Technology

Your phone may have been someone else’s proxy: Google shuts down the IPIDEA network

Google’s threat-intelligence team has dismantled one of the world’s largest "residential proxy" networks, which turned millions of infected phones and PCs into anonymous relays for fraud. Why these networks are so hard to spot, and how to tell if your device was part of one.

Your phone may have been someone else’s proxy: Google shuts down the IPIDEA network

The most valuable thing a hacker can steal from your phone is not your photos. It is your innocence — the fact that traffic from a home internet connection in Dhaka or Dallas looks like an ordinary person, not a criminal. Google’s Threat Intelligence Group (GTIG) has now shut down a network called IPIDEA that was built on exactly that idea, using millions of smartphones and personal computers around the world as unwitting relays.

What a residential proxy network is

Legitimate proxy services rent out IP addresses in data centres. Fraud-detection systems have learned to treat those addresses with suspicion. A residential proxy sidesteps the problem by routing traffic through real homes and offices, so that a login attempt, a bulk account sign-up or a scraping run appears to come from a trustworthy consumer connection. According to Google, IPIDEA was among the largest of its kind, and it was used to hide the identity of people running online fraud, account takeovers, illegal data harvesting and credential theft.

How devices were recruited

The network spread through malicious Android apps and Windows software. Once installed, the proxy component ran permanently in the background — but it was deliberately frugal. Because it used little battery and little data, most owners never noticed that their device was carrying strangers’ traffic. Google also says the operators hid their command-and-control infrastructure carefully, which is why the network could grow so large before it was identified.

Why security tools struggle with this

Traditional botnets announce themselves: a device suddenly sends spam or joins a denial-of-service attack, and the traffic pattern looks abnormal. Proxy traffic is the opposite. Each relayed request is a single, normal-looking web request from a normal-looking address, indistinguishable from the owner browsing. The abuse is only visible in aggregate, from the vantage point of a company like Google that sees a very large slice of the internet.

What you can do

  • On Android, uninstall apps you did not knowingly choose, especially “free VPN”, “booster”, “cleaner” and pirated-app installers — the classic carriers of proxy malware.
  • Check Settings → Network → Data usage for apps with steady background traffic that have no reason to be online.
  • On Windows, review startup programs and remove cracked software; cracks are a favourite delivery vehicle.
  • Keep Google Play Protect on and install security updates promptly.

The takedown will not end the business. Residential proxies are in demand precisely because they work, and the next network is presumably already recruiting. The habit that protects you is dull and effective: only install what you actually need, from sources you can name.

Source: Prothom Alo

Written by

Tech BD

Editorial team of Tech BD.