A new Silent Push investigation reveals that a “passive income” app called Peer2Profit is feeding a commercial proxy service, Astroproxy, that resells enrolled users’ internet connections at up to 27 times what those users were paid, and researchers have shown that the resulting network can reach into home routers behind those IPs.
Peer2Profit markets itself as easy money: install an app, share unused bandwidth, get paid in crypto via a Telegram bot. Rates run $0.35/GB for cellular traffic, $0.28/GB for residential, and $0.10/GB for hosting connections.
Silent Push researchers enrolled a clean residential IP in the Peer2Profit Android app and watched it surface in Astroproxy’s proxy pool within about 10 minutes, confirming an active operational pipeline between the two.
Peer2Profit & Astroproxy Turn Employee Bandwidth
Astroproxy then resells that same bandwidth at $7.60/GB for residential, $13.44/GB for mobile, and $3.95/GB for datacenter traffic, meaning the operation pockets more than 97% of the resale value.

Over a 72-hour crawl, Silent Push enumerated 117,224 unique IPs across Astroproxy’s three pools: 60,247 residential, 38,762 datacenter, and 18,215 mobile.
The residential pool alone churns over 1,000 new IPs hourly, with datacenter adding 585 and mobile 353. Russia and Vietnam dominate the residential geography, while the U.S. accounts for nearly 47% of datacenter IPs; top contributing ISPs include Rostelecom, Viettel, VNPT, and Portugal’s MEO and NOS.
That volatility is precisely why traditional IP-reputation blocklists fail here: by the time an abusive IP gets flagged, it has already rotated out.
The critical finding for defenders isn’t the resale markup; it’s the blind spot. Peer2Profit installs through official app stores with full user consent, so antivirus engines and threat intel feeds have nothing to flag. Any employee can install it on a work laptop or a personal device tethered to the office Wi-Fi without triggering a single alert.
Once running, that device’s public IP and, by extension, the organization’s IP space becomes a rentable exit node for anyone with an Astroproxy subscription, exposing the company to credential-stuffing traffic, fraud attribution, or blocklisting under its own name.

Silent Push’s most alarming discovery: Astroproxy blocks direct requests to internal IP ranges, but that filter evaluates only the literal IP in a request, not where a domain name actually resolves.
By pointing a domain to the default internal address used by MEO Fiber routers, researchers routed a request through an enrolled Peer2Profit node and retrieved a PNG file directly from a residential router’s admin panel.
Astroproxy was notified before publication and given time to remediate; no fix materialized, prompting public disclosure. Subscribers can also filter proxy nodes by country, city, ASN, or connection type, letting an attacker target a specific ISP’s internal management interfaces or probe assets near a chosen corporate network using just one compromised node.
Silent Push argues that reputation-based blocking is structurally too slow for such fluid infrastructure, and advocates active enumeration of proxy pools, combined with traffic-origin attribution, to flag exit nodes in real time rather than after abuse occurs.
Until detection catches up, security teams should treat bandwidth-sharing apps as a policy violation, not a nuisance, because the “not malware” label is exactly what’s letting this traffic walk past every existing control.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.