A bandwidth-sharing app installed by an employee can quietly turn a work device into a gateway for outside traffic.
The software may not behave like traditional malware, yet it can expose a company’s internet connection and potentially place internal systems within reach of paying proxy users.
The risk comes from Peer2Profit, an app that pays users for sharing unused internet bandwidth.
Researchers found that the service feeds devices into Astroproxy, where the same connections are resold as residential, mobile, or datacenter proxy access.
Analysts at Silent Push identified an active operational link between Peer2Profit and Astroproxy after enrolling a test device and observing its IP address appear in Astroproxy’s proxy pool.
The finding shows how a voluntary consumer-style app can create an enterprise security problem without tripping standard antivirus alerts.
The issue is wider than a single product. Residential proxy networks make traffic appear to come from ordinary homes, phones, and offices, which is why residential proxy networks hide attacks so effectively.
Attackers can use such traffic for account attacks, fraud, scanning, and other activity while blending in with legitimate users.
Silent Push found 117,224 unique IP addresses across Astroproxy’s residential, mobile, and datacenter pools during a 72-hour observation period.
The residential pool alone added an average of 1,071 new addresses each hour, making ordinary IP reputation tools slow to react.
Silent Push said in a report shared with Cyber Security News (CSN) that the exposed devices may include corporate systems enrolled by employees seeking small payments.
The report warns that the consequences can include abuse traced to a company’s IP address, blocklisting, reputational harm, and access to local network services.
Peer2Profit has operated since at least 2021 and offers small payments based on the volume of traffic that passes through an enrolled device.
The app supports Android and macOS, while earlier Windows and Linux software development kits enabled developers to embed its sharing function into other applications.
The onboarding process is designed to be simple. Users can register through a Telegram bot, install a client, monitor traffic, and withdraw cryptocurrency earnings.
That low barrier means a worker can install the app on a corporate endpoint or a personal device connected to an office network.
Once active, the device maintains an outbound connection to a backconnect server. A proxy customer can then send traffic through that device, causing websites and services to see the request as originating from the employee’s residential or corporate IP address.
This creates a serious attribution problem. Abuse such as credential stuffing, fraud, or automated scanning may be linked to the organization whose connection was used, even if the company did not initiate the activity.
Recent reporting on credential stuffing botnet exposure illustrates how proxy-supported automated attacks can operate at large scale.
The researchers found that Peer2Profit paid users $0.28 per GB for residential traffic, while Astroproxy charged customers $7.60 per GB.
Mobile traffic was paid at $0.35 per GB and sold at $13.44 per GB, showing why residential and mobile connections are valuable to proxy operators. Traditional endpoint tools may not classify a consent-based bandwidth-sharing program as malicious.
Security teams should therefore review software policies, inspect DNS activity, inventory browser extensions and consumer apps, and monitor for connections to known proxy-control infrastructure.
The most concerning finding involved internal network access. Astroproxy blocked direct requests to private IP ranges, but Silent Push found that this restriction could be bypassed when a domain name resolved to an internal IP address.
Using a Peer2Profit-enrolled node, researchers reached a residential router management interface through Astroproxy and downloaded a PNG file as proof of access.
The test showed that a proxy user could potentially interact with resources that are normally only accessible from inside the affected network.
In a corporate environment, that could include routers, network-attached storage, smart devices, test servers, or other internal services.
The danger becomes more significant when remote workers connect to company VPNs or when personal devices move between home and office networks.
The researchers responsibly disclosed the bypass before publication but reported that meaningful remediation had not occurred.
The situation reinforces why organizations should segment internal networks, restrict management interfaces, and avoid relying solely on IP-based access controls.
Defenders should also identify endpoints running bandwidth-sharing software and block unnecessary connections to proxy backconnect infrastructure.
Proactive monitoring matters because a clean consumer IP can become a proxy exit node with little warning, an issue also seen in major proxy network disruptions.
Organizations should treat these applications as a policy and network security concern, not merely as unwanted software.
Clear employee guidance, application allowlisting, DNS monitoring, network segmentation, and routine endpoint reviews can reduce the chance that a worker’s device becomes an entry point for external proxy customers.
