Free VPN apps on Google Play turned Android phones into proxies (2024)

Free VPN apps on Google Play turned Android phones into proxies (1)

Over 15 free VPN apps on Google Play were found using a malicious software development kit that turned Android devices into unwitting residential proxies, likely used for cybercrime and shopping bots.

Residential proxies are devices that route internet traffic through devices located in homes for other remote users, making the traffic appear legitimate and less likely to be blocked.

While they have legitimate uses for market research, ad verification, and SEO, many cybercriminals use them toconceal malicious activities, including ad fraud, spamming, phishing, credential stuffing, and password spraying.

Users may voluntarily register on proxy services to get monetary or other rewards in return, butsome of these proxy servicesemploy unethical andshady meansto install their proxying tools on people's devices secretly.

When secretly installed, victims will have their internet bandwidth hijacked without their knowledge and risk legal trouble due to appearing as the source of malicious activity.

Proxying Android VPN apps

A report published today by HUMAN's Satori threat intelligence team lists 28 applications on Google Play that secretly turned Android devices into proxy servers. Of these 28 applications, 17 were passed off as free VPN software.

Satori analysts report that the offending apps were all using a software development kit (SDK) by LumiApps that contained "Proxylib," a Golang library to perform the proxying.

HUMAN discovered the first PROXYLIB carrier app in May 2023, a free Android VPN app named "Oko VPN." The researchers later found the same library used by the LumiApps Android app monetization service.

"In late May 2023, Satori researchers observed activity on hacker forums and new VPN applications referencing a monetization SDK,lumiapps[.]io," explains theSatori report.

"Upon further investigation, the team determined that this SDK has exactly the same functionality and uses the same server infrastructure as the malicious applications analyzed as part of the investigation into the earlier version of PROXYLIB. "

A subsequent investigation revealed a set of 28 apps that utilized the ProxyLib library to convert Android devices into proxies, which are listed below:

  1. Lite VPN
  2. Anims Keyboard
  3. Blaze Stride
  4. Byte Blade VPN
  5. Android 12 Launcher (by CaptainDroid)
  6. Android 13 Launcher (by CaptainDroid)
  7. Android 14 Launcher (by CaptainDroid)
  8. CaptainDroid Feeds
  9. Free Old Classic Movies (by CaptainDroid)
  10. Phone Comparison (by CaptainDroid)
  11. Fast Fly VPN
  12. Fast Fox VPN
  13. Fast Line VPN
  14. Funny Char Ging Animation
  15. Limo Edges
  16. Oko VPN
  17. Phone App Launcher
  18. Quick Flow VPN
  19. Sample VPN
  20. Secure Thunder
  21. Shine Secure
  22. Speed Surf
  23. Swift Shield VPN
  24. Turbo Track VPN
  25. Turbo Tunnel VPN
  26. Yellow Flash VPN
  27. VPN Ultra
  28. Run VPN

LumiApps is an Android app monetization platform that states its SDK will use a device's IP address to load webpages in the background and send the retrieved data to companies.

"Lumiapps helps companies gather information that is publicly available on the internet. It uses the user's IP address to load several web pages in the background from well-known websites," reads the LumiApps website.

"This is done in a way that never interrupts the user and fully complies with GDPR/CCPA. The web pages are then sent to companies, who use them to improve their databases, offering better products, services, and pricing."

Free VPN apps on Google Play turned Android phones into proxies (2)

However, it is unclear if the free app developers knew that the SDK was converting their users' devices into proxy servers that could be used for unwanted activities.

HUMAN believes the malicious apps are linked to the Russian residential proxy service provider 'Asocks' after observing connections made to the proxy provider's website. The Asocks service is commonly promoted to cybercriminals on hacking forums.

Free VPN apps on Google Play turned Android phones into proxies (3)

In January 2024, LumiApps released the second major version of its SDK along with Proxylib v2. According to the firm, this addressed "integration issues," and it now supports Java, Kotlin, and Unity projects.

Following HUMAN's report, Google removed any new and remaining apps using the LumiApps SDK from the Play Store in February 2024 and updated Google Play Protect to detect the LumiApp libraries used in the apps.

