{"id":26089,"date":"2026-09-14T11:59:32","date_gmt":"2026-09-14T07:59:32","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/?p=26089"},"modified":"2026-09-15T12:05:16","modified_gmt":"2026-09-15T08:05:16","slug":"smart-tv-box-residential-proxy-malware-threat","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/smart-tv-box-residential-proxy-malware-threat\/26089\/","title":{"rendered":"Trojan TV, or the new risks of malicious proxies"},"content":{"rendered":"<p>In 2026, the owner of an ordinary home router, smart TV, or TV box is a prime target for cybercriminals. These devices are readily recruited into botnets and <a href=\"https:\/\/www.kaspersky.com\/blog\/save-your-home-router-from-apt-residential-proxy\/53840\/\" target=\"_blank\" rel=\"noopener nofollow\">residential proxy networks<\/a>, which we\u2019ve covered before.<\/p>\n<p>Criminals \u201csublease\u201d the infected device by letting outsiders pay to visit any website from the victim\u2019s IP address, so it looks like the device\u2019s owner is doing it. The service is in demand across all kinds of shady schemes: from ad fraud and spam campaigns to password bruteforcing and account hacking. In our previous post, we described how home routers get recruited into these proxy networks; today we\u2019ll look at an even more vulnerable and equally ubiquitous category of devices: smart TVs and TV boxes.<\/p>\n<p>These appeal to criminals for two reasons. First off, unlike computers and phones, TVs are almost always plugged into power and connected to fast internet. A dark screen doesn\u2019t mean the device is switched off. On top of that, the limited user interface and monitoring tools mean suspicious background processes can easily slip unnoticed past users.<\/p>\n<p>The threat is evolving and growing more aggressive. A recent <a href=\"https:\/\/www.plume.com\/resources\/superproxy-how-residential-proxy-networks-have-become-malware-delivery-platforms\" target=\"_blank\" rel=\"noopener nofollow\">study<\/a> found that once proxyware turns up on a set-top box, the risks to its owner go well beyond having their traffic siphoned off.<\/p>\n<h2>Anatomy of the infection<\/h2>\n<p>The researchers focused on a popular TV box by SuperBox, which we already covered earlier in the post <a href=\"https:\/\/www.kaspersky.com\/blog\/android-tv-botnet\/55799\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Is your TV box renting out your network?<\/strong><\/a><\/p>\n<p>SuperBox\u2019s marketing leans heavily on the promise of providing thousands of TV channels, with no subscription or monthly fees. But out of the box, the device can\u2019t actually do anything of the sort. To get access to pirated content, you need to install the brand\u2019s proprietary app store.<\/p>\n<p>Once you launch it and install additional apps, the promised TV channels do appear. Meanwhile behind the scenes, with no warnings or permission prompts, the device floods external sites with unauthorized requests. Network traffic spikes sharply.<\/p>\n<p>The researchers uncovered several alarming facts. First, the victim gets enrolled into as many as five botnets at once. The SuperBox runs clients for several proxyware networks simultaneously, which even try to compete with one another by blocking rival software from being installed.<\/p>\n<p>But the real shock was the attacks on the internal network. The TV box\u2019s proxyware places no limits on what its paying clients can actually do on the network. They can reach not only external sites but also devices inside your home network.<\/p>\n<p>Normally, your home router and ISP settings protect you from outside attacks. But proxyware bypasses these barriers, because it operates from inside the network. During an experiment, the researchers confirmed that an attacker on the internet can easily leverage the infected set-top box to open the admin panel of a home router, such as a Linksys, which is supposed to be accessible only to its owner when connected to the home Wi-Fi network. This means hackers can try to steal data from other devices at the same household or even encrypt a home network storage (NAS).<\/p>\n<p>At the same time, flaws in SuperBox\u2019s factory firmware let hackers remotely install and run any application with superuser privileges. The threat is anything but hypothetical. Over three weeks of monitoring, the test set-top box was hit by more than 1300 attacks through the home proxy network. Attackers installed three different types of malware, including a module for launching DDoS attacks.<\/p>\n<p>The malware uses several methods to gain a foothold in the system, and it survives reboots and power failures alike.<\/p>\n<h2>How to tell if your set-top box is working for hackers<\/h2>\n<p>If you have a cheap TV set-top box or Android TV from a little-known brand, it\u2019s worth checking it for anomalies.<\/p>\n<p>The most reliable method is to review the network traffic. Use the statistics in your router\u2019s control panel\u00a0\u2014 note that some budget models may lack this feature. This feature is called Traffic Analyzer on Asus routers, Traffic Usage on TP-Link, and Traffic Monitor on Keenetic. Find your TV or set-top box in the device list and check the ratio of downloaded to uploaded data. They should consume a lot of traffic to download video while sending very little. If your box is quietly pushing gigabytes of data out or staying chatty on the network even while idle, that\u2019s a telltale sign it\u2019s infected.<\/p>\n<p>If traffic statistics aren\u2019t available, look for indirect signs:<\/p>\n<ul>\n<li>The network and memory activity LEDs won\u2019t stop blinking even though no one is using the device.<\/li>\n<li>The set-top box\u2019s casing is constantly warm or hot.<\/li>\n<li>The interface lags behind the remote, and the box freezes at random moments that have nothing to do with heavy video playback.<\/li>\n<li>Your other devices (computers or phones) are seeing a real drop in internet speed.<\/li>\n<li>When trying to visit familiar sites over your home Wi-Fi, you\u2019re constantly hit with a CAPTCHA, a sign your network may be compromised and flagged as a spam source.