IPIDEA Residential Proxy Botnet Disruption by Google
IPIDEA Residential Proxy Botnet Disruption by Google (TL-2026-0042), also tracked as AISURU, is a high-severity tracked intrusion set scored CVSS 8, first published 2026-02-03. It is attributed to IPIDEA Operators with high confidence, affects N/A Consumer devices enrolled in proxy networks (Windows PCs, Android, maps to 46 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 41 detection rules and 117 indicators of compromise.
Key facts for TL-2026-0042
- Threat ID
- TL-2026-0042
- Also known as
- AISURU, BADBOX 2.0, IPIDEA, Kimwolf, Proxy Botnet, Residential Proxy Botnet
- Severity
- HIGH
- CVSS
- 8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L)
- Status
- MONITORING
- Category
- THREAT_INTEL
- First published
- 2026-02-03
- Last reviewed
- 2026-02-03
- Attribution
- IPIDEA Operators
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL/ESPIONAGE
- Target sectors
- AI/Machine Learning, Advertising, Advertising Technology, All Sectors, Consumer, Consumer/Residential Users, E-Commerce, Financial Services, Government, Healthcare, Internet Infrastructure, Social Media
- Target regions
- Asia-Pacific, Europe, Global, North America, South America, United States
- Detection rules
- 41
- Indicators of compromise
- 117
Malware and tooling in IPIDEA Residential Proxy Botnet Disruption by Google
Malware and tooling: IPIDEA
Google's legal and technical disruption of the IPIDEA residential proxy botnet — a service monetizing 3.2+ million compromised residential IP addresses by renting them to cybercriminals for traffic anonymization, credential stuffing, ad fraud, and AI data scraping. Distinct from TL-0022 (parent: IPIDEA botnet network analysis and Google's legal action filing). TL-0042 focuses on the legal precedent, proxy network forensics, residential IP trust model erosion, and the broader residential proxy ecosystem's convergence with AI-powered scraping operations. Google's civil lawsuit under the Computer Fraud and Abuse Act (CFAA) and state consumer protection statutes seeks permanent injunction against IPIDEA's operators, domain seizure, and disgorgement of criminal profits. The case establishes legal precedent for treating residential proxy botnets as computer fraud — not just terms-of-service violations. Forensic analysis reveals IPIDEA acquired nodes through deceptive 'free VPN' applications, pay-per-install affiliate networks, and SDK bundling in mobile apps, enrolling devices without meaningful informed consent. The disruption exposes the residential proxy industry's fundamental trust problem: when 250 million residential IPs are proxied monthly (per Spur.us tracking), the foundational assumption that residential IP addresses represent legitimate human users collapses — undermining IP-based reputation systems, geo-restriction enforcement, anti-fraud controls, and rate limiting across the entire Internet. [MERGED] This record consolidates TL-2026-0042, TL-2026-0022, and TL-2026-0011 into a single canonical threat. TL-0022 focused on Google's legal-technical disruption playbook and 40M+ IP infrastructure. TL-0011 focused on the 550+ threat actor ecosystem and APT/ransomware usage. All detections, MITRE mappings, references, and timeline events have been merged and deduplicated.
How IPIDEA Residential Proxy Botnet Disruption by Google works
IPIDEA is a residential proxy service that maintained a network of approximately 3.2 million compromised residential IP addresses across 195+ countries, offering customers the ability to route their Internet traffic through genuine residential connections. The service positioned itself as a 'premium residential proxy provider' for market research, SEO monitoring, and price comparison. In reality, IPIDEA's infrastructure was overwhelmingly used for: credential stuffing attacks against financial services and e-commerce platforms, advertising fraud (click fraud, impression fraud, affiliate hijacking), large-scale web scraping operations fueling AI/LLM training datasets, account takeover campaigns, and circumventing security controls that rely on IP reputation.
**Google's Legal Disruption — Establishing CFAA Precedent for Proxy Botnets:** Google filed a civil lawsuit against IPIDEA's operators under the Computer Fraud and Abuse Act (18 USC § 1030), the Racketeer Influenced and Corrupt Organizations Act (RICO), and state consumer protection laws. The lawsuit seeks: (1) permanent injunction against IPIDEA operations, (2) seizure of IPIDEA's domains and payment processing accounts, (3) disgorgement of all profits derived from the botnet, (4) declaratory judgment that residential proxy botnets constitute unauthorized computer access under CFAA. This establishes critical legal precedent: previous enforcement actions against residential proxies relied on FTC consumer protection authority (deceptive practices) or were pursued as terms-of-service violations. Google's CFAA theory argues that when a device is enrolled in a proxy network without genuine informed consent, every proxy connection through that device constitutes unauthorized access — transforming what proxy operators characterized as a legitimate business into a criminal enterprise.
