Search a name like “Mimic VPN” or “NordLynx VPN” and it looks, for a second, like you’ve found a new provider. It isn’t one. These are protocols and connection modes built into VPN apps you may already know, not standalone products with their own pricing page or app store listing.
Confusing the two matters. If you go looking for reviews, pricing, or a download page for “Mimic” as if it were an independent company, you’ll either find nothing useful or, worse, land on a lookalike site cashing in on the confusion. Here’s what these names actually are.
The quick way to tell the difference
A real VPN provider has its own website with a pricing page, its own app in the App Store and Google Play under its own name, and its own privacy policy and company registration. A protocol or feature name doesn’t. It only exists inside the settings menu of a VPN app, usually as a toggle or a dropdown option, and searching for it alongside the parent brand’s name is the fastest way to confirm which one you’re looking at.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Names that are protocols, not providers
Mimic (Norton). A proprietary protocol inside Norton Secure VPN. It wraps your VPN traffic so the connection resembles ordinary HTTPS, the same encryption every bank or shopping site uses, using AES-256 combined with post-quantum key generation (CRYSTAL-Kyber-512) so the packets don’t carry the recognizable signature a firewall would flag as “VPN.” An independent audit by Versprite found it posed no privacy risk to users. It’s slower than WireGuard and only exists inside the Norton Secure VPN app; there’s no separate “Mimic” product to buy. We cover it in full in Norton’s Mimic Protocol Passes an Audit.
NordLynx (NordVPN). NordVPN’s implementation of WireGuard. Standard WireGuard has one real weakness: it needs to permanently assign each connected device a static internal IP address to work, which is a small but real privacy gap. NordLynx solves this with a double network-address-translation (double NAT) system, cycling those internal IPs so none of them stay tied to your device. It’s a setting inside the NordVPN app, not a separate service, and it’s what powers the speeds behind NordVPN’s 4.6/5 score in our testing.
Lightway (ExpressVPN). ExpressVPN’s own protocol, written from scratch in around 2,000 lines of code rather than built on WireGuard or OpenVPN. The small codebase is the point: fewer lines means a smaller attack surface and faster connection and reconnection times, particularly useful when switching between Wi-Fi and mobile data. Exclusive to ExpressVPN’s app; it has been through independent audits of its own.
Nexus and Camouflage Mode (Surfshark). Two different features, often confused with each other. Nexus is Surfshark’s WireGuard-based infrastructure layer that rotates your traffic through multiple servers instead of one fixed exit point. Camouflage Mode is separate: it automatically obfuscates OpenVPN traffic so your ISP can see you’re online but can’t identify VPN usage specifically. Both live inside the Surfshark app only.
Chameleon (VyprVPN). A modified version of OpenVPN that scrambles packet metadata, the header information a firewall reads to identify a protocol, so the traffic doesn’t match known VPN signatures. Built specifically to get past deep packet inspection in countries like China and Iran. VyprVPN-only, and not sold or licensed separately.
Catapult Hydra (Hotspot Shield). Hotspot Shield’s proprietary protocol, engineered to hold speed and stability on poor-quality or high-latency connections rather than to disguise traffic. It uses standard AES-256 encryption, but because it’s closed and proprietary, it hasn’t been through the same level of public, third-party cryptographic scrutiny as an open protocol like WireGuard, which is worth factoring in if you’re evaluating Hotspot Shield specifically on trust rather than speed.
Stealth (ProtonVPN). Proton’s own obfuscation protocol, built in-house rather than adapted from OpenVPN, and notably available even on Proton’s free tier. Designed to disguise VPN traffic as regular web traffic in restrictive networks without the speed cost some obfuscation methods carry.
GhostBear (TunnelBear). TunnelBear’s obfuscation feature, which wraps OpenVPN traffic using a technique related to Obfsproxy (originally built for Tor): randomizing packet headers, padding payloads to a uniform size, and mixing in dummy data so DPI filters can’t fingerprint the traffic as a VPN. Available on TunnelBear’s Windows, macOS, and Android apps specifically.
StealthVPN (Astrill). Astrill’s proprietary protocol, based on OpenVPN with XOR-based scrambling and adjusted packet sizes aimed specifically at defeating China’s DPI infrastructure. Runs over both UDP and TCP. Astrill-exclusive.
