LG Electronics is suspending webOS applications that route third-party traffic through residential-proxy technology unless their developers remove the capability. A package-level review by Spur found residential-proxy SDK indicators in 2,058 of 6,038 examined LG webOS and Samsung Tizen applications, with proxy functionality present in more than 42% of the LG apps assessed. The SDKs can turn a television’s internet connection and public IP address into an exit node, potentially with inadequate consent and, in some cases, while the app is closed; weak filtering could also place other devices on the TV’s local network at risk.
The action highlights a broader ecosystem in which developers embed monetization SDKs in consumer software to supply residential IP addresses to proxy providers. Google Threat Intelligence Group disrupted one such network, IPIDEA, after identifying SDKs in more than 600 Android apps and 3,000 Windows binaries that enrolled millions of devices; Google observed over 550 threat groups using its exit nodes during one seven-day period, including China-, North Korea-, Iran-, and Russia-linked actors. Residential proxy nodes may relay credential-stuffing, fraud, account-takeover, scraping, unauthorized-access, or espionage traffic, exposing affected users to blocklisting, service restrictions, and investigative scrutiny.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence Group disrupted IPIDEA, a residential proxy network built through SDKs embedded in more than 600 Android applications and over 3,000 Windows binaries. Google reported that the action removed millions of enrolled devices from circulation; during a seven-day observation window, it identified more than 550 threat groups using IPIDEA exit nodes, including actors linked to China, North Korea, Iran, and Russia.
LG Electronics began suspending webOS applications that route third-party traffic through residential proxy technology and said it was working with developers to remove the functionality. LG had not announced a deadline for developers to comply and may increase scrutiny during its app-review process.
Spur's package-level analysis identified residential-proxy SDK fingerprints in 2,058 of 6,038 examined LG webOS and Samsung Tizen applications, including more than 42% of the examined LG apps. The research found that some SDKs could remain active after an app closed and warned that inadequate filtering could expose devices on a television's local network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.