As cited
Citation snapshot as of .
threat intel
New Research: How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product
Researchers found that Peer2Profit, a bandwidth-sharing app installed legitimately by users, feeds proxy nodes into Astroproxy, a commercial proxy service, with a markup of up to 27 times the user payment. Over 72 hours, the enumeration detected 117,224 unique IPs across Astroproxy's pools, with the residential pool adding over 1,000 new IPs per hour, making traditional reputation-based detection ineffective. The infrastructure poses a concrete risk: any employee can install Peer2Profit on a corporate device undetected by antivirus, turning the organization's IP space into a proxy exit node, and researchers demonstrated that Astroproxy's internal IP filter can be bypassed using DNS to access corporate routers and internal resources.
Why it matters: Security teams must audit for Peer2Profit and similar bandwidth-sharing apps installed by employees on corporate devices or personal devices on the network, since they are not flagged as malware and expose internal resources to proxy subscribers; defenders should implement proactive enumeration of proxy networks rather than relying solely on reactive IP reputation signals.
- Source published
- First seen by Cybersecurity Tracker