Over 15 free VPN apps on Google Play were found using a malicious software development kit that turned Android devices into unwitting residential proxies, likely used for cybercrime and shopping bots. Residential proxies are devices that route internet traffic through devices located in homes for other remote users, making the traffic appear legitimate and less likely to be blocked. While they have legitimate uses for market research, ad verification, and SEO, many cybercriminals use them to conceal malicious activities, including ad fraud, spamming, phishing, credential stuffing, and password spraying. Users may voluntarily register on proxy services to get monetary or other rewards in return, but some of these proxy services employ unethical and shady means to install their proxying tools on people's devices secretly. When secretly installed, victims will have their internet bandwidth hijacked without their knowledge and risk legal trouble due to appearing as the source of malicious activity. A report published today by HUMAN's Satori threat intelligence team lists 28 applications on Google Play that secretly turned Android devices into proxy servers. Of these 28 applications, 17 were passed off as free VPN software. Satori analysts report that the offending apps were all using a software development kit (SDK) by LumiApps that contained "Proxylib," a Golang library to perform the proxying. HUMAN discovered the first PROXYLIB carrier app in May 2023, a free Android VPN app ...
Free VPN apps on Google Play turned Android phones into proxies
BleepingComputer
·Bill Toulas
·Published Mar 26, 2024
·Updated
Affected Software
2 affected components
LumiApps SDK
Various Android Apps
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how over 15 free VPN apps on Google Play were using malicious SDKs to turn Android devices into proxies.
2
What security implications are discussed in the article?
The article highlights the potential for these compromised VPN apps to facilitate cybercrime and other malicious activities using residential proxies.
3
What products or software are affected?
The affected products include various Android apps that used the malicious LumiApps SDK for creating proxies.
4
How do these malicious VPN apps operate on Android devices?
These VPN apps use a software development kit (SDK) to transform the devices into unwitting residential proxies.
5
What are the potential consequences for users of these compromised VPN apps?
Users may unknowingly contribute to cybercrime activities and face privacy risks due to their devices being exploited as proxies.