Smart televisions and other consumer devices are increasingly exploited as covert platforms for proxy traffic, enabling large-scale cyber attacks and traffic rerouting, posing new challenges for cybersecurity defenders.
Smart televisions have become an efficient vehicle for proxy traffic because they are typically always connected, rarely monitored and often left running in the background. A Cyber Defence Magazine article argues that this makes them close to ideal hosts for residential routing abuse, especially when their owners are offered what looks like a harmless consent screen inside a free app, screensaver or streaming front-end.
The problem is not only that users often agree without reading the terms. It is that the permission can be broad enough to let a device relay other people’s web traffic while it sits idle, with one analysed kit reportedly allowing up to 200 gigabytes a month under the label of “occasional use”. In practice, the traffic is often commercial web scraping, but the same residential path can also be used for sneaker bots, credential abuse and other activity that benefits from appearing to come from a normal household connection.
That overlap between lawful and hostile use is what makes the ecosystem difficult to police. A residential IP address is less likely to be blocked than a data-centre one, so commercial proxy networks have an obvious incentive to recruit consumer devices at scale. According to the Cyber Defence Magazine piece, the kits used for this purpose typically run over persistent connections with weak controls, making them easier to repurpose than many criminal command-and-control channels.
The shift from proxy service to attack platform can be immediate. Nokia Deepfield telemetry, as described in the article, shows devices appearing in distributed denial-of-service incidents rising from roughly one million for a long period to more than nine million by June 2026, with the increase beginning in late 2025. The article links that rise to a residential proxy exposure disclosed in early 2026, which appears to have opened access to infrastructure that was already in place rather than creating a new weakness.
Recent research suggests the same model is spreading beyond televisions. Kaspersky has identified malware campaigns against Android-based car head units that abused legitimate update mechanisms to install hidden proxy tools and other payloads, while Google and the FBI disrupted the NetNut, or Popa, residential proxy network in July 2026 after it was found to have co-opted more than two million devices worldwide. Together, those cases point to a broader pattern: the devices change, but the business model is the same.
For defenders, the practical lesson is that reputation-based controls are losing ground. Home networks, residential ranges and consumer devices can no longer be assumed to be benign simply because they sit behind a household broadband line. The signal that remains useful is behavioural: persistent outbound connections from devices that should be quiet, repeated relay-like patterns and traffic that looks normal only until it is seen at scale.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





