Residential proxy networks are often hard for security teams to detect, but new research shows they can create serious enterprise risks.
Silent Push found that PEER2PROFIT, a bandwidth-sharing application, actively supplies residential proxy capacity to commercial provider ASTROPROXY.
PEER2PROFIT pays users to share unused internet bandwidth through an app installed on their devices. ASTROPROXY then resells access to those connections as residential, mobile, and datacenter proxy services.
Researchers confirmed the relationship by enrolling a controlled residential device in PEER2PROFIT and later detecting its IP address in ASTROPROXY’s proxy pool.
The commercial gap is significant. PEER2PROFIT reportedly pays residential users about $0.28 per GB, while ASTROPROXY sells residential proxy traffic for $7.60 per GB. This model turns ordinary home and business internet connections into commercial proxy exit nodes.
Silent Push observed 117,224 unique IP addresses across ASTROPROXY’s pools during a 72-hour enumeration effort. The residential pool accounted for 60,247 IPs and added an average of 1,071 new addresses per hour.
This rapid rotation makes traditional IP reputation controls less effective because an IP can appear benign one hour and operate as a proxy exit node the next.
Peer2Profit AstroProxy Exposes Resources
The most serious finding involved access to internal network resources. ASTROPROXY reportedly blocked direct requests to private IP ranges, which are commonly used by routers, NAS devices, and other local systems.
However, researchers found that the restriction could be bypassed by using a domain name that resolves to an internal IP address.

In a controlled test, the team used an enrolled PEER2PROFIT node available through ASTROPROXY to reach a residential router management interface.
The researchers downloaded a PNG file from the router as proof that the internal resource was accessible through the proxy network.
This means that a person who installs a bandwidth-sharing client may expose more than their public IP address.

Depending on network configuration, proxy subscribers could potentially reach local devices, including routers, smart-home equipment, storage systems, and other services accessible within that network, silentpush said.
The risk is more severe for remote workers and corporate environments. An employee could install a legitimate bandwidth-sharing application on a company device or a personal device connected to an office network.
The organization’s public address could then become a proxy exit node, while internal resources may become reachable through an external proxy service.
table
| Category | Details |
|---|---|
| Researcher | Silent Push |
| Bandwidth-sharing app | PEER2PROFIT |
PEER2PROFIT is not classified as malware. It is installed with user consent and distributed through official channels, making it unlikely to trigger antivirus alerts or standard threat-intelligence detections.
This creates a security blind spot, software can be legitimate while still introducing major exposure to corporate networks.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN