Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Malicious macOS ClickFix Domains Hide Atomic Stealer Attacks via Browser Fingerprinting
August 6, 2026
CISA Warns of Critical TeamCity RCE Vulnerability, CVE-2023-42793, Actively Exploited
August 6, 2026
Apple iCloud Private Relay WebKit Flaws Expose User IP Addresses
August 6, 2026
Home/CyberSecurity News/Free Apps on Samsung, LG Smart TVs Covertly Used for AI Proxy Abuse
CyberSecurity News

Free Apps on Samsung, LG Smart TVs Covertly Used for AI Proxy Abuse

Key Takeaways Millions of smart TVs and mobile devices are being covertly leveraged as residential proxy nodes by free apps. The Bright Data SDK, embedded in popular applications, routes third-party...

Sarah simpson
Sarah simpson
June 6, 2026 4 Min Read
64 0

Key Takeaways

  • Millions of smart TVs and mobile devices are being covertly leveraged as residential proxy nodes by free apps.
  • The Bright Data SDK, embedded in popular applications, routes third-party web-scraping traffic through users’ home internet connections.
  • Connected TVs are targeted due to their always-on nature and lack of security oversight, with traffic relaying even occurring during active use.
  • Users can mitigate this by blocking specific DNS hostnames and TLS SNI at their router level.

Millions of smart televisions and mobile devices are being silently co-opted into a vast commercial residential proxy network, facilitating data scraping for artificial intelligence training. This revelation comes from new research by Include Security, which uncovered that free applications across major smart TV platforms like Samsung, LG, and Roku are embedding an SDK that transforms user devices into proxy nodes.

Table Of Content

  • Key Takeaways
  • Bright Data SDK at the Core of the Operation
  • Exploitation Details and Partner Network
  • What You Should Do

The enrollment process for these devices often involves a consent dialog that is deliberately obscured, requiring users to navigate deep within menu structures using a TV remote’s arrow keys.

Bright Data SDK at the Core of the Operation

The primary component enabling this covert activity is an SDK developed by Bright Data, a Tel Aviv-based firm. Bright Data actively promotes what it claims is the world’s largest residential proxy network, boasting over 150 million IP addresses sourced through embedded software in various partner applications.

Once installed, this SDK covertly reconfigures a user’s connected TV (CTV) or mobile device, turning it into an exit node. This allows Bright Data’s paying clientele to route their web-scraping traffic through the user’s personal internet connection, effectively masking the origin of the data requests.

Researcher Buchodi, collaborating with Include Security, highlighted why connected TVs are particularly attractive targets compared to smartphones. TVs remain continuously powered, are always connected to Wi-Fi, operate in standby mode 24/7, are largely exempt from corporate or mobile device management (MDM) oversight, and typically receive minimal direct user interaction after initial setup.

Exploitation Details and Partner Network

Analysis of the SDK’s configuration confirms its exploitative nature. Idle threshold flags are set to ignore_screen_on: true and ignore_on_call: true. This means a device is deemed eligible to relay third-party traffic even when a user is actively viewing content or engaged in a call, ensuring continuous proxy availability.

The default monthly bandwidth allocation for Wi-Fi relaying is capped at 200 GB per device. This figure was extracted from configuration values retrieved from Bright Data’s unauthenticated public endpoint at clientsdk.bright-sdk.com.

This same unauthenticated endpoint also exposed a partner manifest, which researchers identified as including several prominent entities:

  • PlayWorks Digital: Manages over 400 CTV game titles distributed across Samsung, LG, Comcast, Roku, and Sky, reaching an estimated 250 million TV households.
  • CloudTV: Integrated across more than 125 TV brands and 15 original equipment manufacturers (OEMs).
  • Viber Media (Rakuten): Boasts between 250 million and 820 million monthly active users.
  • Moonfrog Labs: Reports approximately 10 million monthly active users for its “Teen Patti Gold” game alone.
  • Hola Networks: Identified as Bright Data’s parent company.

The SDK establishes a persistent WebSocket connection to proxyjs.brdtnet.com:443, which resolves to AWS Global Accelerator IPs and presents a TLS certificate for *.luminatinet.com. Notably, Luminati Networks was Bright Data’s corporate name prior to 2018.

This legacy hostname provides a critical detection pivot for cybersecurity defenders. Any network traffic directed to luminatinet.com or brdtnet.com specifically indicates the SDK’s peer-tunneling activity, distinct from legitimate Bright Data customer traffic.

Crucially, the SDK utilizes Apple’s NWParameters.requiredInterface API to directly bind the data plane to the physical Wi-Fi or cellular interface. This mechanism effectively bypasses any user-configured VPN, ensuring that the proxy traffic flows unhindered. Furthermore, the control plane employs CFHTTPMessage primitives instead of URLSession, which circumvents standard iOS instrumentation tools. This combination ensures that the SDK’s most sensitive communication channels remain largely invisible to typical security monitoring layers.

Include Security formally notified Bright Data of their findings on May 11, 2026, via [email protected]. As of the publication date, no response had been received.

What You Should Do

  • Block DNS Hostnames: Buchodi recommends blocking the following DNS hostnames at your router level: proxyjs.brdtnet.com, proxyjs.luminatinet.com, and clientsdk.bright-sdk.com.
  • Implement TLS Filtering: For networks supporting TLS-based filtering, configure your firewall or router to drop any handshake with Server Name Indication (SNI) matching *.brdtnet.com, *.luminatinet.com, or *.luminati.io.
  • MDM Administrators: For managed devices in enterprise environments, scan for Swift binary symbols such as BrdWebSocketFacade and BrdNetwork.DNSResolver to identify affected applications.
  • Review App Permissions: Be vigilant when installing free applications on smart TVs and mobile devices. Carefully review any consent requests, especially those related to network usage or data sharing, even if they are deeply nested in settings.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

ExploitSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

Next Post

ChatGPT Lockdown Mode to Mitigate Prompt Injection, Data Exfiltration

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Blogger Bug Locked Legitimate Sites, Mistaking Them for Malware
August 6, 2026
Cisco Patches Critical SD-WAN Vulnerabilities, Update Now
August 6, 2026
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us