A recent investigation has revealed that certain SuperBox streaming devices and the CyberFlix TV application may be enrolling users' home internet connections into a residential proxy network, potentially allowing third parties to route traffic through their households. This activity could expose users to privacy risks, consume bandwidth, and associate their public IP addresses with illicit online activities.
The issue was initially identified in the CyberFlix TV app, which is available through SuperBox's custom app store. Researchers found that this application contains "Popanet" proxy functionality that registers the device with a server controlled by the proxy operator. Subsequent research indicates that these proxy networks can also serve as platforms for delivering additional malware to compromised devices.
Residential proxy networks operate by renting out ordinary home IP addresses to customers. This makes their internet traffic appear to originate from a legitimate consumer connection rather than a data center, which can help cybercriminals bypass IP-based fraud controls and reputation systems. Law enforcement agencies have previously warned that such proxies are used by "foreign entities" to conceal their identities and make their activities appear to come from someone else's home network. The FBI defines a residential proxy as an intermediary server that uses legitimate IP addresses assigned by an Internet Service Provider (ISP) to consumer IoT devices, such as streaming devices, to route traffic. Once compromised, a device's IP address can be used by threat actors to mask their online activity, potentially making the consumer appear responsible.
Beyond the impact on connectivity and the potential for a household's IP address to be linked to activities like credential stuffing, account abuse, or attempts to bypass enterprise security controls, the reported SuperBox configuration raises additional security concerns. Researchers discovered exposed Android Debug Bridge (ADB) access, root-level privileges without authentication, and the removal of protections that typically restrict untrusted app installation or prompt users to approve risky actions.
While many users might assume that placing a streaming device behind a home router offers sufficient protection, proxy-enabled devices can establish an encrypted outbound connection to a remote server. This creates a channel that the home router treats as legitimate traffic initiated from within the network, effectively bypassing typical network address translation and firewall protections against unsolicited inbound connections.
To mitigate these risks, users are advised against connecting devices or installing applications that promise unauthorized access to free movies and TV. If a SuperBox device is owned or CyberFlix TV has been installed, it is recommended to disconnect the device from the network. A factory reset may not be sufficient to secure the device, suggesting that replacement might be necessary. The core issue stems from a business model that monetizes user connections, which can compromise IP addresses, bandwidth, privacy, and local network security. Even network segmentation, such as placing the device on a separate guest network, may not fully address the risk posed by a product designed to establish a persistent proxy channel with weak device-level protection.