**Proxy Network Forensics — How IPIDEA Built Its Botnet:** Google's technical investigation, supported by Spur.us intelligence and University of Sherbrooke research, revealed IPIDEA's node acquisition pipeline: (1) Deceptive 'Free VPN' applications — mobile and desktop VPN apps that provide functional VPN service while secretly enrolling user devices as exit nodes in IPIDEA's proxy network. The proxy functionality is disclosed only in dense Terms of Service that users don't read; (2) Pay-per-install affiliate networks — IPIDEA operated affiliate programs paying $0.10-$0.50 per installation, with 'all promotion methods allowed' language that tacitly endorses malware distribution, software bundling, and deceptive download buttons; (3) SDK bundling in legitimate mobile applications — IPIDEA's SDK was embedded in apparently legitimate mobile apps (flashlight apps, battery optimizers, QR scanners) that users download for utility, unaware the app also turns their phone into a proxy relay; (4) IoT device exploitation — router firmware vulnerabilities and default credential exploitation to enroll IoT devices as proxy nodes without any user interaction.
**Residential IP Trust Erosion — The Systemic Impact:** The broader residential proxy industry has reached an inflection point. Spur.us tracking shows 250 million unique residential proxy IPs in the past 90 days across all providers — an unprecedented number. The top providers by IP count: Luminati/Bright Data (11.8M), NetNut (10.9M), ABCProxy (9.3M), Oxylabs (6.7M), IPIDEA (3.2M). This scale fundamentally breaks the Internet's trust model: IP reputation systems that classify 'residential' as 'likely legitimate' are now unreliable because a significant percentage of residential traffic is actually proxied criminal activity. Consequences: (1) Rate limiting by IP is ineffective when attackers rotate through millions of residential IPs; (2) Geo-restriction enforcement fails when proxy users appear to be in any desired country; (3) Anti-fraud systems that trust residential IPs over datacenter IPs generate false negatives at scale; (4) Captcha and bot detection systems are calibrated against datacenter traffic patterns, not residential proxy traffic.
**AI Scraping Convergence — The New Economic Driver:** The residential proxy industry's economic model is shifting from traditional cybercrime use cases to AI/LLM data scraping. AI companies and their contractors require massive-scale web scraping to build training datasets, and they need to evade website anti-bot protections. Residential proxies provide: (1) the appearance of organic human browsing from distributed locations, (2) automatic IP rotation to avoid rate limits, (3) geographic diversity for location-specific content scraping, (4) residential IP reputation that bypasses bot detection. This creates a new economic dynamic: legitimate AI companies are indirectly funding botnet infrastructure by purchasing proxy services that rely on compromised devices for their node pools. The line between 'legitimate business intelligence' and 'botnet-powered scraping' has blurred beyond distinction.
**Historical Context — From 911.re to IPIDEA:** IPIDEA's disruption follows a pattern of residential proxy service takedowns: 911.re (operational 2015-2022, shut down after KrebsOnSecurity exposure), Microleaves/Shifter.io (exposed 2022, database breach), VIP72 (shut down 2022), RSocks (DOJ takedown 2022), and the Aisuru botnet's pivot from DDoS to residential proxy monetization (2025). Each disruption removes one provider but the ecosystem persists because the business model is profitable: IPIDEA charged customers $1.50-$15 per GB of residential proxy traffic with near-zero infrastructure costs (the 'infrastructure' is other people's devices). Google's legal approach — attacking the CFAA basis rather than just deceptive practices — aims to establish precedent that makes the ENTIRE business model illegal, not just specific implementations.
**Merged Intelligence — TL-0022 (Google Disruption Playbook):** Google's five-step legal-technical disruption playbook (investigation → legal action → court orders → technical disruption → partnerships) refined through Glupteba (2021) and CryptBot (2023) was applied to IPIDEA. The operation included ISP subscriber notifications, AV signature pushes by Microsoft Defender/Norton/Malwarebytes/Kaspersky, and Google Safe Browsing flags for installer binaries. IPIDEA's commercial API served customers at $0.77-$15/GB with an estimated $100M+ in annual revenue from the 40M+ residential IP pool.
**Merged Intelligence — TL-0011 (550+ Threat Actor Ecosystem):** Security researchers documented 550+ distinct threat actors leveraging IPIDEA, including APT28, Sandworm, and Volt Typhoon for C2 anonymization; ransomware affiliates for data exfiltration and negotiation routing; and sanctions evasion schemes accessing financial services from restricted jurisdictions. The 911 S5 botnet takedown (Operation Tunnel Rat, May 2024, operator Yunhe Wang arrested) set the direct legal precedent. IoT device enrollment through default credentials, firmware vulnerabilities, and supply chain compromises expanded the proxy pool beyond traditional PCs to routers, smart home devices, and Android TV boxes.