Free VPN apps on Google Play turned Android phones into proxies (4)

Meanwhile, many apps listed above are now available again on the Google Play store, presumably after their developers removed the offending SDK. They were sometimes published from different developer accounts, potentially indicating previous account bans.

Free VPN apps on Google Play turned Android phones into proxies (5)

BleepingComputer has reached out to Google for a comment on the status of the currently available apps using the same names and whether they are now safe, but we have yet to hear back.

If you have used one of the listed apps, updating to the newest version that does not use the particular SDK will stop the proxying activity. However, out of an abundance of caution, it may be safer to remove them altogether.

If the app was removed from Google Play and no safe version exists, you are recommended to uninstall it. Play Protect should also warn users in that case.

Finally, it is likely safer to use paid VPN apps instead of free services as many products in the latter category are more eager to implement indirect monetization systems, including data collection/selling, advertising, and enrollment in proxy services.

Update 3/27 - A Google spokesperson sent BleepingComputer the following comment:

Google Play Protect automatically protects users by disabling these identified apps. Once the apps are disabled, they cannot run on the device or do any harm on the device.

Google Play Protect will also provide a warning and ask users if they would like to fully uninstall.

The spokesperson also confirmed that all 28 of the malicious apps reported by HUMAN have now been removed from Google Play.

Hence, all the apps with the same or similar names as those mentioned in the list above are completely safe to use.

Related Articles:

More Android apps riddled with malware spotted on Google Play

Google tests blocking side-loaded Android apps with risky permissions

Google says spyware vendors behind most zero-days it discovers

Google paid $10 million in bug bounty rewards last year

Google Pay app shutting down in US, users have till June to move funds

Free VPN apps on Google Play turned Android phones into proxies (2024)

FAQs

Free VPN apps on Google Play turned Android phones into proxies? ›

In May 2023, HUMAN's Satori Threat Intelligence team discovered that Oko VPN, a free VPN app offered through the Google Play store, utilized a Golang library that performed proxy node enrollment. Further investigation unearthed connections to 'Asocks,' a shady residential proxy seller, suggesting a monetization scheme.

Is there a 100% free VPN for Android? ›

Yes – ProtonVPN is a completely free Android VPN that you can use for as long as you like. It offers unlimited data and servers in 3 locations.

What malicious apps caught secretly turning Android phones into proxies for cybercriminals? ›

The discovery was made by HUMAN's Satori Threat Intelligence team. They found a group of VPN apps on the Play Store that come with a special feature. These apps use a Golang library to secretly transform your device into a proxy node without you even realizing it. HUMAN has codenamed this operation PROXYLIB.

Are free VPN apps on Google Play safe? ›

However, threat actors make use of interest in free VPN services to target users. Over 15 VPN apps on Google Play were found to be using malicious development kits to turn users' devices into residential proxies that are likely being used for cybercrime and shopping bots, a report from Bleeping Computer said. .

What is the best VPN proxy for Android? ›

The Best VPNs for Android in 2024
  • Best Privacy Features. NordVPN. 9.7 /10. Highly-rated Google Play app. ...
  • Best App Performance. Surfshark. 9.5 /10. Fast speeds, especially on Android devices. ...
  • Fastest VPN for Android. IPVanish. 9.3 /10. ...
  • Best Value Android VPN. Private Internet Access VPN. 9.4 /10. ...
  • Best Encryption. ExpressVPN. 9.1 /10.
Apr 3, 2024

Is there any 100% free VPN? ›

Proton VPN is currently the best free VPN. The vast majority of free VPNs impose heavy restrictions on things like data allowance, usage time and connection speeds, making them practically useless for anything beyond the most negligible of online activities. Proton VPN imposes no such limitations on its free users.

What is the best free VPN for Android without payment? ›

The best completely free VPN for Android is Proton VPN. The free VPN delivered high levels of internet privacy and security in our tests, as well as excellent speeds connecting to its free servers. Unlike other safe free VPNs, Proton VPN allows unlimited bandwidth, and there is no requirement to submit payment details.

What is the app that detects hacked phones? ›

Don't risk your phone getting hacked and your personal data being compromised. Avast One will detect and alert you in the event of a malware attack. Plus, it will automatically scan your phone for threats, protect your browsing with a web shield, and keep you safe from other online scams.

