Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Google Gemini installer deploys Vidar Stealer, steals browser data
August 21, 2026
Critical Vulnerability in Dameware Mini Remote Control Exposes Networks
August 21, 2026
Sakura Internet Breach Exposes 1.36 Million Customer Records
August 21, 2026
Home/Threats/Critical Vulnerability in Dameware Mini Remote Control Exposes Networks
Threats

Critical Vulnerability in Dameware Mini Remote Control Exposes Networks

Key Takeaways Employee-installed bandwidth-sharing applications like Peer2Profit can transform corporate devices into proxy exit nodes. This practice exposes an organization’s network by...

David kimber
David kimber
August 21, 2026 5 Min Read
3 0

Key Takeaways

  • Employee-installed bandwidth-sharing applications like Peer2Profit can transform corporate devices into proxy exit nodes.
  • This practice exposes an organization’s network by routing external, often malicious, traffic through its IP address.
  • The risk extends beyond simple bandwidth sharing, potentially allowing proxy users to access internal network resources via DNS bypass.
  • Traditional security tools often fail to flag these apps as malicious, necessitating a shift in enterprise security policies and monitoring strategies.

Employee-Installed Bandwidth Sharing Apps Create Enterprise Security Risks

A new report highlights a significant and often overlooked cybersecurity threat: consumer-grade bandwidth-sharing applications. These apps, when installed by employees on work devices, can inadvertently transform corporate endpoints into residential proxy gateways, exposing internal networks to external users and potential abuse. Unlike traditional malware, these applications operate with user consent, making them difficult for conventional security solutions to detect.

Table Of Content

  • Key Takeaways
  • Employee-Installed Bandwidth Sharing Apps Create Enterprise Security Risks
  • Peer2Profit and Astroproxy: A Dangerous Connection
  • The Pervasive Threat of Residential Proxy Networks
  • Bandwidth-Sharing Apps: A Gateway to Corporate Networks
  • DNS Bypass Raises Internal Network Access Risks
  • What You Should Do

Peer2Profit and Astroproxy: A Dangerous Connection

The core of this issue lies with applications like Peer2Profit, which financially compensate users for sharing their unused internet bandwidth. Research has revealed a direct operational link between Peer2Profit and Astroproxy, a service that resells these shared connections as residential, mobile, or datacenter proxies. This means that a device participating in Peer2Profit can have its IP address appear in Astroproxy’s pool, allowing paying customers to route their traffic through it.

Analysts at Silent Push said in a report that they confirmed this link by enrolling a test device with Peer2Profit and subsequently observing its IP address within Astroproxy’s proxy pool. This finding underscores how seemingly innocuous consumer software can introduce substantial enterprise security vulnerabilities without triggering standard antivirus alarms.

The Pervasive Threat of Residential Proxy Networks

The problem extends beyond a single product. Residential proxy networks are highly valued by threat actors because they enable traffic to originate from legitimate-looking sources—homes, mobile devices, and offices—effectively masking malicious activity. Attackers exploit these networks for various illicit purposes, including account takeovers, financial fraud, network scanning, and other operations, all while blending in with legitimate user traffic.

Silent Push’s observations over a 72-hour period revealed 117,224 unique IP addresses across Astroproxy’s residential, mobile, and datacenter pools. The residential pool alone added an average of 1,071 new addresses per hour, demonstrating the scale and rapid turnover that can render conventional IP reputation tools ineffective.

The report, shared with Cyber Security News (CSN), cautioned that corporate systems enrolled by employees seeking minor payments could be among the exposed devices. Consequences for organizations include the potential for malicious activities to be traced back to their IP addresses, leading to blocklisting, reputational damage, and even unauthorized access to local network services.

Bandwidth-Sharing Apps: A Gateway to Corporate Networks

Peer2Profit, operational since at least 2021, offers small payments based on the volume of traffic routed through an enrolled device. The application supports Android and macOS, with earlier Windows and Linux software development kits allowing its integration into other applications.

The onboarding process for Peer2Profit is designed for simplicity, enabling users to register via a Telegram bot, install a client, monitor traffic, and withdraw cryptocurrency earnings. This low barrier to entry means employees can easily install the app on corporate endpoints or personal devices connected to the office network.

Once active, the device establishes an outbound connection to a backconnect server. A proxy customer can then route their traffic through this device, making websites and services perceive the request as originating from the employee’s residential or corporate IP address. This creates a severe attribution problem, as abuse like credential stuffing, fraud, or automated scanning could be linked to the organization whose connection was used, regardless of their involvement.

