Free streaming boxes may rent out your home internet

Published

The bargain with a cheap streaming box has always been obvious enough: you get television you did not pay for, and somebody gets something from you. Researchers now have a specific answer to what that something is. On certain SuperBox devices, it appears to be your home internet connection, resold to whoever wants to use it.

Malwarebytes has pulled together findings on the devices and the apps distributed through SuperBox's own app store. An earlier analysis identified CyberFlix TV, available from that store, as carrying Popanet proxy functionality that registers the device with a server run by a proxy operator. More recent research from Plume warns that these proxy networks can also act as delivery platforms for malware, which means an attacker may not only route traffic out through a household box but also reach back through that same connection to install something on it.

Your address, somebody else's behavior

Residential proxy networks rent out ordinary home IP addresses. Traffic sent through them looks like it came from a consumer broadband line rather than a data center, which is exactly why fraud and reputation systems struggle with it. Criminals pay for that. The FBI has warned that consumer devices including streaming boxes, tablets, routers and digital photo frames are used this way, and that once a device is enrolled, the household's address can end up carrying activity the household knows nothing about.

That is the practical harm, and it is not abstract. Credential stuffing runs, account abuse and attempts to slip past corporate security controls can all leave a trail that ends at a residential connection, and it is the person paying the broadband bill whose address is on it. The bandwidth cost is the least of it.

The safeguards Android normally provides were switched off

What makes the reported SuperBox configuration worse than a bad app is the state of the device underneath it. Researchers found exposed Android Debug Bridge access, root privileges available without any authentication, and the removal of the protections that would normally stop untrusted apps installing or at least prompt the user before something risky happens. On a stock Android device those three things are what stand between a dubious app and full control of the hardware.

The usual reassurance, that a device behind a home router cannot be reached from outside, does not apply here either. Network address translation and a firewall do make unsolicited inbound connections hard. But a proxy-enabled box holds open an encrypted outbound connection to a remote server, and the router treats that as ordinary traffic that started inside the house. The channel is already open, and it was opened from the inside.

A factory reset may not be enough

The advice from Malwarebytes is blunt. If you own a SuperBox device or have installed CyberFlix TV, disconnect it from the network, and treat replacement rather than a factory reset as the safe option, because a reset may not remove the problem.

Network segmentation is the standard answer for untrustworthy smart-home gear, and it genuinely helps for a badly written doorbell or thermostat. It does not solve this one. A product designed to hold open a persistent proxy channel and shipped with its device protections disabled is still selling your connection from a guest network. The exposure is the business model, not a bug in it.

The wider pattern is by now familiar. IntelFusions has covered an Android TV box botnet that learned to imitate real browser traffic and, more unusually, car head units turned into proxy nodes by their own software updater. Cheap consumer hardware with a thin margin and a permanent internet connection is a good place to build a proxy network, and the people building them have noticed.

The full write-up, including the guidance for anyone who owns one of these boxes, is published by Malwarebytes.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions