How to Avoid Installing Malware and Resproxy Apps on Your Smart TV
Samsung and LG ban hundreds of millions of downloads after discovering apps secretly routing home internet traffic through smart TVs.

Stock photo for illustration only, not from the actual event
- Samsung and LG banned deceptive apps utilizing resproxy networks
- Security firm Mnemonic discovered background code linked to Bright Data
- Popular games like Pac-Man and SpongeBob ports included the hidden code
- Users must explicitly consent before the TV turns into a network node
Malware and digital threats are everywhere nowadays. While you might expect to encounter them when downloading strange software from shady corners of the internet, official marketplaces like the Google Play Store and Apple App Store are far from immune despite strict review processes. Now, this security concern has officially expanded to smart TV app marketplaces as well.
According to reports from TechCrunch, Samsung recently banned applications that share users' internet connections with strangers. Before this ban went into effect, hundreds of millions of users may have downloaded these apps onto their smart TVs, putting a massive fraction of Samsung's customer base at risk. These programs did not necessarily look suspicious either; at least one Pac-Man game was actively promoted by Samsung and featured prominently in the Editor's Choice section seen by customers on their smart TVs.

Stock photo for illustration only, not from the actual event
The core issue was uncovered by security firm Mnemonic, tracking back to a data collection company named Bright Data. This company's software conceals processes designed to let strangers route web traffic directly through your home internet connection. Once set up, these malicious applications do not even need to remain open for outsiders to tap into your home network for any purpose they choose. As TechCrunch highlights, these resproxy networks are increasingly utilized by cybercriminals because they make tracking illegal activity nearly impossible, allowing someone in England to route traffic through an Arizona home internet connection and obscure their actual physical location.
Residential proxy networks have become a favored tool for malicious actors because they route traffic through legitimate residential IP addresses. This makes automated bot traffic look like genuine human users from standard Internet Service Providers, effectively bypassing standard web filters and making the true origin point extremely difficult for investigators to trace.
It may seem shocking that Samsung allowed such software onto its official storefront, but many of these programs utilized clever tricks to bypass detection. A large number were extremely simple utilities consisting of only a handful of lines of code that pulled remote content from an external server, creating an illusion of full functionality while appearing completely safe to reviewers. This issue is not exclusive to Samsung, as LG also banned resproxy applications shortly after revelations showed that over 40% of the apps on its marketplace were adding users' smart TVs to proxy networks.
Complicating matters further, entirely legitimate applications also bundled Bright Data's code. Play.Works, which licenses games like Pac-Man, Space Invaders, Tetris, Doodle Jump, and SpongeBob, included the code within their ports. Consumers would naturally assume an official SpongeBob app downloaded to a television is safe, while remaining entirely unaware that it contained sleeper resproxy code.
The positive news is that both Samsung and LG have successfully banned these applications from their official marketplaces, meaning users should no longer worry about downloading apps that let outsiders tap into their home bandwidth. However, other smart TV manufacturers may not have caught up yet, leaving a persistent risk that newly downloaded TV applications could still harbor malicious intent.
Researchers also discovered that simply installing these apps will not instantly transform a television into a resproxy device. Even if the code loads onto the hardware, users must explicitly agree to a consent screen before activation occurs. Therefore, owners should remain vigilant regarding pop-up prompts on smart TV apps, denying consent to anything unfamiliar or unnecessary for basic app functionality, and promptly deleting suspicious or unused programs since the background code disappears entirely upon uninstallation.
From there, general security best practices go a long way. Before installing any app on a smart TV or other connected devices, inspect listings carefully with healthy skepticism. Check app store descriptions for spelling and grammatical errors, examine whether promotional images match the app functionality, scan user reviews for complaints or obvious rating inflation, and investigate the developer's background to ensure legitimacy.
Nevertheless, smart TV app marketplaces maintain a notoriously poor security reputation overall. As a general rule of thumb, it is likely best to avoid smart TV applications entirely whenever possible. While mainstream media streaming services remain generally safe, too many loopholes persist to guarantee the security of random utility apps and games.
Source: Lifehacker
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment