How residential proxy networks are hiding hackers in your home
The U.S. government and a bunch of large internet providers, phone companies, and cable network operators are freaking out about a rising threat that they know is there but can't really see all that well.
We're talking about residential proxy networks — also known as "resproxies," or "huge pain in my ass," depending on who you talk to at these companies. Residential proxy networks allow other people to rent access to your home or office internet connection. These proxy networks are enabled by software embedded in a bunch of always-on internet-connected devices, like off-brand consumer electronics and Android-powered streaming boxes, all the way through to phone and smart TV apps, browser extensions, and pirated video games.
You might not think too much about the knock-off digital picture frame in your house. But it's exactly this kind of unsuspecting internet-connected device that is among a dizzying number of products secretly sharing your home and office internet connections — and sometimes enlisting these networks into worldwide botnets of cybercrime.
By piggybacking home and office internet connections, residential proxy networks allow hackers, spies, and cybercriminals to make their attacks look like they're coming from sleepy American suburbs that are unlikely to raise alarm bells, unlike a flood of pings coming from Moscow, Tehran, or Pyongyang. The malicious traffic from the proxy blends in with the rest of the home or office network's traffic, making it far more difficult to know where the malicious activity is really originating. It's the digital equivalent of allowing people into your home, not realizing that they're criminals wanting to use your house to hide from the cops.
As The Wall Street Journal ($) recently put it, resproxies are "turning everyday electronics into a global threat." Some estimates put these networks in the tens of millions of devices, representing a significant security risk to network owners — and to anyone on the receiving end of a malicious botnet powered by a residential proxy network.
This obviously isn't good if your home network is being abused by government-backed hackers or cybercriminals, and might get you a visit from the FBI (which is never fun). You could also have your home or office network flagged as suspicious, or blocked by your internet provider, sending you offline until you resolve it.
Resproxy code also puts other devices on the same home or office network at risk of being compromised, hijacked, or manipulated.
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent blogs include: When AI chatbots and LLMs get legal, check your privilege | Most fitness wearables lack end-to-end encryption and don't disclose government data demands | U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents | Online ads giant Adform was hacked, proving once again why ad blockers are necessary | A beginner's guide to analyzing the network traffic of apps and websites
Realizing the scale of the problem, internet providers and tech companies have been fighting back by working with the authorities to conduct takedowns and enforcement actions targeting the bigger-game residential proxy networks. Some companies are taking their own steps in response to abuses. Electronics giants Samsung and LG banned resproxies from their smart TV app stores after researchers found their stores littered with bad apps.
But the problem is spiraling and becoming an issue that the tech and telecom companies alone cannot contain. Researchers at Google say proxy networks "are overwhelmingly misused by bad actors." One CISO told me recently that resproxies have become an industry wide problem, and that the feds and corporate giants are cracking down on them because almost all of them facilitate malicious operations. It was the CISO's view that any ostensibly legitimate uses for residential proxy networks do not justify their overall pain.
Let's find out more about the problem with residential proxy networks, and what we can all do to take action.
In this article for Astonishing admin subscribers, we'll explore more about how residential proxy networks operate, and how and why resproxies pose a threat — not just to their targets, but also to you, including your home or office network. I also have a ton of guidance on how to check if your network has been flagged as being abused by a resproxy, and what you can do to fix it.