On Wednesday, Brian Krebs published a piece that should, by rights, terrify anyone who has ever clicked “Buy Now” on a $40 Android TV box. His July 30 report details how a substantial percentage of off-brand streaming sticks sold through Amazon, Best Buy, Newegg, and Walmart arrive with malware pre-installed — software that quietly converts the device into a residential proxy node, renting out your home IP address to strangers on the internet.
The conventional response to this news writes itself: don’t buy cheap Chinese electronics. Change your passwords. Check your router logs. All good advice. All missing the point.
The story here isn’t that cheap hardware is sketchy. That has been true since the first factory in Shenzhen figured out how to shave fifty cents off a bill of materials. The story is that there is a thriving, multi-million-dollar market for residential IP addresses — and the customers aren’t just cybercriminals.
The Supply Side Is Two Million Devices and Counting
The Krebs report is the latest dispatch from a battlefield that has been expanding for years. In January, the Kimwolf botnet was found to have infected more than two million devices, many of them Android TV boxes. Kimwolf’s operators reportedly bragged about compromising the control panel for Badbox 2.0, a China-based botnet that also relied on pre-installed malware on streaming hardware. The cybersecurity firm Bitsight has tracked the infrastructure behind these operations, linking them to a company called Zhejiang Fengwo IoT Technology Ltd.
The scale is staggering, but the mechanics are simple. A piece of code smaller than a family photo sits on a device in your living room, maintaining an encrypted tunnel to a command-and-control server. When someone, somewhere, needs to make a web request that appears to come from a residential IP address in suburban Dallas or rural Ohio, your TV stick handles it. You never notice. Your Netflix still works fine.
The Demand Side Wears a Tie
Here is where the story gets uncomfortable. The people buying access to residential proxy networks are not, for the most part, cartoon villains in hoodies. They are ad verification companies checking whether their clients’ display ads are rendering correctly. They are e-commerce price scrapers monitoring competitors’ listings. They are sneaker resellers running bots to secure limited drops. They are SEO firms checking search rankings from different geographic locations. They are travel aggregators comparing flight prices without getting blocked.
These are, in many cases, legitimate businesses — or at least businesses that operate in the daylight, with office space and payroll and corporate credit cards. They buy residential proxy access from intermediaries who present themselves as above-board data services. The intermediaries buy from networks that buy from affiliates that buy from the malware operators. Everyone in the chain has just enough plausible deniability to sleep at night.
One digital marketing executive, nursing a beer at a conference hotel bar in Austin earlier this year, put it plainly: “Look, I don’t ask where the IPs come from. I pay a vendor, they give me clean residential IPs, I do my competitive analysis. If I asked questions, I’d have to find a new vendor, and my reports would take three times as long. Nobody wants that conversation.”
Nobody wants that conversation. That is the whole business model.
The Regulatory Blind Spot Is the Product
The Federal Trade Commission has authority over unfair and deceptive trade practices. The Federal Communications Commission regulates communications devices. The Department of Justice prosecutes computer fraud. And yet a device sold on Amazon with Prime shipping can quietly enroll your home network in a criminal enterprise, and the legal apparatus designed to prevent exactly this kind of thing is effectively absent.
Part of the problem is jurisdictional. The manufacturers are overseas. The malware operators are overseas. The proxy networks are incorporated in jurisdictions that make subpoenas an exercise in futility. But part of the problem is simpler than that: nobody in Washington has decided this is worth prioritizing. The victims are individual consumers who do not know they have been victimized. The beneficiaries are companies that do not want to be looked at too closely. The political constituency for enforcement is, in practical terms, zero.
Meanwhile, the market grows. Estimates from cybersecurity researchers suggest the residential proxy industry generates hundreds of millions of dollars annually. That money does not come from nowhere. It comes, in part, from the $40 streaming stick you plugged into the back of your television because the Roku was too expensive.
The uncomfortable truth is that the internet economy has normalized a practice — the buying and selling of residential IP addresses — that is functionally indistinguishable from the unauthorized use of someone else’s computer. We have simply built enough euphemisms and intermediary layers to make it feel like commerce rather than intrusion. Krebs’s report is a reminder that the euphemisms have a body count, measured in millions of compromised devices. The people renting your living room IP address probably have a LinkedIn profile. That is not a contradiction. That is the business.
Sources
- Read This Before You Buy That TV Streaming Stick
- Is Your Android TV Streaming Box Part of a Botnet? – Krebs on Security
- Top 5 Best Streaming Devices 2026 Don’t Buy Before Watching!
- residential proxies – Krebs on Security
- Popa botnet hijacks Android TV boxes to act as residential proxies | Fox News
- The Kimwolf Botnet is Stalking Your Local Network – Krebs on Security