Researchers reported that certain SuperBox pirate-streaming devices, including the S7 Pro, and the CyberFlix TV application can covertly enroll household connections in the Popanet residential proxy network. Traffic routed through a victim’s public IP address can consume bandwidth, conceal criminal activity, and leave the household associated with abuse it did not perform. Google reportedly estimated that Popanet operated through approximately two million devices.
The affected configurations reportedly disable key Android protections, expose unauthenticated Android Debug Bridge (ADB) access and root privileges, permit silent APK installation, and maintain encrypted outbound proxy connections. In a three-week Popanet honeypot test, researchers logged 1,352 attempts to access ADB services, including attempts to install the Mirai-derived CECbot and the proxy/DDoS-capable Maskify malware. Owners of affected SuperBox devices or devices running CyberFlix TV should disconnect and replace them, as a factory reset may not restore a trustworthy state.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Plume Security Labs published Part 2 of its SuperProxy investigation, identifying the Netway SDK in AppLinked and the Proxice framework on SuperBox devices. The report described Netway reverse-proxy infrastructure and a shared proxy credential exposure, plus Proxice's signed DEX payload delivery, ENS-based C2 resolution, private-network access, and apparent credential stuffing against Microsoft login services.
Ars Technica published reporting based on Plume research that SuperBox S7 Pro devices expose unauthenticated ADB and root access, disable Android safeguards, and maintain proxy-server connections that can enable remote command execution and malware installation.
Plume Security Labs reported that Cyberflix TV on SuperBox streaming devices contained hidden Popanet software that silently enrolled devices in the SuperProxy residential-proxy network. Researchers observed sensitive credentials, verification codes, enterprise-security bypass attempts, and scraping traffic, and confirmed a flaw that could let proxy users reach internal services and potentially compromise the home network.
After joining the Popanet network as a residential exit node and redirecting ADB ports 5555 and 5858 to a honeypot, Plume recorded 1,352 distinct access attempts over more than three weeks. The attempts used 0.0.0.0 or 127.0.0.1 loopback techniques and included efforts to install the CECbot Mirai variant and Maskify.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcexakep.ru
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcecyberveille.ch
Open sourceplume.com
Open sourceprnewswire.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.