The IPIDEA network is one of the biggest residential proxies worldwide and has been successfully taken down by Google in partnership with others. There were reportedly over 6.1 million updated IP addresses each day and over 69,000 new IP addresses added every day that were provided to criminal elements globally.
Residential proxies allow cybercriminals to mask their identity for attack purposes because they can route traffic through "monetized" or hijacked consumer devices, such as smartphones, desktop computers, and Internet of Things (IoT) devices. It is estimated that the IPIDEA network was utilized by more than 550 criminal enterprises around the world, including individuals from China, North Korea, Iran, and Russia, for purposes ranging from company espionage to password spraying, botnets, and advanced persistent threats (APTs).
How IPIDEA Operated
1. Proxy SDKs: They provided code that could allow the user to operate as a proxy by using multiple different applications (SDKs) such as Castar, Earn, Hex, and Packet SDKs.
2. Multi-brand infrastructure: They have multiple brands of residential proxies that they control including, but not limited to, 360 Proxy, ABC Proxy, Door VPN, Galleon VPN, Luna Proxy, and Radish VPN, as well as VPN Services.
3. Two Tier C2 network: In order for a device to be able to function properly, it would contact a Tier One server and then retrieve the Tier Two nodes and relay traffic and instructions sent by the servers. Google identified 7,400 Tier Two servers in use by IPIDEA.
4. Stealth tactics: Many of the applications created by IPIDEA contained Trojanized Window binaries that would disguise them as a legitimate utility, game, or content-based applications. For example, the applications that they created would often disguise themselves as OneDriveSync or Windows Update.
Impact of Threats
1. Some of the devices connected to the network and helped facilitate traffic routing for malicious traffic, DDoS attacks, and corporate network breaches; additionally, it allowed attackers to hide their location through the use of computers connected to the network.
2. Proxy networks were used to generate revenue for their creators; developers received payments for each installation of SDKs that converted their devices into exit nodes.
3. The network served as a platform for other botnets, including but not limited to BADBOX 2.0, located within China.
Google’s Action
1. Domains taken down: Including www.ipidea.io, plus dozens of Tier One control domains.
2. Play Protect update: Android apps containing IPIDEA SDKs are automatically flagged, removed, and blocked.
3. The focus of legal proceedings is directed at the people behind the operation to eliminate a market that allowed millions of compromised devices to partake in criminal activity.
Key Takeaways for Cybersecurity
1. As a result of their use in legitimate applications or IoT devices, residential proxies are considered a high threat for attacks.
2. Users should not download applications on apps that come from untrusted providers or that have a promise of earning "easy money for utilizing bandwidth you don’t need."
3. Organizations need to analyze their outbound traffic patterns for any abnormal proxy activity.
4. Mobile security solutions and endpoint detection and response (EDR) applications should identify any SDKs or binaries responsible for turning devices into proxy nodes.
Source: The Hacker News