Key facts
- Media streaming devices, such as the SuperBox S7 Pro, are being used to create residential proxy networks.
- These devices often have Android security features disabled, granting extensive system rights to installed applications.
- Attackers can exploit open ADB ports and root access to install malware, including variants of Mirai and Maskify.
- Home networks connected to these devices are vulnerable to further infections and participation in botnets.
- Security researchers observed a significant number of attempts to exploit these vulnerabilities.
Free media streaming devices, such as the SuperBox S7 Pro, are increasingly being used to create residential proxy networks, posing significant security risks to home networks. These devices, often offered in exchange for free content, funnel home internet connections into a unified network that attackers can rent to route malicious traffic, making it appear as legitimate activity.
Security firm Plume's research highlights a vast ecosystem of malware targeting these devices. Malicious apps can be installed remotely, even when the devices are behind a router. The Android-based SuperBox, for instance, comes with most of its security protections disabled, allowing pre-installed apps or those from its app store to run with root privileges. This grants them unfettered administrative rights, enabling them to install other apps, surveil, and join the local network.
Key Android defenses such as signature verification, the "unknown sources" restriction, permission review dialogs, and Play Protect scanning are neutered. The device's ADB (Android Debug Bridge) is exposed to the internet, and the mechanism for gaining root access requires no authentication. This combination allows both proxy service customers and malicious apps to execute virtually any command on the device.
Even when users position these devices behind their home routers, the security is false. Apps with built-in proxy functions maintain open, encrypted outbound connections to proxy servers, which routers cannot block. Researchers confirmed this vulnerability by setting up a honeypot, which recorded 1,352 distinct attempts to access the ADB port over three weeks. Intruders attempted to install malicious apps like CECbot, a variant of Mirai, and Maskify, turning the devices into nodes for other proxy networks or botnets used in DDoS attacks.
Plume warns that these residential proxy networks are not just monetization tools but active targets for malware delivery. The devices owners are often unaware that their connections are being used to facilitate crime or even nation-state attacks, and their IP addresses gain a reputation reflecting the malicious activities. While some proxy services try to prevent access to local networks, vulnerabilities exist that allow attackers to bypass these measures. The firm strongly advises users to disconnect and discard such devices.