Indicators of comrpomise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | api[.]peer2profit[.]global | Peer2Profit device-registration API |
| IP address | 145.239.21.108:443 | Backconnect server returned during SDK registration |
| IP address | 135.181.73[.]138 | Historical infrastructure IP sharing an SSL certificate linking Peer2Profit and Astroproxy |
| IP address | 162.19.83[.]163 | Historical infrastructure IP sharing an SSL certificate linking Peer2Profit and Astroproxy |
| IP address | 94.130.135[.]167 | Historical infrastructure IP sharing an SSL certificate linking Peer2Profit and Astroproxy |
| IP address | 45.10.174.44 | Peer2Profit backconnect server |
| IP address | 45.10.174.47 | Peer2Profit backconnect server |
| IP address | 45.10.174.48 | Peer2Profit backconnect server |
| IP address | 45.10.174.49 | Peer2Profit backconnect server |
| IP address | 45.10.174.50 | Peer2Profit backconnect server |
| IP address | 45.10.174.51 | Peer2Profit backconnect server |
| IP address | 45.10.174.53 | Peer2Profit backconnect server |
| IP address | 45.10.174.55 | Peer2Profit backconnect server |
| IP address | 45.10.174.56 | Peer2Profit backconnect server |
| IP address | 45.10.174.57 | Peer2Profit backconnect server |
| IP address | 172.241.25.105 | Peer2Profit backconnect server |
| IP address | 172.241.25.106 | Peer2Profit backconnect server |
| IP address | 172.241.25.107 | Peer2Profit backconnect server |
| IP address | 137.74.6.101 | Peer2Profit backconnect server |
| IP address | 137.74.7.212 | Peer2Profit backconnect server |
| IP address | 139.99.64.99 | Peer2Profit backconnect server |
| IP address | 139.99.64.101 | Peer2Profit backconnect server |
| IP address | 139.99.64.102 | Peer2Profit backconnect server |
| IP address | 139.99.64.113 | Peer2Profit backconnect server |
| IP address | 145.239.16.66 | Peer2Profit backconnect server |
| IP address | 147.135.199.160 | Peer2Profit backconnect server |
| IP address | 147.135.199.185 | Peer2Profit backconnect server |
| IP address | 147.135.199.186 | Peer2Profit backconnect server |
| IP address | 51.79.133.114 | Peer2Profit backconnect server |
| IP address | 51.89.238.177 | Peer2Profit backconnect server |
| IP address | 51.89.238.184 | Peer2Profit backconnect server |
| IP address | 54.38.210.140 | Peer2Profit backconnect server |
| IP address | 54.38.210.145 | Peer2Profit backconnect server |
| IP address | 54.38.210.150 | Peer2Profit backconnect server |
| IP address | 185.35.223.163 | Peer2Profit backconnect server |
| IP address | 185.35.223.164 | Peer2Profit backconnect server |
| IP address | 185.35.223.165 | Peer2Profit backconnect server |
| IP address | 185.35.223.166 | Peer2Profit backconnect server |
| File name | p2p-sdk[.]dll | Peer2Profit Windows SDK sample |
| SHA-256 | 0b10a1e48df2884a7a8a1ebf5aa903207955433c8ea00d7602c78be6e6c177cc | Hash for p2p-sdk[.]dll |
| File name | p2pclient | Peer2Profit ELF sample |
| SHA-256 | eb8826bac873442045a6a05f1fa25b410ca18db6942053f6d146467c00d5338d | Hash for p2pclient |
| File name | Peer2Profit-0.47[.]dmg | Peer2Profit macOS disk image sample |
| SHA-256 | 8871d12a7bb7529ff6e90ad5a18c86e92a402a2d02d3283d1385bdb52ba2b0f2 | Hash for Peer2Profit-0.47[.]dmg |
| File name | P2P_3.4.4_(53)-release[.]apk | Peer2Profit Android application package sample |
| SHA-256 | c85c7436fdb71cf52db6ef134b336d66c7dbd3738a7866f8b9992434d1208a4b | Hash for P2P_3.4.4_(53)-release[.]apk |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…