Cyber Security News

Bandwidth-Sharing App Can Turn Employee Devices Into Gateways to Internal Networks

A bandwidth-sharing app installed by an employee can quietly turn a work device into a gateway for outside traffic.

The software may not behave like traditional malware, yet it can expose a company’s internet connection and potentially place internal systems within reach of paying proxy users.

The risk comes from Peer2Profit, an app that pays users for sharing unused internet bandwidth.

Researchers found that the service feeds devices into Astroproxy, where the same connections are resold as residential, mobile, or datacenter proxy access.

Analysts at Silent Push identified an active operational link between Peer2Profit and Astroproxy after enrolling a test device and observing its IP address appear in Astroproxy’s proxy pool.

The finding shows how a voluntary consumer-style app can create an enterprise security problem without tripping standard antivirus alerts.

The issue is wider than a single product. Residential proxy networks make traffic appear to come from ordinary homes, phones, and offices, which is why residential proxy networks hide attacks so effectively.

Attackers can use such traffic for account attacks, fraud, scanning, and other activity while blending in with legitimate users.

Old PEER2PROFIT website (Source – SilentPush)

Silent Push found 117,224 unique IP addresses across Astroproxy’s residential, mobile, and datacenter pools during a 72-hour observation period.

The residential pool alone added an average of 1,071 new addresses each hour, making ordinary IP reputation tools slow to react.

Silent Push said in a report shared with Cyber Security News (CSN) that the exposed devices may include corporate systems enrolled by employees seeking small payments.

The report warns that the consequences can include abuse traced to a company’s IP address, blocklisting, reputational harm, and access to local network services.

Bandwidth-Sharing App Can Turn Employee Devices Into Gateways

Peer2Profit has operated since at least 2021 and offers small payments based on the volume of traffic that passes through an enrolled device.

The app supports Android and macOS, while earlier Windows and Linux software development kits enabled developers to embed its sharing function into other applications.

PEER2PROFIT Telegram bot (Source – SilentPush)

The onboarding process is designed to be simple. Users can register through a Telegram bot, install a client, monitor traffic, and withdraw cryptocurrency earnings.

That low barrier means a worker can install the app on a corporate endpoint or a personal device connected to an office network.

Once active, the device maintains an outbound connection to a backconnect server. A proxy customer can then send traffic through that device, causing websites and services to see the request as originating from the employee’s residential or corporate IP address.

This creates a serious attribution problem. Abuse such as credential stuffing, fraud, or automated scanning may be linked to the organization whose connection was used, even if the company did not initiate the activity.

Recent reporting on credential stuffing botnet exposure illustrates how proxy-supported automated attacks can operate at large scale.

The researchers found that Peer2Profit paid users $0.28 per GB for residential traffic, while Astroproxy charged customers $7.60 per GB.

Mobile traffic was paid at $0.35 per GB and sold at $13.44 per GB, showing why residential and mobile connections are valuable to proxy operators. Traditional endpoint tools may not classify a consent-based bandwidth-sharing program as malicious.

Device management via Telegram (Source – SilentPush)

Security teams should therefore review software policies, inspect DNS activity, inventory browser extensions and consumer apps, and monitor for connections to known proxy-control infrastructure.

DNS Bypass Raises Internal Risk

The most concerning finding involved internal network access. Astroproxy blocked direct requests to private IP ranges, but Silent Push found that this restriction could be bypassed when a domain name resolved to an internal IP address.

Using a Peer2Profit-enrolled node, researchers reached a residential router management interface through Astroproxy and downloaded a PNG file as proof of access.

The test showed that a proxy user could potentially interact with resources that are normally only accessible from inside the affected network.

In a corporate environment, that could include routers, network-attached storage, smart devices, test servers, or other internal services.

The danger becomes more significant when remote workers connect to company VPNs or when personal devices move between home and office networks.

The researchers responsibly disclosed the bypass before publication but reported that meaningful remediation had not occurred.

The situation reinforces why organizations should segment internal networks, restrict management interfaces, and avoid relying solely on IP-based access controls.

