Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse.
New research shows that PEER2PROFIT, a bandwidth-sharing application, can turn employee or personal devices into commercial proxy exit nodes that are then monetized through ASTROPROXY potentially exposing corporate IP space and internally reachable resources.
The relationship was confirmed through controlled testing. Researchers enrolled a clean residential device in the PEER2PROFIT network, then observed its public IP address appear in ASTROPROXY’s residential proxy pool roughly 10 minutes later.
Unlike datacenter proxies, which are cheap and comparatively easy to identify, residential proxy traffic originates from legitimate ISP-assigned addresses.
Requests therefore appear to come from ordinary homes, mobile subscribers, businesses, universities, or corporate networks.
This makes conventional IP reputation systems inadequate: an IP can be benign in one hour and become an active proxy exit node in the next, long before it accumulates an abuse history.
PEER2PROFIT is not necessarily deployed as malware. It is marketed as a passive-income service that pays users for relaying traffic through their internet connection.
Its onboarding flow has reportedly moved to Telegram, where users can register devices, monitor consumption, and withdraw cryptocurrency earnings.
That accessibility creates a significant enterprise exposure. An employee can install a bandwidth-sharing client on a work endpoint, a personally owned device connected to office Wi-Fi, or a home system connected through a corporate VPN.
Once enrolled, the organization’s public IP may be offered to proxy customers as an exit point.
Any traffic relayed through that connection can appear to originate from the enterprise.
This could associate a company’s IP range with credential-stuffing attempts, ad fraud, malicious scanning, financial fraud, spam delivery, or rate-limit evasion.
The resulting reputational harm may trigger blocklisting by SaaS providers, payment platforms, anti-fraud services, and partner networks.
Analysis of the PEER2PROFIT Windows SDK identified a classic backconnect-proxy architecture. The client first registers through api[.]peer2profit[.]global, submitting device and client information to retrieve a proxy coordination server.
The enrolled endpoint then establishes a persistent outbound session to a backconnect server.
When a proxy customer requests access to a target, the server forwards an HTTP CONNECT request to the device, which opens a connection to the requested destination and relays data between the target and the proxy infrastructure.
The protocol uses a lightweight binary wrapper and nibble inversion to obfuscate transferred data.
Each proxied request is handled in a separate thread and associated with a dedicated backconnect socket through a StartLet-Context header.
Researchers identified backconnect infrastructure across a limited set of hosting providers and autonomous systems, including Datacheap in Russia, Leaseweb USA, PSKZ in Kazakhstan, and OVH in France.
This infrastructure is substantially more stable than the rotating pool of residential exit nodes, making it a more useful hunting and detection signal.
Silent Push Researchers said that, the finding demonstrates an operational pipeline: PEER2PROFIT recruits and compensates users for bandwidth, while ASTROPROXY sells access to that bandwidth as residential proxy capacity.
Historical infrastructure analysis initially linked PEER2PROFIT and ASTROPROXY through shared SSL certificate material. Controlled enrollment subsequently confirmed that ASTROPROXY was actively selling residential connectivity supplied by PEER2PROFIT.
The margin behind the model is considerable. PEER2PROFIT reportedly pays residential users about $0.28 per GB while ASTROPROXY sells residential proxy traffic for approximately $7.60 per GB.
Mobile traffic is paid at roughly $0.35 per GB and sold at $13.44 per GB. The gap explains the strong incentive to recruit more endpoint bandwidth.
The residential pool is dominated by Russia and Vietnam, which together account for over 40% of all observed IPs. Portugal, Ukraine, and Brazil follow.
A 72-hour enumeration of ASTROPROXY pools identified 117,224 unique IP addresses: 60,247 residential, 38,762 datacenter, and 18,215 mobile nodes.
Residential nodes alone added an average of 1,071 new IPs per hour, reinforcing why static blocklists and reactive reputation systems rapidly become outdated.
The most serious finding concerns internal network access. Researchers reported that ASTROPROXY blocked direct requests to internal IP addresses, but the restriction could be bypassed by using a domain name resolving to a private address.
Using a PEER2PROFIT-backed node, researchers accessed a MEO residential router-management interface and retrieved a PNG file as proof of connectivity.
The test indicates that a proxy subscriber may be able to reach router interfaces, NAS appliances, smart devices, and other internal services accessible from the enrolled node.
For enterprises, the implications are sharper. A remote employee operating such software while connected to a corporate VPN, or a user running it on an office network, could unintentionally provide proxy customers with a path to internal assets.
Proxy services offering filters by country, city, ASN, and connection type may further enable targeted selection of potential corporate or ISP-adjacent nodes.
Organizations should inventory and restrict bandwidth-sharing software, monitor persistent outbound connections to known proxy coordination infrastructure, review split-tunnel VPN policies, and use active proxy-node intelligence rather than relying only on historical IP reputation.
| Name | File Type | SHA256 |
| p2p-sdk[.]dll | DLL | 0b10a1e48df2884a7a8a1ebf5aa903207955433c8ea00d7602c78be6e6c177cc |
| p2pclient | ELF | eb8826bac873442045a6a05f1fa25b410ca18db6942053f6d146467c00d5338d |
| Peer2Profit-0.47[.]dmg | DMG | 8871d12a7bb7529ff6e90ad5a18c86e92a402a2d02d3283d1385bdb52ba2b0f2 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…