VYPR
researchPublished Aug 21, 2026· 1 source

Employee-Installed Bandwidth-Sharing App Creates Network Gateway Risk

A seemingly innocuous bandwidth-sharing application, Peer2Profit, can transform employee devices into gateways for external network traffic, posing significant risks to corporate networks.

A consumer-grade application designed for sharing unused internet bandwidth, known as Peer2Profit, has been found to inadvertently create substantial security risks for enterprise networks. When employees install this application on work devices, it can transform those devices into gateways, allowing external users to route traffic through the company's IP address. This practice bypasses traditional security measures and can expose internal systems to malicious actors.

Researchers at Silent Push discovered an active operational link between Peer2Profit and the Astroproxy network. By enrolling a test device with Peer2Profit, they observed its IP address appearing in Astroproxy's extensive pool of residential, mobile, and datacenter proxies. This means that individuals paying for proxy services through Astroproxy can leverage compromised employee devices to mask their online activities, making attacks appear to originate from legitimate corporate or residential IP addresses.

The implications for businesses are severe. Malicious actors can use these proxies for a variety of illicit activities, including account takeovers, fraud, credential stuffing, and network scanning. When these activities are traced back to a company's IP address, it can lead to reputational damage, IP address blocklisting, and potential regulatory scrutiny, even though the company itself did not initiate the malicious actions.

Peer2Profit, operational since at least 2021, incentivizes users with small cryptocurrency payments for sharing bandwidth. The application is available for Android and macOS, and its SDKs have been used to embed its functionality into other applications for Windows and Linux. The ease of installation, often facilitated through a Telegram bot, lowers the barrier for employees to install it on corporate endpoints or personal devices connected to the office network.

Once installed, the Peer2Profit app establishes an outbound connection to a backconnect server. This connection allows proxy customers to send traffic through the enrolled device. While Astroproxy attempts to block direct requests to private IP ranges, researchers found that this restriction could be bypassed if a domain name resolved to an internal IP address. This bypass could potentially grant proxy users access to internal network resources like routers, NAS devices, or test servers.

Traditional endpoint security solutions may not flag consent-based bandwidth-sharing applications as malicious, making detection difficult. Security teams need to adopt a multi-layered approach, including reviewing software policies, monitoring DNS activity for unusual resolutions, inventorying all installed consumer applications, and actively searching for connections to known proxy infrastructure.

To mitigate these risks, organizations should implement clear employee guidance on acceptable software use, enforce application allowlisting, enhance DNS monitoring, segment internal networks to limit lateral movement, and conduct regular endpoint reviews. The dynamic nature of proxy networks, where clean IPs can quickly become exit nodes, underscores the need for proactive and continuous security vigilance.

Synthesized by Vypr AI