SuperProxy: How Residential Proxy Networks Have Become Malware Delivery Platforms

Part 2 of Plume Security Lab’s SuperProxy Research Series

Overview

In Part 1 of Plume’s SuperProxy research series, the Plume Security Lab uncovered how SuperBox streaming devices silently enrolled users into residential proxy networks through bundled applications, allowing attackers to monetize home internet connections without user knowledge.

Part 2 reveals the next stage of the threat.

Our researchers found that these residential proxy networks are not simply monetization tools. They are also used as targets for additional malware delivery, enabling cybercriminals to infect already-compromised devices with entirely new malware families while remaining largely invisible to the device owner.

Read Now


About the Research

The Plume Security Lab conducted this research through reverse engineering, infrastructure analysis, controlled experiments, and live traffic monitoring of residential proxy activity observed on SuperBox streaming devices. The findings build on the first installment of the SuperProxy research series and continue Plume’s work exposing threats affecting connected homes worldwide.