Malicious Apps Caught Secretly Turning Android Phones into Proxies for Cybercriminals
ID: ac34dbba-9aad-5aa5-a7ab-3bb8cfe410ed
STIX ID: report--ac34dbba-9aad-5aa5-a7ab-3bb8cfe410ed
Feed Name: The Hacker News
**PROXYLIB**: Several malicious Android VPN apps on Google Play used a native Golang library and the LumiApps SDK to covertly convert infected mobile devices into residential proxy nodes (RESIPs); Google removed 29 apps after discovery. Operators reportedly enroll devices, route traffic through them, sell access to the proxy network via services like LumiApps and Asocks, and incentivize developers to expand the botnet, enabling threat actors to obfuscate origins and facilitate further abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