<\/li>\n<li>Your ISP\u2019s tech support calls you asking about suspicious network loads.<\/li>\n<\/ul>\n<h2>What to do with an infected device<\/h2>\n<p>The best solution is to disconnect the device from the internet and dispose of it. If you have to keep using it, follow these steps to minimize the risks:<\/p>\n<ol>\n<li><strong>Do a factory (hard) reset<\/strong>. Restore the set-top box to its original state.<\/li>\n<li><strong>Take it offline before setting up.<\/strong> The first time you turn it on after a reset, skip the Wi-Fi setup step and don\u2019t plug in the Ethernet cable.<\/li>\n<li><strong>Block app installation.<\/strong> Go to Android settings and disable installation of apps from unknown sources. Be sure to turn off any debugging features if enabled: USB debugging, Wireless debugging, and ADB. Menu item names may differ depending on your Android version and device manufacturer.<\/li>\n<li><strong>Isolate it on the network.<\/strong> Set up a guest Wi-Fi network on your router and connect the TV box to it. Enable Client Isolation in your router\u2019s settings, if it has one. This will stop the box from seeing other devices on your home network, which protects your computers and network storage.<\/li>\n<li><strong>Check for updates.<\/strong> Once the box is connected to the guest network, check for official firmware updates: manufacturers sometimes patch known vulnerabilities, though with lesser-known brands, you shouldn\u2019t count on it.<\/li>\n<\/ol>\n<h2>Your most reliable safeguards<\/h2>\n<p>Buying cheap devices with pirate streaming features and installing software from shady sources is a surefire way to compromise your home network. Your IP address will become a source of malicious activity, which at best gets you blocked by your ISP and at worst puts you on law enforcement\u2019s radar. What\u2019s more, hackers can use the box as a launchpad to attack your home computers and NAS, which can lead to personal data theft or a ransomware attack.<\/p>\n<p>The best protection is to buy devices from trusted brands and pay for legal content. And to rule out someone hijacking control of your network, make sure your router\u2019s admin panel and other home devices are protected with unique, strong passwords. To avoid having to remember them all, use reliable password managers such as <a href=\"https:\/\/me-en.kaspersky.com\/password-manager?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>. Additionally, the Smart Home Monitor feature included in <a href=\"https:\/\/me-en.kaspersky.com\/premium?icid=me-en_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">Kaspersky Premium<\/a> lets you keep all your devices fully under control.<\/p>\n<blockquote><p>There may be more things you don\u2019t know about your smart home devices:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/android-tv-botnet\/55799\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Is your TV box renting out your network?<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/smart-speaker-tv-smartphone-eavesdropping\/50236\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Are your TV, smartphone, and smart speakers eavesdropping on you?<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/five-rules-against-ip-camera-surveillance\/56293\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Five rules to stop IP cameras from spying on you<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-avoid-threats-from-budget-android-devices\/49565\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>The hidden risks of cheap Android devices<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/save-your-home-router-from-apt-residential-proxy\/53840\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Is your router secretly working for foreign intelligence?<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\">\n","protected":false},"excerpt":{"rendered":"<p>How budget smart TVs and set-top boxes infect home networks and join malicious botnets.<\/p>\n","protected":false},"author":2722,"featured_media":26090,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1486],"tags":[105,205,1032,2719,22,628,187,1885,2757,97,629,630,486,321,521,131,692,174],"class_list":["post-26089","post","type-post","status-publish","format-standard","has-post-thumbnail","category-threats","tag-android","tag-botnets","tag-ddos","tag-fakes","tag-google","tag-internet-of-things","tag-passwords","tag-proxy","tag-proxyware","tag-security-2","tag-smart-devices","tag-smart-home","tag-smart-tv","tag-technology","tag-threats","tag-tips","tag-trojans","tag-wi-fi"],"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/smart-tv-box-residential-proxy-malware-threat\/26089\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/smart-tv-box-residential-proxy-malware-threat\/31057\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/smart-tv-box-residential-proxy-malware-threat\/30891\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/smart-tv-box-residential-proxy-malware-threat\/42675\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/smart-tv-box-residential-proxy-malware-threat\/56404\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/smart-tv-box-residential-proxy-malware-threat\/31055\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/smart-tv-box-residential-proxy-malware-threat\/36800\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/smart-tv-box-residential-proxy-malware-threat\/36468\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/smart-tv\/","name":"Smart TV"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2722"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=26089"}],"version-history":[{"count":1,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26089\/revisions"}],"predecessor-version":[{"id":26091,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26089\/revisions\/26091"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/26090"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=26089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=26089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=26089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}