Friday, September 11, 2026

Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks

Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse.

New research shows that PEER2PROFIT, a bandwidth-sharing application, can turn employee or personal devices into commercial proxy exit nodes that are then monetized through ASTROPROXY potentially exposing corporate IP space and internally reachable resources.

The relationship was confirmed through controlled testing. Researchers enrolled a clean residential device in the PEER2PROFIT network, then observed its public IP address appear in ASTROPROXY’s residential proxy pool roughly 10 minutes later.

Unlike datacenter proxies, which are cheap and comparatively easy to identify, residential proxy traffic originates from legitimate ISP-assigned addresses.

Requests therefore appear to come from ordinary homes, mobile subscribers, businesses, universities, or corporate networks.

This makes conventional IP reputation systems inadequate: an IP can be benign in one hour and become an active proxy exit node in the next, long before it accumulates an abuse history.

PEER2PROFIT is not necessarily deployed as malware. It is marketed as a passive-income service that pays users for relaying traffic through their internet connection.

Its onboarding flow has reportedly moved to Telegram, where users can register devices, monitor consumption, and withdraw cryptocurrency earnings.

That accessibility creates a significant enterprise exposure. An employee can install a bandwidth-sharing client on a work endpoint, a personally owned device connected to office Wi-Fi, or a home system connected through a corporate VPN.

Once enrolled, the organization’s public IP may be offered to proxy customers as an exit point.

Any traffic relayed through that connection can appear to originate from the enterprise.

This could associate a company’s IP range with credential-stuffing attempts, ad fraud, malicious scanning, financial fraud, spam delivery, or rate-limit evasion.

The resulting reputational harm may trigger blocklisting by SaaS providers, payment platforms, anti-fraud services, and partner networks.

Analysis of the PEER2PROFIT Windows SDK identified a classic backconnect-proxy architecture. The client first registers through api[.]peer2profit[.]global, submitting device and client information to retrieve a proxy coordination server.

The enrolled endpoint then establishes a persistent outbound session to a backconnect server.

When a proxy customer requests access to a target, the server forwards an HTTP CONNECT request to the device, which opens a connection to the requested destination and relays data between the target and the proxy infrastructure.

The protocol uses a lightweight binary wrapper and nibble inversion to obfuscate transferred data.

Each proxied request is handled in a separate thread and associated with a dedicated backconnect socket through a StartLet-Context header.

Researchers identified backconnect infrastructure across a limited set of hosting providers and autonomous systems, including Datacheap in Russia, Leaseweb USA, PSKZ in Kazakhstan, and OVH in France.


Old PEER2PROFIT website (Source : Silentpush).
Old PEER2PROFIT website (Source : Silentpush).

This infrastructure is substantially more stable than the rotating pool of residential exit nodes, making it a more useful hunting and detection signal.

Silent Push Researchers said that, the finding demonstrates an operational pipeline: PEER2PROFIT recruits and compensates users for bandwidth, while ASTROPROXY sells access to that bandwidth as residential proxy capacity.

Peer2Profit Proxy Threat

Historical infrastructure analysis initially linked PEER2PROFIT and ASTROPROXY through shared SSL certificate material. Controlled enrollment subsequently confirmed that ASTROPROXY was actively selling residential connectivity supplied by PEER2PROFIT.

ASTROPROXY website  (Source : Silentpush).
 ASTROPROXY website (Source : Silentpush).

The margin behind the model is considerable. PEER2PROFIT reportedly pays residential users about $0.28 per GB while ASTROPROXY sells residential proxy traffic for approximately $7.60 per GB.

Mobile traffic is paid at roughly $0.35 per GB and sold at $13.44 per GB. The gap explains the strong incentive to recruit more endpoint bandwidth.

The residential pool is dominated by Russia and Vietnam, which together account for over 40% of all observed IPs. Portugal, Ukraine, and Brazil follow.

A 72-hour enumeration of ASTROPROXY pools identified 117,224 unique IP addresses: 60,247 residential, 38,762 datacenter, and 18,215 mobile nodes.

Top 10 countries per proxy pool (Source : Silentpush).
Top 10 countries per proxy pool (Source : Silentpush).

Residential nodes alone added an average of 1,071 new IPs per hour, reinforcing why static blocklists and reactive reputation systems rapidly become outdated.

The most serious finding concerns internal network access. Researchers reported that ASTROPROXY blocked direct requests to internal IP addresses, but the restriction could be bypassed by using a domain name resolving to a private address.

Using a PEER2PROFIT-backed node, researchers accessed a MEO residential router-management interface and retrieved a PNG file as proof of connectivity.

The test indicates that a proxy subscriber may be able to reach router interfaces, NAS appliances, smart devices, and other internal services accessible from the enrolled node.

For enterprises, the implications are sharper. A remote employee operating such software while connected to a corporate VPN, or a user running it on an office network, could unintentionally provide proxy customers with a path to internal assets.

Proxy services offering filters by country, city, ASN, and connection type may further enable targeted selection of potential corporate or ISP-adjacent nodes.

Organizations should inventory and restrict bandwidth-sharing software, monitor persistent outbound connections to known proxy coordination infrastructure, review split-tunnel VPN policies, and use active proxy-node intelligence rather than relying only on historical IP reputation.

IOCs

NameFile TypeSHA256
p2p-sdk[.]dllDLL0b10a1e48df2884a7a8a1ebf5aa903207955433c8ea00d7602c78be6e6c177cc
p2pclientELFeb8826bac873442045a6a05f1fa25b410ca18db6942053f6d146467c00d5338d
Peer2Profit-0.47[.]dmgDMG8871d12a7bb7529ff6e90ad5a18c86e92a402a2d02d3283d1385bdb52ba2b0f2

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News