DAITA and bridges (Mullvad). Not obfuscation in the classic disguise-as-HTTPS sense, but a related and more advanced idea. DAITA (Defense Against AI-guided Traffic Analysis) pads packets and injects decoy traffic to resist machine-learning-based pattern matching, the kind of analysis that can sometimes identify VPN use even through encryption by looking at traffic shape alone. Bridges route around network-level blocking the way Tor bridges do. Mullvad-only, and aimed at a deeper threat model than simply getting past a hotel firewall.
WireGuard, OpenVPN, IKEv2. Worth naming precisely because they’re the opposite case: open, non-proprietary protocols that any provider can implement, not owned or built by a single company. WireGuard is the lean, modern default nearly every top provider uses as its base layer, even under a different name (NordLynx and Lightway are both WireGuard-adjacent). OpenVPN is the older, thoroughly audited standard still used for router setups and restrictive networks. IKEv2 is built into iOS and macOS and specializes in reconnecting fast when you switch networks. If you see one of these names, it tells you what technology a specific provider is using, not which company you’re dealing with. Our full protocol breakdown covers how they compare in depth.
Shadowsocks. Not built by any VPN company at all. Shadowsocks is an open-source proxy protocol originally created in China specifically to get around the Great Firewall, by disguising traffic as ordinary encrypted web traffic rather than using a recognizable VPN handshake. Some VPNs (including Private Internet Access) offer it as a connection option, and it’s also the basis for standalone circumvention tools like Outline (below). Free, technical to configure manually, and not tied to a single provider.
VLESS and V2Ray. Another open protocol family built for censorship circumvention rather than general-purpose VPN use, widely used in China and other heavily filtered networks. VLESS is a lightweight transport protocol; V2Ray (and its successor Xray) is the software platform that implements it. China has specifically targeted VLESS traffic with more aggressive blocking as of 2026, which we cover in China Blocks the VLESS Protocol. Not something a typical consumer VPN user needs to touch directly, but a name that turns up often in circumvention discussions.
SSTP. Secure Socket Tunneling Protocol, built by Microsoft and native to Windows. It tunnels traffic through SSL/TLS on port 443, which makes it reasonably good at getting past basic firewalls, though it’s Windows-centric and less commonly offered by major providers today than WireGuard or OpenVPN.
SoftEther. Free, open-source VPN server software originally developed as a university research project in Japan. It supports multiple protocols at once (including its own SoftEther protocol, OpenVPN, and L2TP/IPsec) and is more often self-hosted by technical users than offered as a feature by consumer VPN apps.
Why this confusion happens
Providers name their proprietary protocols the way companies name product features anywhere else, and marketing pages don’t always make clear that the name refers to a setting rather than the product itself. A page announcing “Introducing Mimic” or “NordLynx is here” reads, out of context, exactly like a product launch. Search engines then index those pages under the protocol name alone, and someone who searches that name later has no obvious way to tell they’re looking at a feature rather than a company.
There’s also a real reason to look this up: obfuscated and proprietary protocols solve a genuine problem, getting a VPN to work on networks or in countries that actively try to detect and block VPN traffic. If that’s why you searched, the feature is worth using. It’s just not something you buy on its own.
What to check if you’re not sure
Search the name alongside “VPN” and see whether the results describe a standalone company with pricing, or a feature page on an existing provider’s website. Check whether the name appears inside a settings menu of an app you already have installed rather than as something you’d download separately. And if a site tries to sell you a name from this list as if it were an independent VPN with its own subscription, that’s a strong sign the site itself isn’t trustworthy. Our checklist for vetting an unfamiliar VPN covers exactly that kind of red flag in more depth.
Mimic, NordLynx, Lightway, Nexus, Camouflage Mode, Chameleon, Catapult Hydra, Stealth, GhostBear, StealthVPN, and DAITA are all protocols and features, not companies. Each one lives inside one specific provider's app: Norton, NordVPN, ExpressVPN, Surfshark, VyprVPN, Hotspot Shield, ProtonVPN, TunnelBear, Astrill, and Mullvad respectively. WireGuard, OpenVPN, IKEv2, Shadowsocks, VLESS, SSTP, and SoftEther are the opposite case: open protocols any provider can use, not owned by one. If you found one of these names while researching, you were looking at a feature of a VPN that's likely already on our comparison table, not a new provider to vet from scratch.
See NordVPN, which runs NordLynx by default or try ProtonVPN, including its free Stealth protocol.
Keep reading: VPN Protocols Explained 2026: WireGuard, OpenVPN, IKEv2 Compared and Obfuscated Servers Explained: How to Make Your VPN Invisible to VPN Blockers.