MITRE ATT&CK techniques used in TL-2026-0042
collection
T1005 Data from Local System; T1119 Automated Collection
discovery
T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1205 Traffic Signaling; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts
exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
execution
T1053 Scheduled Task/Job; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1090.003 Multi-hop Proxy; T1132 Data Encoding; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573 Encrypted Channel; T1665 Hide Infrastructure
credential-access
initial-access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
lateral-movement
T1210 Exploitation of Remote Services
impact
T1489 Service Stop; T1496 Resource Hijacking; T1498 Network Denial of Service; T1657 Financial Theft
persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
resource-development
T1583 Acquire Infrastructure; T1583.005 Botnet; T1584 Compromise Infrastructure; T1584.005 Botnet; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Affected products and versions in IPIDEA Residential Proxy Botnet Disruption by Google
- N/A — Consumer devices enrolled in proxy networks (Windows PCs, Android TV Boxes, Android Apps, IoT devices, routers)
Vulnerable versions: Devices with proxy software installed; Devices with IPIDEA proxy software or SDK-embedded apps
Fixed in: Remove proxy software
Remediation for IPIDEA Residential Proxy Botnet Disruption by Google
Patches
- [object Object]
Immediate actions
- Audit Android TV boxes and streaming devices for unauthorized software
- Block all IPIDEA-related domains at DNS/firewall level
- Block known proxy enrollment domains at DNS/firewall
- Block known proxy service domains at perimeter
- Check for apps containing Hex SDK, Packet SDK, Earn SDK, Castar SDK
- Check for unusual bandwidth consumption patterns
- Enable Google Play Protect on all Android devices
- Review software installations for bundled proxy clients
- Review software inventory for unauthorized applications
- Scan endpoints for known proxy client software
Workarounds
- Block outbound SOCKS5 connections from workstations
- Block outbound connections on non-standard ports from IoT devices
- Block outbound connections to known proxy API endpoints
- Factory reset compromised Android TV boxes
- Implement egress filtering for unusual traffic patterns
- Implement strict software installation policies
- Isolate suspected devices on separate VLAN
- Monitor for processes listening on unusual ports
- Use network segmentation to limit proxy impact
Longer-term hardening
- Audit third-party app integrations for embedded proxy SDKs
- Deploy DNS filtering to block residential proxy infrastructure
- Deploy EDR with behavioral detection for proxy activity
- Implement application allowlisting
- Implement application allowlisting to prevent proxy installation
- Implement network segmentation for IoT devices
- Monitor for software bundles containing proxy components
- Monitor for unusual outbound connection patterns
- Network monitoring for proxy-like traffic patterns
- Only purchase Play Protect certified Android TV devices
Weaknesses (CWE) in IPIDEA Residential Proxy Botnet Disruption by Google
CWE-506
Timeline of IPIDEA Residential Proxy Botnet Disruption by Google
Showing the 20 most recent tracked events.
- US federal court grants ex parte Temporary Restraining Order (TRO) authorizing: seizure of IPIDEA domains, C2 server redirection, hosting provider cooperation, API endpoint nullification. Orders domain registrars to transfer ipidea.net and related domains to Google's control.
- Coordinated disruption executed: IPIDEA domains sinkholed (ipidea.net confirmed ENOTFOUND as of 2026-02-11). C2 servers redirected. API endpoints nullified. Enrolled devices can no longer communicate with IPIDEA infrastructure. ISP notifications begin for infected subscribers.
- Major antivirus vendors push detection signatures for IPIDEA proxy SDK. Microsoft Defender, Norton, Malwarebytes, Kaspersky, and others add IPIDEA SDK to malware databases. Google Safe Browsing flags installer binaries. Automated cleanup begins on enrolled devices.
- IPIDEA reaches approximately 3.2 million residential IP addresses across 195+ countries. Spur.us tracking confirms IPIDEA among top 5 residential proxy providers globally. Node acquisition continues through deceptive VPN apps and mobile SDK bundling. Source: Spur.us intelligence
- IPIDEA disruption sends shockwave through residential proxy industry. Remaining RPaaS providers (Bright Data, Oxylabs, SmartProxy) emphasize transparent consent mechanisms. Regulatory discussion intensifies around requiring explicit opt-in for proxy network participation. Google publishes disruption playbook guidance for other tech companies.
- Residential proxy industry shifts toward AI/LLM data scraping as primary economic driver. AI companies and contractors purchase residential proxy access to bypass anti-bot protections while building training datasets. Proxy services experience unprecedented demand growth. Source: KrebsOnSecurity / Spur.us
- Security researchers document IPIDEA's residential proxy network being used by 550+ threat actors for credential stuffing, APT operations, ransomware, ad fraud, and sanctions evasion. Investigations reveal proxy pool built through malware, deceptive SDKs, and IoT compromise.
- Threat intelligence firms confirm IPIDEA's China-based operations, affiliate programs for bandwidth harvesting, and systematic abuse by cybercriminal organizations. Network identified as successor/competitor to dismantled 911 S5 infrastructure.
- Aisuru botnet pivots from DDoS to residential proxy monetization. 700,000+ compromised IoT devices rented to proxy services for traffic anonymization. Demonstrates the DDoS-to-proxy pipeline: botnets discover proxying is more profitable than DDoS-for-hire. Source: KrebsOnSecurity
- Academic and industry research documents the residential proxy ecosystem as critical infrastructure for modern cybercrime — IPIDEA, NSOCKS, 922 Proxy, and others identified as providing IP diversity that defeats IP-based security controls at scale.
- Spur.us reports 250 million unique residential proxy IPs observed in 90-day window — unprecedented scale. Top providers: Luminati/Bright Data (11.8M), NetNut (10.9M), ABCProxy (9.3M), Oxylabs (6.7M), IPIDEA (3.2M). Residential IP trust model breaking at this scale. Source: Spur.us / KrebsOnSecurity
- Google files civil lawsuit against IPIDEA operators under CFAA, RICO, and state consumer protection laws. Seeks permanent injunction, domain seizure, profit disgorgement. CFAA theory: proxy enrollment without genuine consent = unauthorized computer access. Establishes precedent for treating proxy botnets as criminal enterprises. Source: Google legal filing
- Federal court issues temporary restraining order authorizing seizure of IPIDEA-related domains and payment processing accounts. Sinkholing redirects IPIDEA infrastructure to Google-controlled servers, disrupting proxy network operations and enabling victim notification. Source: Court filings
- Coordinated law enforcement and private sector action disrupts IPIDEA's operational infrastructure — management servers, API endpoints, and payment processing targeted. Compromised endpoint devices remain at risk of re-enrollment into successor networks.
- Discovered
- KrebsOnSecurity reports on KimWolf botnet exploiting residential router vulnerabilities to build proxy networks, demonstrating that IPIDEA disruption has not stopped the ecosystem — new botnets fill the gap. Source: KrebsOnSecurity
- Disclosed
- IPIDEA infrastructure remains down (ipidea.net DNS ENOTFOUND). Former IPIDEA customers have migrated to surviving services or new entrants. PPI ecosystem continues adapting — new proxy botnets emerging with improved evasion. Google's legal precedent established: residential proxy services built on deceptive enrollment = botnets under CFAA.
- ThreadLinqs Intelligence revalidates TL-2026-0042 with focus on legal precedent, proxy network forensics, residential IP trust erosion, and AI scraping convergence — distinct from TL-0022 (IPIDEA botnet network analysis). Source: ThreadLinqs Intelligence
- As of 2026-05-29, this threat remains active: Google's Jan 28, 2026 disruption (GTIG + court order, per the July 2025 BADBOX 2.0 injunction) degraded IPIDEA by millions of nodes but did not kill it. Per Google and Cybernews, operators rebranded (Smartproxy.org), SDKs stay installed, exit nodes still route, and Aisuru/Kimwolf persist — MONITORING is correct.
Sources cited for IPIDEA Residential Proxy Botnet Disruption by Google
- KrebsOnSecurity: The Rise of Bulletproof Residential Networks
- Google — Glupteba Botnet Legal Disruption (Precedent)
- University of Sherbrooke: Residential Proxy as a Service Analysis
- DOJ: RSocks Residential Proxy Botnet Disrupted
- KrebsOnSecurity: Breach Exposes Users of Microleaves Proxy Service
- KrebsOnSecurity: A Deep Dive Into the Residential Proxy Service 911
- KrebsOnSecurity — 911.re Proxy Service Exposé
- CFAA: 18 USC § 1030 — Computer Fraud and Abuse Act
- Google TAG: Fog of War Report — Proxy Usage in Conflict
- Google — CryptBot Disruption (Legal Playbook)
- Google Safe Browsing — SDK Detection
- Spur.us — Residential Proxy Detection
- HUMAN Security — Proxy Botnet Analysis
- OWASP — Credential Stuffing Prevention
- Google Ads — Invalid Traffic Prevention
More in threat intel
- VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Theft
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding, JADESNOW/INVISIBLEFERRET, SharkStealer)
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C Domains Surge +771%
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
Detection coverage for TL-2026-0042
As of 2026-02-03, Threadlinqs Intelligence publishes 41 detection rule(s) for TL-2026-0042 across Splunk SPL, Microsoft KQL and Sigma, covering 117 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.