Accessibility Statement Skip Navigation
  • Resources
  • Investor Relations
  • Journalists
  • +44 (0)20 7454 5110
  • Client Login
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All Public Company News
      • All Multimedia News
      • View All News Releases

      • Regulatory News

      • D/A/CH Regulatory News
      • UK Regulatory News
      • View All Regulatory News

  • Business & Money
      • Auto & Transportation

      • Aerospace & Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads & Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking & Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film & Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers & Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalisation
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls & Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil & Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defence
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation & Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking & Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers & Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines & Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics & Personal Care
      • Fashion
      • Food & Beverages
      • Furniture & Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewellery
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film & Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks & Tourist Attractions
      • Gambling & Casinos
      • Hotels & Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Animal Welfare
      • Corporate Social Responsibility
      • Economic News, Trends & Analysis
      • Education
      • Environmental
      • European Government
      • Labour & Union
      • Natural Disasters
      • Not For Profit
      • Public Safety
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Report Results
  • Amplify Content
  • All Products
  • General Enquiries
  • Media Enquiries
  • Partnerships
  • Hamburger menu
  • Cision PR Newswire UK provides press release distribution, targeting, monitoring, and marketing services
  • Send a Release
    • Phone

    • +44 (0)20 7454 5110 from 8 AM - 5:30 PM GMT

    • ALL CONTACT INFO
    • Contact Us

      +44 (0)20 7454 5110
      from 8 AM - 5:30 PM GMT

  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists
  • News in Focus
    • Browse News Releases
    • Regulatory News
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
    • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Report Results
  • Amplify Content
  • All Products
  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists
  • General Enquiries
  • Media Enquiries
  • Partnerships
  • Worldwide Offices
  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists

Plume Security Labs Exposes Hidden Proxy Network Inside SuperBox Streaming Devices that Route Potentially Harmful Traffic over Home Networks

This image opens in the lightbox

News provided by

Plume Design, Inc.

28 May, 2026, 12:00 GMT

Share this article

Share toX

Share this article

Share toX

Investigation reveals media streaming devices sold at major U.S. retailers silently tunnel third-party internet traffic, including potentially stolen credentials and enterprise security bypass operations through subscribers' home broadband connections

PALO ALTO, Calif., May 28, 2026 /PRNewswire/ -- Plume Design, Inc. ("Plume"), the global subscriber experience platform for more than 450 Internet Service Providers (ISPs) across 58 countries, today released a report that uncovers significant security concerns found in SuperBox Android streaming devices sold at major U.S. retailers, which contain dormant software that when activated converts consumers' home internet connections into nodes in a residential proxy network or SuperProxy. The proxy routes unknown third-party traffic that includes potentially stolen credentials, account takeover materials and enterprise security bypass operations through subscriber households without their knowledge or consent. The report, based on a months-long investigation, is the first in a series from Plume's Security Labs.

Continue Reading
This image opens in the lightbox
Plume Security Labs Exposes Hidden Proxy Network Inside SuperBox Streaming Devices that Route Potentially Harmful Traffic over Home Networks.

"The average connected home is becoming increasingly complex, more like a corporate network, and threats like this one illustrate the need for significantly enhanced levels of intelligence and security," said Chris Griffiths, Chief Technology Officer at Plume. "ISPs are better situated than ever to be on the forefront of detecting and resolving these issues. By leveraging AI and large-scale network orchestration across hundreds of millions of devices, we can help ISPs spot anomalies that individual households or traditional security tools often miss, and act on them before they spread."

Plume manages one of the most comprehensive data sets in the telecommunications industry, monitoring more than 500 million connected devices across 40 million households globally. After an alert from a customer, Plume's Network Operations Center flagged anomalous outbound traffic from an unusually high number of streaming devices across its network. The traffic volume was sufficient to destabilize residential networks, prompting Plume's Security Labs to launch a comprehensive technical investigation into streaming devices, spanning multiple models, across its user base.

"The SuperProxy investigation is a wake-up call," said Eric Svenson, Vice President, Technology Engineering and Operations at Armstrong, (a multi-state operator based in Pennsylvania). "Consumer devices are being weaponized inside our subscribers' homes, and as their ISP, we have both the responsibility and the vantage point to do something about it. Plume's research is the kind of partnership our industry needs more of; work that protects Armstrong customers today and sets a higher standard for what every subscriber should expect from their provider."

"These devices ship with remote access and full administrative control, wide open and require no password, no authentication, no user approval," said Griffiths. "Unfortunately, this isn't limited to a single product. The same residential proxy software was used in other types of consumer media streaming devices and also used in other malicious campaigns such as the Vo1d botnet, which demonstrates this is a broader supply-chain problem across the streaming ecosystem."

Five Key Findings

A streaming app secretly turns the device into a proxy network node. One of the apps available through SuperBox's custom application store, Cyberflix TV, contains hidden proxy software called Popanet that silently registers the device with a remote command server and begins relaying foreign internet traffic through the subscriber's home connection. Plume's telemetry recorded tens of thousands of outbound connections per device per day to thousands of distinct destinations.

Sensitive credentials and security bypass attempts are flowing through subscriber homes. Researchers intercepted the actual traffic being routed through the proxy and found sensitive login credentials for gaming platforms, messaging app verification codes that could be used for real-time account takeovers, deliberate attempts to defeat enterprise security systems and large-scale automated web scraping, all passing through consumer broadband connections without the subscriber's knowledge.

Plume mapped more than 250 proxy server addresses. Researchers fully reverse-engineered Popanet's command-and-control protocol — the first publicly known teardown of this system — and mapped more than 250 verified server addresses across multiple hosting providers, revealing a professionally built proxy operation.

A security flaw in the proxy's own code exposes the home network. The proxy attempts to block access to the subscriber's local network, but contains a bypass that was confirmed through live testing. Remote proxy users can exploit this flaw to reach the device's own internal services, potentially extending the compromise beyond the device to the home network itself.

SuperBox's custom app store bypasses all standard Android safety checks. The store installs software silently with full administrative privileges: no security verification, no warnings and no user approval. Its catalog is controlled by the store's operator, not by Google nor the device owner.

Plume's Approach

Plume is identifying and isolating these proxies for blocking at multiple levels and sharing intelligence with its ISP customers. Monitoring these proxies is extending Plume's detection capabilities to additional threat types including Distributed Denial of Service (DDoS) tools and botnets.

Multi-phased Research

This is Part 1 of a three-part investigative series into SuperBox and the hidden security risks it presents inside subscriber homes. Part 2 will expose the malware ecosystem exploiting subscriber devices, including botnet agents and competing proxy SDKs, and detail how Plume helps ISPs detect and block these threats. Part 3 will examine the content delivery infrastructure behind SuperBox's "latest movies" promise, presenting technical evidence that raises serious questions about the origin of that content.

The full research paper is available at:

plume.com/resources/superproxy-the-unhealthy-marriage-of-superbox-and-residential-proxies

About Plume
Plume established the first managed WiFi platform for ISPs in 2016, enabling the company to scale across the globe and expand into managing the entire subscriber experience, including approximately 500 million connected devices, in 40 million homes, on behalf of 450 ISPs, across 58 countries. By integrating managed WiFi, cybersecurity and customer care, Plume created the first open, hardware-agnostic SaaS Subscriber Experience Platform for ISPs. Powered by an unmatched global dataset and AI optimization, the Plume Platform builds subscriber confidence through improved Wi-Fi experiences, seamless new service implementation and proactive customer care. Plume's open-source framework OpenSync® is pre-integrated and supported on the leading silicon, CPE and platform SDKs, and supports leading industry standards like RDK-B and prplWave. Discover more about how Plume is empowering ISPs at plume.com.

About Armstrong
For over 80 years, Armstrong has been a leader in telecommunications technology and innovation. Founded in 1946 by Jud L. Sedwick as Armstrong County Line Construction, Armstrong remains a family-owned and operated company deeply committed to the communities it serves.

Armstrong's world-class fiber network spans six states—Pennsylvania, Ohio, Maryland, New York, West Virginia, and Kentucky—delivering advanced infrastructure with a focus on exceptional customer service and satisfaction. The company provides 24/7 local support, transparent pricing, and complimentary technical service to residential and business customers throughout its service area.

For more information on Armstrong's Advanced Fiber Network, please visit ArmstrongOneWire.com/network.

Photo - https://mma.prnewswire.com/media/2989435/PLUME_DESIGN_INC__Security_Labs.jpg
Logo - https://mma.prnewswire.com/media/1960101/Plume__Logo.jpg

Modal title

Also from this source

Plume Earns Certified Most Loved Workplace® Recognition One Year After Launching Company-Wide Culture Transformation

Plume Earns Certified Most Loved Workplace® Recognition One Year After Launching Company-Wide Culture Transformation

Plume Design, Inc. ("Plume"), the global technology leader trusted by more than 450 Internet Service Providers (ISPs) across 58 countries, today...

FPT Partners with Plume to Deliver Intelligent Wi-Fi Optimization and Enhanced Connectivity for Vietnamese Households

FPT Partners with Plume to Deliver Intelligent Wi-Fi Optimization and Enhanced Connectivity for Vietnamese Households

FPT Telecom, one of Vietnam's leading telecommunications and Internet service providers and a subsidiary of FPT Corporation, today announced a...

More Releases From This Source

Explore

Computer & Electronics

Computer & Electronics

Telecommunications Industry

Telecommunications Industry

High Tech Security

High Tech Security

Networks

Networks

News Releases in Similar Topics

Contact PR Newswire

  • +44 (0)20 7454 5110
    from 8 AM - 5:30 PM GMT
  • General Enquiries
  • Media Enquiries
  • Partnerships

Products

  • Content Distribution
  • Multimedia Services
  • Disclosure Services
  • Cision Communications Cloud®

About

  • About PR Newswire
  • About Cision
  • Partnering Opportunities
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United States
  • Vietnam

My Services

  • All News Releases
  • PR Newswire Amplify™
  • Resources
  • Blog
  • Journalists
  • Data Privacy

Do not sell or share my personal information:

  • Submit via Privacy@cision.com 
  • Call Privacy toll-free: 877-297-8921

Contact PR Newswire

Products

About

My Services
  • All News Releases
  • Customer Portal
  • Resources
  • Blog
  • Journalists
+44 (0)20 7454 5110
from 8 AM - 5:30 PM GMT
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 PR Newswire Europe Limited. All Rights Reserved. A Cision company.