lumen, and the Shadowserver Foundation moved on a different brand: NetNut, also tracked as Popa. Google’s follow-on post said the January lesson was that a single network can look resilient after a public hit, so the work had to be a program. In one week in June, GTIG said it saw 316 distinct threat clusters on suspected NetNut exits. The company estimated that network at roughly 2 million devices and said the new action cut the available pool by millions. The FBI and IRS seized public domains, including infrastructure used to supply static residential addresses through contracts with internet providers. Parent company Alarum told markets the outage could hit operations and results if it lasted. Buyers who had walked from IPIDEA to the next API found the next API in the same kind of trouble.

That is not the end of the supply. Team Cymru’s September count is the adult version of the January announcement. Proxy shops reconstitute on fresh controllers, often on cloud providers that will rent a virtual machine to a stranger. The brief’s sample of backconnect hosts already carrying open SOCKS proxies is the unglamorous part: an IP address in Singapore is not a moral category. It is a place a node can hide while a phone in another country does the exiting. Whitelabel brands that shared IPIDEA’s pool, names buyers knew as separate storefronts, were never separate networks. When the upstream was hit they blinked. When the upstream was rebuilt they had somewhere to point.

The television in the living room was inventory too

Phones were the headline. Televisions were the quieter enrollment. On August 3, 2026, TechCrunch reported that Samsung would ban Smart TV apps that share a household’s internet connection with strangers, after researchers found residential-proxy kits inside popular titles, including games. A Samsung spokesperson said new registrations with that functionality were already restricted and that the company was removing apps that contained the components. LG had moved in the same direction after research suggested a large share of webOS apps were quietly sharing bandwidth. An app does not need to stay open to keep a tunnel. The set becomes an always-on exit. The owner sees a normal menu. The investigator sees a residential address and assumes a person.

That is the consumer version of the 550-group statistic. No one should sideload a “share your connection” app for a few dollars. Check what is installed. Revoke VPN and accessibility permissions a weather widget does not need. Factory-reset a cheap Android box that arrived with extra icons. If a relative was paid to run a bandwidth app, assume the box has been an exit and treat stored passwords as burned. Play Protect helps people who stay inside the official store. It does not help a television stick that never saw the store, and it does not help a Windows box that ran a cracked optimizer. The Windows file count in Google’s January inventory is the reminder that this was never only a phone story.

Enterprises have a different problem. Residential-proxy traffic is how account takeovers look like commuting customers. Fraud teams that still treat “home ISP” as a safe category are buying the story the proxy shop sells. The AEGIS Alliance technology and hacker news files will keep the distinction: a household address is a path, not an identity. Related vendor-risk cases on this desk include the 700Credit API breach that exposed nearly six million car buyers, the NGate malware that cloned tap-to-pay cards, and the phantom-hacker warnings about crews that drain accounts while sounding like a bank. Different products. The device in the house is now a workplace for strangers.

Disruption is a bill, not a burial

IPIDEA’s brands going dark was a real cost. Court-seized domains were a real cost. Millions of devices dropping out was a real cost. Team Cymru’s August snapshot says the operators paid the bill and reopened. NetNut’s July seizure says the FBI is willing to take the next storefront’s names. Samsung’s August policy says a television maker finally noticed that a game can be a tunnel. None of that retires the product. Bulletproof hosts used to sell the same invisibility with a server in a poorly supervised rack. Residential proxies sell it with a stranger’s living room. When one shop is hit, buyers walk down the hall. When the shop rebuilds on new cloud controllers, the hall gets its old tenant back under a fresh hostname.

Google framed both operations as a program, which is how a large vendor describes work that is public protection and market defense at the same time. Both can be true. A cleaner Android ecosystem is good for people who own phones. It is also good for the company that ships the operating system. Readers can hold those facts without doing the vendor’s publicity. The measurable test is the one Team Cymru already ran: how many addresses answer, where the controllers live, and whether the whitelabel brands are separate or just paint. “One of the world’s largest” was a January phrase. 1,021,627 tracked addresses in September is a count. The AEGIS Alliance will take the lawsuits as progress and the rebuild as the reason the lawsuits have to continue. The next app that offers to pay for idle bandwidth will use softer copy. The hallway will still be for rent, including to the fraud compounds and state crews that already know how to buy an exit by the hour, a market The AEGIS Alliance has traced through cases like the Prince Group Bitcoin forfeiture.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button