Peer2Profit AstroProxy Residential Proxy Network Exposes Internal Network Resources

Residential proxy networks are often hard for security teams to detect, but new research shows they can create serious enterprise risks.

Silent Push found that PEER2PROFIT, a bandwidth-sharing application, actively supplies residential proxy capacity to commercial provider ASTROPROXY.

PEER2PROFIT pays users to share unused internet bandwidth through an app installed on their devices. ASTROPROXY then resells access to those connections as residential, mobile, and datacenter proxy services.

Researchers confirmed the relationship by enrolling a controlled residential device in PEER2PROFIT and later detecting its IP address in ASTROPROXY’s proxy pool.

The commercial gap is significant. PEER2PROFIT reportedly pays residential users about $0.28 per GB, while ASTROPROXY sells residential proxy traffic for $7.60 per GB. This model turns ordinary home and business internet connections into commercial proxy exit nodes.

Silent Push observed 117,224 unique IP addresses across ASTROPROXY’s pools during a 72-hour enumeration effort. The residential pool accounted for 60,247 IPs and added an average of 1,071 new addresses per hour.

This rapid rotation makes traditional IP reputation controls less effective because an IP can appear benign one hour and operate as a proxy exit node the next.

Peer2Profit AstroProxy Exposes Resources

The most serious finding involved access to internal network resources. ASTROPROXY reportedly blocked direct requests to private IP ranges, which are commonly used by routers, NAS devices, and other local systems.

However, researchers found that the restriction could be bypassed by using a domain name that resolves to an internal IP address.

Old PEER2PROFIT website (Source: silentpush)
Old PEER2PROFIT website (Source: silentpush)

In a controlled test, the team used an enrolled PEER2PROFIT node available through ASTROPROXY to reach a residential router management interface.

The researchers downloaded a PNG file from the router as proof that the internal resource was accessible through the proxy network.

This means that a person who installs a bandwidth-sharing client may expose more than their public IP address.

PEER2PROFIT Telegram bot (Source: silentpush)
PEER2PROFIT Telegram bot (Source: silentpush)

Depending on network configuration, proxy subscribers could potentially reach local devices, including routers, smart-home equipment, storage systems, and other services accessible within that network, silentpush said.

The risk is more severe for remote workers and corporate environments. An employee could install a legitimate bandwidth-sharing application on a company device or a personal device connected to an office network.

The organization’s public address could then become a proxy exit node, while internal resources may become reachable through an external proxy service.

table

CategoryDetails
ResearcherSilent Push
Bandwidth-sharing appPEER2PROFIT

PEER2PROFIT is not classified as malware. It is installed with user consent and distributed through official channels, making it unlikely to trigger antivirus alerts or standard threat-intelligence detections.

This creates a security blind spot, software can be legitimate while still introducing major exposure to corporate networks.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories