Malicious smart TV apps enable covert proxy networks used by cybercriminals

Security researchers warn of a surge in malicious smart TV applications capable of turning household devices into hidden components of proxy networks, exposing users to cyberattacks and bandwidth theft amid lax app review processes.

Security researchers have identified a wave of malicious smart TV apps that can turn household televisions into parts of a proxy network, quietly routing internet traffic through home connections and obscuring the real source of online activity. According to reporting by FlatpanelsHD and TechCrunch, the affected devices include sets running Samsung’s Tizen and LG’s webOS software, with Roku and Amazon Fire TV also named among the platforms where suspicious apps have appeared.

The basic method is simple but difficult for ordinary users to spot. An app or game appears normal, yet contains code that allows third parties to use the television’s internet connection in the background. That means a smart TV can be drafted into a botnet without the viewer opening the app again, and without any obvious warning on screen. In practice, the owner may only notice slower broadband speeds, higher data use or unexplained activity linked to their home IP address.

The scale of the problem has been a concern. FlatpanelsHD said security firm Spur found that more than 42% of apps available on LG’s webOS platform contained botnet code capable of routing traffic through televisions, while 26.5% of Samsung’s Tizen apps were similarly affected. The publication also reported that one infected app was a Pac-Man game aimed at children and promoted by Samsung as an Editor’s Choice pick, raising questions about how such software passed platform review.

TechCrunch reported on 3 August 2026 that Samsung said it had already restricted new app registrations involving these proxy functions and was introducing stricter developer rules to ban residential proxy software. LG has taken a similar line. John Taylor, senior vice-president at LG, told KrebsOnSecurity that a residential proxy network was not an intended use for its smart TVs and that LG was working with developers to remove the functionality from webOS apps, with suspension threatened for those that do not comply.

The concern is not limited to bandwidth theft or hidden traffic. Security researchers and the reports cited by FlatpanelsHD say residential proxy networks have been rented out by criminal groups, including actors linked to China, North Korea, Iran and Russia, for cyberattacks and large-scale data gathering. For users, the practical response is to remove suspicious apps, update the television’s software, change passwords and check home network settings for unfamiliar devices.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.