All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Media streaming devices pose security risks via proxy networks

Created at 31 Aug · 4:41 PM1 source↑ Market-relevant
IN SHORT

Free media streaming devices like SuperBox S7 Pro can compromise home networks by acting as proxy servers for malicious traffic, according to security firm Plume. These devices often have security features disabled, allowing attackers to install malware and gain access to local networks.

Key Numbers

1,352distinct attempts to reach ADB through a honeypot
3weeks honeypot ran for data collection
2 milliondevices potentially running Popanet proxy service

Who's Involved

Plume
security firm that published research on media streaming device vulnerabilities
SuperBox S7 Pro
media streaming device identified as a security risk
Gergely Eberhardt
Plume researcher who detailed ADB port exploitation
CECbot
malicious app found on compromised SuperBox devices
Mirai
botnet malware variant found on compromised SuperBox devices
Maskify
malware found on compromised SuperBox devices
Media streaming devices pose security risks via proxy networks

↳ Why This Matters

The widespread use of compromised media streaming devices as proxy servers creates a significant threat to home network security, enabling cybercriminals to conduct illicit activities while remaining largely invisible to device owners. This practice undermines online security and can lead to further infections and participation in malicious botnets.

Key facts

  • Media streaming devices, such as the SuperBox S7 Pro, are being used to create residential proxy networks.
  • These devices often have Android security features disabled, granting extensive system rights to installed applications.
  • Attackers can exploit open ADB ports and root access to install malware, including variants of Mirai and Maskify.
  • Home networks connected to these devices are vulnerable to further infections and participation in botnets.
  • Security researchers observed a significant number of attempts to exploit these vulnerabilities.

Free media streaming devices, such as the SuperBox S7 Pro, are increasingly being used to create residential proxy networks, posing significant security risks to home networks. These devices, often offered in exchange for free content, funnel home internet connections into a unified network that attackers can rent to route malicious traffic, making it appear as legitimate activity.

Security firm Plume's research highlights a vast ecosystem of malware targeting these devices. Malicious apps can be installed remotely, even when the devices are behind a router. The Android-based SuperBox, for instance, comes with most of its security protections disabled, allowing pre-installed apps or those from its app store to run with root privileges. This grants them unfettered administrative rights, enabling them to install other apps, surveil, and join the local network.

Key Android defenses such as signature verification, the "unknown sources" restriction, permission review dialogs, and Play Protect scanning are neutered. The device's ADB (Android Debug Bridge) is exposed to the internet, and the mechanism for gaining root access requires no authentication. This combination allows both proxy service customers and malicious apps to execute virtually any command on the device.

Even when users position these devices behind their home routers, the security is false. Apps with built-in proxy functions maintain open, encrypted outbound connections to proxy servers, which routers cannot block. Researchers confirmed this vulnerability by setting up a honeypot, which recorded 1,352 distinct attempts to access the ADB port over three weeks. Intruders attempted to install malicious apps like CECbot, a variant of Mirai, and Maskify, turning the devices into nodes for other proxy networks or botnets used in DDoS attacks.

Plume warns that these residential proxy networks are not just monetization tools but active targets for malware delivery. The devices owners are often unaware that their connections are being used to facilitate crime or even nation-state attacks, and their IP addresses gain a reputation reflecting the malicious activities. While some proxy services try to prevent access to local networks, vulnerabilities exist that allow attackers to bypass these measures. The firm strongly advises users to disconnect and discard such devices.

Frequently asked questions

A residential proxy network uses internet connections from ordinary homes to route traffic. This makes malicious activity appear to originate from legitimate IP addresses with good reputations.

These devices often have their built-in security features disabled, allowing them to be easily compromised and used to relay traffic for proxy services, sometimes in exchange for free content.

Compromised devices can allow attackers to install additional malware, access other devices on the local network, and use the home's IP address for illegal activities, potentially leading to the IP being blacklisted.

It is difficult for most users to detect, as the traffic is often encrypted and disguised. Even savvy users may not see obvious signs of inbound connections.

What Happens Next

01Users are advised to disconnect and discard affected media streaming devices.
02Further research may reveal similar vulnerabilities in other streaming devices.
03Security firms will likely continue to monitor and report on the evolving threat landscape of residential proxy networks.

How It Developed

Attackers are using residential proxy networks to route malicious traffic through home internet connections.
Security firm Plume identified malware targeting SuperBox media players, which can be installed remotely.
These devices often have Android security protections disabled, allowing apps to run with administrative rights.
Exploiting open ADB ports and root access, attackers can install additional malware and join botnets.
Some proxy services attempt to block local network access, but vulnerabilities allow attackers to bypass these protections.
Researchers observed over 1,300 attempts to access ADB ports through a honeypot over three weeks.
Malicious apps like CECbot, Mirai, and Maskify were found to be installed on compromised devices.
Experts warn that these devices pose a tangible threat and recommend users disconnect and discard them.

Sources

T1
How some media streaming devices open home networks to a world of harmvar abtest_2169812 = new ABTest(2169812, 'impression');Ars Technica

Related Stories

Raindrops act like tiny lightning bolts, corroding cars, study finds
31 Aug · 5:16 PM
NASA's Roman Telescope Launched to Study Dark Energy and Dark Matter
31 Aug · 1:06 PM
Massive 12TB Steam data leak reveals lost PC gaming history
30 Aug · 9:46 PM
Australian police arrest two men accused of widespread open-source software hacking
31 Aug · 4:11 PM
Meta's Pocket AI turns game ideas into playable prototypes
31 Aug · 10:11 AM