Samsung said it is banning Smart TV apps that contain residential proxy software after researchers found several apps could route third-party internet traffic through users’ home connections. Security firm Mnemonic reported that some apps passed review with dormant proxy functionality and later fetched remote configuration at launch, allowing the behavior to be activated after approval. Researchers said at least one Samsung-endorsed Pac-Man app included Bright Data proxy code, raising concerns that large numbers of TVs could be turned into a botnet-like proxy network.
The findings highlighted a weakness in Smart TV app review, where thin-shell apps can load remote content that differs from the code originally inspected. Samsung said it has begun removing existing apps containing residential proxy SDKs, blocking new submissions with that functionality, and tightening restrictions after the disclosures. The case also underscored broader risks from third-party SDKs, remote feature toggles, and marketplace trust signals that can give unsafe apps added legitimacy.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After being contacted about the findings, Samsung said it had begun banning apps that share users' internet connections through residential proxy software. The company also said it had restricted new app registrations with proxy functionality, would remove existing apps containing such code, and was implementing platform-wide policies explicitly banning residential proxy SDKs.
Mnemonic published research describing how Samsung Smart TV apps could be turned into residential proxy nodes and warning that remote code or configuration changes could potentially activate large numbers of TVs into a botnet-like proxy network. The report also said some affected apps claimed installation counts in the hundreds of millions, according to their developers.
Mnemonic researcher Harrison Sand identified at least one Samsung-endorsed Pac-Man app containing Bright Data residential proxy code. Sand found the code loaded when the app opened and could remain dormant until a user accepted a consent screen, after which it could run in the background until the app was deleted.
Security researchers at Mnemonic found that several Samsung Smart TV apps contained residential proxy functionality or SDKs that could share users' internet connections with third parties. Their analysis showed some apps could retrieve remote configuration at launch, allowing proxy behavior to be enabled after app-store review.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcexakep.ru
Open sourcetechrepublic.com
Open sourcetechcrunch.com
Open sourcemnemonic.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.