Illustration of an employee connecting to a network as bandwidth is diverted into a residential proxy service

Your Employee’s Side Hustle Could Be Your New Attack Surface

Legitimate bandwidth-sharing app feeds commercial proxy network, exposing internal devices.

No phishing. No malware. No exploit. An employee turns a side hustle into passive income, and your company’s IP address becomes somebody else’s infrastructure.

That bargain has been around for years in the residential proxy economy. But new Silent Push research release Thursday suggests security teams need to keep a careful eye on legitimate bandwidth-sharing software that could give outsiders a path to internal network resources without triggering traditional malware defenses.

“We joined a bandwidth-sharing network to see what actually happens to your IP address. The answer should worry every security team that assumes ‘not malware’ means ‘not a risk’,” Silent Push researchers wrote.

Beyond the Break weekly cybersecurity newsletter — Subscribe

In a test of one commercial bandwidth-sharing tool Peer2Profit, it documented how the platform resold the bandwidth of one of its end users to a paid proxy service called AstroProxy that in turn resold the bandwidth.  

“After about 10 minutes of running the Peer2Profit Android app, our test IP appeared in our proxy enumeration datasets, tagged as ‘AstroProxy.'”

Over the 72-hour crawl, researchers tracked the IP addresses across three distinct networks: 60,247 residential, 38,762 data center, and 18,215 mobile connections. Russia and Vietnam accounted for more than 40% of residential IPs, followed by Portugal, Ukraine and Brazil. All traffic, according to Silent Push, flowed through legitimate internet carriers.

Side Hustle, Meet Attack Surface

Funneling traffic through a corporate IP carries its own risk, including credential-stuffing attempts and fraud attributed to an address the company doesn’t control. But Silent Push said what concerned it more was the potential of exposing corporate networks to a third party.

The risks associated with bandwidth-sharing apps goes beyond exposing a user’s public IP address. It potentially opens their entire local network. Anyone subscribing to the proxy service, like AstroProxy, could gain unintended network visibility.

“The success of this experiment means that a user running a bandwidth-sharing client is not only giving away the public IP address, but it is also potentially exposing every device on that network to anyone with access to the proxy service, including the router, NAS devices, smart home infrastructure, and any other internally accessible resource.”

In a corporate environment where employees work remotely via corporate VPNs or connect personal devices to office networks, the implications are considerably more serious, as internal company assets could also be exposed, researchers said.

Additionally, Silent Push found that AstroProxy offered exit-node targeting options that could make internal-network probing more precise. A threat actor, for example, could select proxies associated with a particular ISP, ASN or geography and use a single well-placed node to probe otherwise inaccessible internal resources.

A constant churn of new IPs makes reactive, reputation-based detection ineffective, researchers said. “By the time an IP is flagged for abuse, it has likely already been replaced in the proxy pool.”

Not Malware. Still Your Problem

“These apps are not malware. Peer2Profit installs through official channels with full user consent, which means standard antivirus tools and threat intelligence feeds don’t flag it, and any employee can install it on a corporate device without triggering a single alert,” researchers wrote.

Silent Push does not allege that AstroProxy, Peer2Profit or other services cited in its research are operating unlawfully. These are commercial services that describe their proxy sourcing clearly as consent-based and, in AstroProxy’s case, “ethically sourced.”

It should be noted, Silent Push did not document direct outreach to the companies, or the internet providers, or hosting firms mentioned in the report.

Silent Push said it will continue tracking both networks and published Peer2Profit backconnect infrastructure and software-sample hashes alongside its research.

Separately, a reviewed the terms of several major U.S. residential internet providers by SPB clearly state the use of bandwidth-sharing apps, the reselling or redistributing a residential connections violate the subscriber’s own service agreements for Comcast’s Xfinity, Spectrum  and AT&T. Starlink also prohibits customers from reselling access without authorization, although it allows certain resale under authorized Priority plans.

Passive Income, Active Attack Surface

The Silent Push findings don’t show related widespread corporate breaches. However, researchers raise the concern, if an employee device turns a trusted connection into infrastructure for strangers, does it matter that the software isn’t malware?

Silent Push’s findings arrive amid growing federal scrutiny of residential proxies.

In March, the FBI warned that threat actors use residential proxies to disguise phishing, credential stuffing and identity theft, and specifically cautioned against apps that pay users for “unused bandwidth.”

Then in July, the FBI, Google, Lumen and other partners disrupted NetNut, a residential proxy network tied to more than 2 million devices. Google said 316 threat clusters, including cybercriminal and espionage groups, used suspected NetNut exit nodes in a single week in June.

Neither action involved Peer2Profit or AstroProxy, but both underscore broader concern about residential proxy infrastructure.

Your Employee Made $5. Your IP Became Infrastructure

The findings extend a pattern Security Point Break has tracked this year. In June, Spur research found residential-proxy code in 34% of 6,038 LG and Samsung smart-TV apps, including games and screensavers using SDKs from Bright Data, Massive and Honeygain/Oxylabs.

Days later, a Digital Citizens Alliance and risk3sixty investigation estimated that 20 million or more U.S. IP connections are collected annually for residential proxy networks. Of connections researchers tested, 85% carried prior fraud indicators; the report also said no federal agency has clear ownership of the problem.

The same report examined Honeygain, another bandwidth-sharing app, and observed traffic involving T-Bank, a Russian bank sanctioned by the U.S. Treasury, passing through its test connection. The researchers said they found no indication Honeygain knew how those connections were being used.

Total
0
Shares
Previous Article
Cracked digital shield and broken padlock over medical records, illustrating the CareCloud healthcare data breach

CareCloud Data Breach Balloons to 3.7 Million, 10x Initial Estimate

Next Article
Illustration of a U.S. businessman arriving in Europe beneath an EU compliance countdown clock, representing the Cyber Resilience Act Sept. 11 deadline.

The Cyber Resilience Act: America's Next EU Compliance Headache

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading