Google Disrupts IPIDEA: The Proxy Brands Named and What Buyers Should Do
Google Threat Intelligence Group disrupted the IPIDEA residential proxy network on Jan 28, 2026 and named 13 linked proxy and VPN brands. The list, the NetNut link, and what buyers should check.
On January 28, 2026, Google Threat Intelligence Group (GTIG) published No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network, announcing that Google and partners had taken action against the IPIDEA residential proxy network, which Google describes as "one of the largest residential proxy networks in the world."
In July 2026, NetNut was taken down by Google, the FBI and others (our coverage). Taken together, the two cases put the residential proxy market's gray zone squarely in view.
Everything below comes from Google's original post. We only report what it states.
What Google did
According to the post, Google:
- Took legal action to take down domains used to control devices and route proxy traffic, and domains used to market IPIDEA products under various brands.
- Shared technical intelligence on IPIDEA's SDKs and proxy software with platform providers, law enforcement and research firms.
- Enforced platform policy so that Google Play Protect warns users, removes apps containing IPIDEA SDKs and blocks future installs.
- Worked with industry partners Spur, Lumen's Black Lotus Labs and Cloudflare to disrupt IPIDEA's domain resolution.
Google says it believes these actions reduced the pool of devices available to the operators "by millions."
The numbers Google published
| Metric | Per Google's post |
|---|---|
| Threat groups using IPIDEA exit nodes | 550+ in a single seven-day period in January 2026 |
| Tier Two servers | Approximately 7,400 |
| Unique Windows PE file hashes | 3,075 |
| Android apps connecting to Tier One C2 domains | 600+ |
The post also ties the infrastructure to botnets including BadBox 2.0, which Google sued in 2025, and more recently Aisuru and Kimwolf.
The brands Google named
Google writes that "many well-known residential proxy brands are not only related but are controlled by the actors behind IPIDEA." The post lists, in this order:
Proxy and VPN brands: 360 Proxy, 922 Proxy, ABC Proxy, Cherry Proxy, Door VPN, Galleon VPN, IP 2 World, Ipidea, Luna Proxy, PIA S5 Proxy, PY Proxy, Radish VPN, Tab Proxy
SDKs controlled by IPIDEA actors: Castar SDK, Earn SDK, Hex SDK, Packet SDK
Trojanized VPN apps: Galleon VPN, Radish VPN, Aman VPN (defunct)
Two caveats from the post itself are worth keeping in mind:
- Because operators share device pools through reseller and partnership agreements, Google found "significant overlaps" between networks' exit nodes, which makes "definitive quantification and attribution challenging." Google expects "downstream impact across affiliated entities."
- These are the findings of Google's investigation, not a court ruling. Refer to the original post for the authoritative list.
How devices ended up in the network
Google's explanation is blunt: proxy operators need code running on consumer devices to turn them into exit nodes. Devices are either pre-loaded with proxy software, or users unknowingly install trojanized apps with embedded proxy code. "Many of the malicious applications we analyzed in our investigation did not disclose that they enrolled devices into the IPIDEA proxy network."
Some people install this software on purpose, lured by offers to "monetize" spare bandwidth. Google warns that once a device becomes an exit node, traffic its owner does not control passes through their home network.
How this connects to NetNut
The two cases share a pattern:
- Both were led by GTIG with industry partners; in the NetNut case the FBI also seized the domain.
- Both relied on devices whose owners hadn't knowingly opted in, including infected streaming boxes and trojanized apps.
- Both were heavily used by attackers: 550+ threat groups in one week for IPIDEA, 316 threat clusters in one week for NetNut.
One line from Google's post should be on every proxy buyer's checklist: "any claims of 'ethical sourcing' must be backed by transparent, auditable proof of user consent."
What proxy buyers should do now
1. Check what you're running on. Compare your current providers against the list above. If a production workflow depends on one of them, plan a migration now rather than waiting for an outage, and avoid prepaying large balances.
2. Treat "too cheap" as a question, not a bargain. Rock-bottom or "unlimited" residential bandwidth should prompt one question first: where do these IPs come from?
3. Ask about sourcing in writing. A credible provider can tell you which apps or SDKs supply its IPs, how consent is collected and whether participants are paid. Silence is a signal.
4. Test sample IPs yourself. IPs shared with attackers tend to land on blocklists quickly. Our guide on how to check if a proxy IP is clean walks through IP type, blocklists, risk scores and leak tests.
5. Keep a second provider ready. For anything business-critical, integrate at least two providers so a takedown doesn't stop your operation.
Advice for everyday users
Google's consumer guidance applies to cross-border teams too:
- Be "extremely wary" of apps that pay for "unused bandwidth" or "sharing your internet."
- Stick to official app stores and review permissions for third-party VPN and proxy apps.
- Buy connected devices such as set-top boxes from reputable manufacturers; for Android TV, check the official site for Play Protect certified devices.
What we're doing
We don't recommend any brand named in Google's post. For every residential provider we list, our review states what the provider publicly discloses about IP sourcing, and says so when it discloses nothing. Browse alternatives in our residential proxies category or filter the proxy comparison table.
Some links are affiliate links. We may earn a commission if you buy through them, at no extra cost to you and without affecting our ratings.




