Phone being hacked Phone being hacked

Phone Used as Proxies via Malicious VPN Apps

A significant number of free VPN applications, which were available on the Google Play Store, were recently discovered to secretly repurpose user’s devices as unwitting proxies for the use in cyber-crime.

The ‘PROXYLIB’ campaign utilized a code library to facilitate proxy functionality and was found to be present in over 28 applications on the Google Play store, 17 of which were marketed as Free VPN software.

The applications which were part of the ‘PROXYLIB’ campaign provided legitimate and functional VPN services to users on the surface. However, in the background, they were secretly registering the user’s entire device and by association, network to a residential proxy network, without the user’s knowledge or consent.

Residential proxies are often considered as the prime proxy choice among cyber-criminals, as they can appear as a home network, compared to regular data-centre proxies which will almost always indicate a proxy being used. This allows an attacker to bypass many access controls across a wide variety of security systems, since the network will not appear as part of a proxy network.

The use of residential proxies can have legitimate purposes, such as market research or SEO. However, cybercriminals often exploit residential proxies for malicious purposes like fraud, spamming, and phishing.

Proxylib Operational Overview – (Source: Human Security, Inc)

Most concerningly, HUMAN, a security team, attribute the malicious applications to the Russian proxy service provider known as ‘Asocks’, after connections were made to the website. Asocks is commonly promoted to cybercriminals for the purpose of malicious activity on hacking forums.

A full list of the 28 applications which utilized the PROXYLIB library is as follows:

  1. Lite VPN
  2. Anims Keyboard
  3. Blaze Stride
  4. Byte Blade VPN
  5. Android 12 Launcher (by CaptainDroid)
  6. Android 13 Launcher (by CaptainDroid)
  7. Android 14 Launcher (by CaptainDroid)
  8. CaptainDroid Feeds
  9. Free Old Classic Movies (by CaptainDroid)
  10. Phone Comparison (by CaptainDroid)
  11. Fast Fly VPN
  12. Fast Fox VPN
  13. Fast Line VPN
  14. Funny Char Ging Animation
  15. Limo Edges
  16. Oko VPN
  17. Phone App Launcher
  18. Quick Flow VPN
  19. Sample VPN
  20. Secure Thunder
  21. Shine Secure
  22. Speed Surf
  23. Swift Shield VPN
  24. Turbo Track VPN
  25. Turbo Tunnel VPN
  26. Yellow Flash VPN
  27. VPN Ultra
  28. Run VPN

Regarding containment for a device that has installed one of the listed apps, BleepingComputer recommends the following approach:

  1. Update the application to the newest version: This would ensure the PROXYLIB library would not be present, and therefore, will stop the proxying activity.
  2. Removal of the application: While the updated version may address the proxying
    activity, uninstalling the application from affected devices eliminates the risk of possible malicious activity entirely.

The ‘PROXYLIB’ application outlines the importance of cautiousness and due diligence required by not only organizations and industry professionals, but also individual consumers. With constantly evolving threats, including the obfuscated nature of applications such as the ones as part of the PROXYLIB campaign, consumers of all levels may fall victim to having their network being used by criminals, entirely without their knowledge.

Leave a Reply

Your email address will not be published. Required fields are marked *