The financial incentive is clear: Peer2Profit paid users $0.28 per GB for residential traffic, which Astroproxy then resold for $7.60 per GB. Similarly, mobile traffic fetched $0.35 per GB for users and was sold for $13.44 per GB, highlighting the significant profit margins driving these proxy operations. Since traditional endpoint security tools may not classify these consent-based bandwidth-sharing programs as malicious, organizations must implement robust security policies and monitoring.

DNS Bypass Raises Internal Network Access Risks

Perhaps the most alarming discovery was the potential for internal network access. While Astroproxy typically blocked direct requests to private IP ranges, Silent Push researchers found a bypass: if a domain name resolved to an internal IP address, the restriction could be circumvented.

Through a Peer2Profit-enrolled node, researchers successfully accessed a residential router management interface via Astroproxy and downloaded a PNG file as proof of concept. This test demonstrated that a proxy user could potentially interact with resources normally only accessible from within the affected network. In a corporate setting, this could mean unauthorized access to routers, network-attached storage, smart devices, test servers, or other critical internal services. The risk escalates when remote workers connect to company VPNs or when personal devices move between home and office networks.

The researchers responsibly disclosed this bypass before publishing their findings but noted that no meaningful remediation had occurred. This situation underscores the critical need for organizations to segment internal networks, restrict management interface access, and avoid sole reliance on IP-based access controls.

What You Should Do

  • Review Software Policies: Establish clear policies prohibiting the installation of bandwidth-sharing applications on corporate devices and personal devices connected to corporate networks.
  • Implement Application Allowlisting: Control which applications are permitted to run on endpoints, thereby preventing unauthorized software like Peer2Profit from being installed.
  • Monitor DNS Activity: Actively monitor DNS queries for suspicious resolutions or connections to known proxy-control infrastructure.
  • Perform Network Segmentation: Segment internal networks to limit the blast radius of any potential compromise and restrict access to critical internal services.
  • Conduct Endpoint Reviews: Regularly inventory browser extensions and consumer applications on endpoints and monitor for outbound connections to proxy backconnect servers.
  • Educate Employees: Inform employees about the risks associated with bandwidth-sharing apps and the importance of adhering to corporate security policies.
  • Block Known Indicators of Compromise (IoCs): Configure firewalls and intrusion detection/prevention systems to block traffic to the following known Peer2Profit infrastructure:
    • Domain: api[.]peer2profit[.]global
    • IP Addresses: 145.239.21.108:443, 135.181.73[.]138, 162.19.83[.]163, 94.130.135[.]167, 45.10.174.44, 45.10.174.47, 45.10.174.48, 45.10.174.49, 45.10.174.50, 45.10.174.51, 45.10.174.53, 45.10.174.55, 45.10.174.56, 45.10.174.57, 172.241.25.105, 172.241.25.106, 172.241.25.107, 137.74.6.101, 137.74.7.212, 139.99.64.99, 139.99.64.101, 139.99.64.102, 139.99.64.113, 145.239.16.66, 147.135.199.160, 147.135.199.185, 147.135.199.186, 51.79.133.114, 51.89.238.177, 51.89.238.184, 54.38.210.140, 54.38.210.145, 54.38.210.150, 185.35.223.163, 185.35.223.164, 185.35.223.165, 185.35.223.166
    • File Hashes (SHA-256):
      • 0b10a1e48df2884a7a8a1ebf5aa903207955433c8ea00d7602c78be6e6c177cc (p2p-sdk[.]dll)
      • eb8826bac873442045a6a05f1fa25b410ca18db6942053f6d146467c00d5338d (p2pclient)
      • 8871d12a7bb7529ff6e90ad5a18c86e92a402a2d02d3283d1385bdb52ba2b0f2 (Peer2Profit-0.47[.]dmg)
      • c85c7436fdb71cf52db6ef134b336d66c7dbd3738a7866f8b9992434d1208a4b (P2P_3.4.4_(53)-release[.]apk)

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Sakura Internet Breach Exposes 1.36 Million Customer Records

Next Post

Fake Google Gemini installer deploys Vidar Stealer, steals browser data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Spring Security Flaw Lets Attackers Gain Admin Access to LDAP Servers
August 21, 2026
CVE-2024-23963: Apple Find My Vulnerability Exposes Real-Time User Locations
August 21, 2026
Critical TrueConf Server Flaws Let Attackers Push Malware via Updates
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us