Communications protocol flow (Source – SilentPush)

Defenders should also identify endpoints running bandwidth-sharing software and block unnecessary connections to proxy backconnect infrastructure.

Proactive monitoring matters because a clean consumer IP can become a proxy exit node with little warning, an issue also seen in major proxy network disruptions.

Organizations should treat these applications as a policy and network security concern, not merely as unwanted software.

Clear employee guidance, application allowlisting, DNS monitoring, network segmentation, and routine endpoint reviews can reduce the chance that a worker’s device becomes an entry point for external proxy customers.

Indicators of comrpomise (IoCs):-

TypeIndicatorDescription
Domainapi[.]peer2profit[.]globalPeer2Profit device-registration API
IP address145.239.21.108:443Backconnect server returned during SDK registration
IP address135.181.73[.]138Historical infrastructure IP sharing an SSL certificate linking Peer2Profit and Astroproxy
IP address162.19.83[.]163Historical infrastructure IP sharing an SSL certificate linking Peer2Profit and Astroproxy
IP address94.130.135[.]167Historical infrastructure IP sharing an SSL certificate linking Peer2Profit and Astroproxy
IP address45.10.174.44Peer2Profit backconnect server
IP address45.10.174.47Peer2Profit backconnect server
IP address45.10.174.48Peer2Profit backconnect server
IP address45.10.174.49Peer2Profit backconnect server
IP address45.10.174.50Peer2Profit backconnect server
IP address45.10.174.51Peer2Profit backconnect server
IP address45.10.174.53Peer2Profit backconnect server
IP address45.10.174.55Peer2Profit backconnect server
IP address45.10.174.56Peer2Profit backconnect server
IP address45.10.174.57Peer2Profit backconnect server
IP address172.241.25.105Peer2Profit backconnect server
IP address172.241.25.106Peer2Profit backconnect server
IP address172.241.25.107Peer2Profit backconnect server
IP address137.74.6.101Peer2Profit backconnect server
IP address137.74.7.212Peer2Profit backconnect server
IP address139.99.64.99Peer2Profit backconnect server
IP address139.99.64.101Peer2Profit backconnect server
IP address139.99.64.102Peer2Profit backconnect server
IP address139.99.64.113Peer2Profit backconnect server
IP address145.239.16.66Peer2Profit backconnect server
IP address147.135.199.160Peer2Profit backconnect server
IP address147.135.199.185Peer2Profit backconnect server
IP address147.135.199.186Peer2Profit backconnect server
IP address51.79.133.114Peer2Profit backconnect server
IP address51.89.238.177Peer2Profit backconnect server
IP address51.89.238.184Peer2Profit backconnect server
IP address54.38.210.140Peer2Profit backconnect server
IP address54.38.210.145Peer2Profit backconnect server
IP address54.38.210.150Peer2Profit backconnect server
IP address185.35.223.163Peer2Profit backconnect server
IP address185.35.223.164Peer2Profit backconnect server
IP address185.35.223.165Peer2Profit backconnect server
IP address185.35.223.166Peer2Profit backconnect server
File namep2p-sdk[.]dllPeer2Profit Windows SDK sample
SHA-2560b10a1e48df2884a7a8a1ebf5aa903207955433c8ea00d7602c78be6e6c177ccHash for p2p-sdk[.]dll
File namep2pclientPeer2Profit ELF sample
SHA-256eb8826bac873442045a6a05f1fa25b410ca18db6942053f6d146467c00d5338dHash for p2pclient
File namePeer2Profit-0.47[.]dmgPeer2Profit macOS disk image sample
SHA-2568871d12a7bb7529ff6e90ad5a18c86e92a402a2d02d3283d1385bdb52ba2b0f2Hash for Peer2Profit-0.47[.]dmg
File nameP2P_3.4.4_(53)-release[.]apkPeer2Profit Android application package sample
SHA-256c85c7436fdb71cf52db6ef134b336d66c7dbd3738a7866f8b9992434d1208a4bHash for P2P_3.4.4_(53)-release[.]apk

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

3 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

9 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

14 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

25 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago