IPIDEA is a large malicious residential proxy network and botnet associated with China-linked operators. It covertly leverages compromised consumer devices as proxy exit nodes, allowing downstream customers and threat actors to route traffic through legitimate residential IP space to conceal origin and evade network-based defenses. At peak scale it was described as one of the largest networks of its kind, and by mid-2026 it had recovered from earlier disruption activity to exceed its prior size at roughly 10 million daily IPs.
The ecosystem around IPIDEA is built from compromised edge and consumer devices, including IoT and SOHO routers, Android devices infected through backdoored applications or malicious SDKs, and Android TV-class hardware. The network functions as part of a broader criminal proxy supply chain in which operators both maintain their own infected device pools and resell access to other proxy services, increasing resilience and making disruption difficult. IPIDEA has also been observed as a supplier to other proxy brands and reseller ecosystems.
Operationally, IPIDEA provides external proxy infrastructure used to mask malicious activity. Residential proxies from IPIDEA have been linked to fraud operations, including payment-card monetization workflows, and the broader malicious proxy ecosystem has been used by cybercriminal and espionage-linked actors for activities such as password spraying, covert access, scraping, and other abuse that benefits from residential IP reputation. Following a January 2026 disruption, IPIDEA reportedly lost about a quarter of its victim population but rebuilt capacity within months and shifted to new command-and-control infrastructure between March and May 2026, illustrating strong operator adaptability.
IPIDEA primarily targets and runs across consumer and embedded platforms rather than traditional enterprise endpoints, with especially strong evidence for Android and IoT/SOHO device compromise. Its role is best understood as botnet-backed proxyware enabling anonymization, abuse infrastructure, and downstream criminal operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
In January 2026, Synthient published research showing that multiple new large DDoS botnets had grown rapidly by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners and infecting other Android-based devices behind the user’s firewall.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet de proxies résidentiels malveillants à très grande échelle, utilisé pour fournir des IPs résidentielles via des appareils compromis et reposant sur une infrastructure C2 renouvelée après perturbation.
A China-linked residential proxy network referenced as another example of a disrupted proxy ecosystem similar to the one involving Popa/NetNut.
A previously disrupted proxy network mentioned as a related precedent to the NetNut/Popa takedown.
Another malicious residential proxy network referenced as an earlier disruption and described as a main competitor to NetNut in the residential proxy ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.