Is my Android phone being spied on? ›

15 signs someone is spying on your phone
  • Unfamiliar applications. ...
  • Anomalous data usage. ...
  • Your device is “rooted” or “jailbroken” ...
  • Your phone battery is draining fast. ...
  • Your phone is getting too hot. ...
  • Unusual activity on linked accounts. ...
  • Intrusive pop-ups. ...
  • Strange activity in standby mode.
Feb 21, 2024

What apps block hackers? ›

The best apps to protect your phone include Avast Mobile Security, Lookout Security & Antivirus, and McAfee Mobile Security. These apps are available on both Android and iOS devices.

What is the best free VPN on the Play Store? ›

The 5 Best 100% Free VPNs for Android – Our Favorites for 2024
  1. ProtonVPN. © ProtonVPN. ProtonVPN is definitely the best choice on this list and there's a simple reason for that – unlimited bandwidth. ...
  2. Hide.me. © Hide.me. ...
  3. TunnelBear. © TunnelBear. ...
  4. Hotspot Shield. © Hotspot Shield. ...
  5. Windscribe. © Windscribe.

What is Google's free VPN? ›

You can use VPN by Google One to help: Shield your online activity from hackers, internet service providers, phone carriers, and public Wi-Fi providers. Prevent others from knowing your IP address from the sites and apps that you visit.

How to use VPN on Android without apps? ›

Manually (built-in)

Go into your Android settings. Click Network & Internet. Click Advanced. Select VPN.

What is the best proxy for Google Play? ›

Best Google Play Proxies

Our residential proxies are the ideal solution for bypassing geo-restrictions and accessing the Google Play Store. We offer anonymous IPs from real devices situated around the globe, making it possible to access any content without worry.

How do I get proxy on Android? ›

How to configure proxy settings
  1. Open your Android's Settings by clicking on the gear icon.
  2. Tap Wi-Fi.
  3. From all the Wi-Fi networks, tap the ⓘ icon next to the Wi-Fi you're connected to.
  4. Click on Proxy to see all the advanced options.
  5. Change your Android proxy settings. Select Manual.

Is Atlas VPN still free? ›

Atlas VPN has two pricing tiers: Free and Premium. Free is exactly what the name implies with limited features. Notably, free users only get access to four server locations: The Netherlands, Singapore, Los Angeles and New York, and their data usage is limited to 5GB of data per account.

What is the best completely free VPN? ›

8 Free VPNs of 2024
  • TunnelBear: Best for user-friendliness.
  • Proton VPN: Best for enhanced anonymity.
  • hide.me: Best for leak protection.
  • Windscribe: Best for unlimited device connection.
  • VPN Unlimited: Best for lifetime protection.
  • CyberGhost: Best for ease of use.
  • Hotspot Shield: Best for streaming.
Apr 6, 2024

Does Android have built-in VPN? ›

Android includes a built-in (PPTP, L2TP/IPSec, and IPSec) VPN client.

Is ProtonVPN completely free? ›

Proton VPN's amazing free version has no limit on data usage, it's an Editors' Choice winner and one of the best VPNs. Proton VPN has one of the most attractive free options we've seen from any VPN. Without paying anything at all, you can get an ad-free VPN with no data logging and no bandwidth limits.

How can I set up VPN on my Android for free? ›

  1. Open your device's Settings app.
  2. Tap Network & internet. VPN. If you can't find it, search for "VPN." If you still can't find it, get help from your device manufacturer.
  3. Tap the VPN you want.
  4. Enter your username and password.
  5. Tap Connect. If you use a VPN app, the app opens.

References

Top Articles
Latest Posts
Article information

Author: Nathanial Hackett

Last Updated:

Views: 5886

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Nathanial Hackett

Birthday: 1997-10-09

Address: Apt. 935 264 Abshire Canyon, South Nerissachester, NM 01800

Phone: +9752624861224

Job: Forward Technology Assistant

Hobby: Listening to music, Shopping, Vacation, Baton twirling, Flower arranging, Blacksmithing, Do it yourself

Introduction: My name is Nathanial Hackett, I am a lovely, curious, smiling, lively, thoughtful, courageous, lively person who loves writing and wants to share my knowledge and understanding with you.