Estimated reading time: 7 minutes
Silent Push researchers pointed a proxy connection at a home router in Portugal. They reached its management interface. Then they pulled an image file off it as proof.
The router belonged to a customer of MEO, Portugal’s largest internet provider. The researchers held no credentials. They planted no malware. They held a subscription to a commercial proxy service, and someone on that network had installed an app to earn pocket money.
That is the shape of residential proxy risk. Silent Push published the research on August 14. It traces the path from Peer2Profit, a bandwidth sharing program, through to AstroProxy, a commercial service that sells the bandwidth on.

How Bandwidth Sharing Creates A Proxy Exit Node
Peer2Profit pays users to route traffic through their devices. Onboarding runs through a Telegram bot. A user registers, downloads a client, and starts earning. Rates vary by connection type. Cellular pays $0.35 per gigabyte. Residential pays $0.28. Hosting pays $0.10.
Silent Push tested whether that bandwidth surfaces in AstroProxy. Researchers enrolled a clean residential IP address as a Peer2Profit node in a controlled lab. Within roughly ten minutes, the address appeared in their own proxy enumeration data, tagged as AstroProxy.
The markup is the business model. AstroProxy sells residential traffic at $7.60 per gigabyte. Mobile sells at $13.44. Datacenter sells at $3.95. Silent Push calculates the operation retains over 97% of the value earned from selling that bandwidth.
The Scale Behind Residential Proxy Networks
Over a 72-hour crawl, Silent Push counted 117,224 unique IP addresses across three AstroProxy pools. Residential held 60,247. Datacenter held 38,762. Mobile held 18,215.
Churn is the part that defeats defenders. The residential pool added an average of 1,071 new addresses every hour. Reputation-based blocking works only after an address misbehaves. At that rate, the address has already rotated out of the pool.
Geography concentrates. Russia and Vietnam together account for more than 40% of observed residential addresses, followed by Portugal, Ukraine and Brazil. The nodes sit on large national carriers including Rostelecom, Viettel and VNPT. Those carriers serve millions of ordinary subscribers, which is precisely why the proxied traffic blends in.
Why Security Tools Do Not Flag Bandwidth Sharing
These clients are not malware. Users install them deliberately, through official channels. Antivirus does not flag them. The backconnect servers and registration APIs do not appear in standard threat intelligence feeds or reputation systems. To most security tooling, the traffic looks benign.
Nothing stops an employee from installing one on a corporate device, or on a personal device sitting on the corporate network. Once it runs, the organization’s address space becomes available as a proxy exit node. Abuse traffic, credential stuffing, and fraud then appear to originate from a corporate IP address.
Not every install is voluntary. Silent Push notes the Peer2Profit SDK spread through pay-per-install botnets including PrivateLoader, a pattern researchers flagged publicly in 2023. Windows and Linux SDKs are no longer offered through official channels.
Reaching Inside The Network
AstroProxy blocks proxy requests aimed directly at internal IP addresses. Silent Push found the filter simple to defeat.
Researchers used a domain name that resolved to the default internal address MEO assigns to residential router management interfaces. The request passed the filter. Through a node enrolled in Peer2Profit and sold via AstroProxy, they reached the router and downloaded a file from it.
Silent Push disclosed the finding to the provider ahead of publication and says no meaningful remediation followed. The firm writes that devices like these sit almost invisible to security teams and “expose internal resources to anyone with a proxy subscription.”
Joao Batista, senior threat analyst at Silent Push, describes the underlying mechanism as a DNS rebinding-style issue. A DNS record resolves to an internal IP and slips past filters built to block direct internal addressing.
“We demonstrated this specifically against router management interfaces, that’s what we tested and verified,” Batista told Cyber Insurance News. “Based on our test, it’s plausible that other internal devices, NAS boxes, VPN concentrators, internal servers, could be reachable the same way.”
That extension does not appear in the published research. For an organization whose staff work remotely, or who connect personal laptops to office networks, it changes the size of the question. Silent Push has made DNS the attack surface before, and the same principle applies here. The record does the work the attacker would otherwise have to.
Cyber Insurance News Podcast
Three questions for any business owner. Who owns which credentials? How are they being used? When were they last changed? Christopher Skipworth, CEO of Passpack, guarantees most owners cannot answer them.

What Underwriters Can And Cannot Know
Targeting sharpens the exposure. AstroProxy subscribers filter nodes by country, city, ASN and connection type. An attacker can select a node that sits topologically close to an intended target. One node inside the right network is enough.
Batista is careful about what the research does not establish.
“We haven’t personally worked an incident where this was the confirmed entry point,” he said. “Though the exposure we demonstrated, internal network access via proxy, is exactly the kind of vector that could lead to one.”
The cost side is unmeasured too. A company whose address lands on a blocklist through proxied abuse traffic faces a remediation bill nobody has published. Batista says delisting timelines vary widely by list operator, running from automatic within days to manual processes taking weeks. He declined to attach a cost figure without data behind it.
One further observation carries weight for policy language. AstroProxy advertises ethically sourced proxies gathered with user consent, in a KYC and AML compliant way. Batista says the Peer2Profit cashout app listed Russia and Vietnam among available payout countries during Silent Push testing. He frames that as an observation about what the app permits, not as confirmation of payouts to sanctioned individuals. Researchers did not test the payout flow end to end.
The demand side is already documented. SpyCloud expects residential proxies to remain core infrastructure for account takeover and infostealer operations through 2026. North Korean IT worker schemes rely on proxy networks to mask location at scale.
Which leaves one control question that almost nobody asks at bind. Does the applicant know whether any device on its network is currently selling bandwidth? Endpoint tooling will not answer it. Proxy pool enumeration will.
FAQ – Residential Proxy Risk
What is residential proxy risk?
It describes what happens when a device on a corporate or home network joins a commercial proxy pool. The organization’s IP address becomes available as an exit node. Traffic routed through it appears to originate from that organization, including abuse traffic and credential stuffing attempts.
How does a device end up in a proxy pool?
An employee installs a bandwidth sharing app such as Peer2Profit and earns cents per gigabyte routed. Some free VPN apps also bundle software development kits that enroll devices in the background. Users consent deep in the terms and rarely realize what they agreed to.
Why do antivirus tools miss these programs?
They are not malware. Users install them deliberately through official channels. Silent Push notes the backconnect servers and registration APIs do not appear in standard threat intelligence feeds. To most security tooling, the resulting traffic looks entirely benign.
Can a proxy node reach inside the network it sits on?
Silent Push demonstrated it. Direct internal IP requests are blocked, but a domain name resolving to an internal address bypassed that filter. Researchers reached a router management interface and downloaded a file from it as proof of access.
Has this caused a cyber insurance claim?
Not that Silent Push can confirm. Senior threat analyst Joao Batista says the firm has not worked an incident where a bandwidth sharing client was the confirmed entry point. He describes the demonstrated internal access as the kind of vector that could lead to one.
Related Cyber Insurance Posts
- Data Center Cyber Claims Rank Second. The Larger Exposure Is Invisible.
- Silent Push 6.0 Gives Cyber Underwriters Sharper Threat Intelligence(Opens in a new browser tab)
- Cyber Risk and Incident Response Boost: LevelBlue Acquires Aon Consulting Units(Opens in a new browser tab)
- Lumen Warns Edge Device Security Risks Now Define Cyber Risk Exposure(Opens in a new browser tab)
- The Call Is Coming from Inside the Office: Tackling Insider Cybersecurity Threats(Opens in a new browser tab)