Samsung and LG promise to clamp down on apps that turn smart TVs into botnets

MW
Mike Wheatley
Samsung and LG promise to clamp down on apps that turn smart TVs into botnets

Remember the “resproxies” that can potentially hijack your smart TV and merge it into a massive botnet in order to conduct malicious cybercrime on the web?

We first reported on them last month and unfortunately they’re still around, but the good news is that both Samsung Electronics and LG Electronics are promising to fight tooth and nail to get rid of any and all smart TV applications containing resproxy code.

In August, the cybersecurity firm Mnemonic reported that it had discovered hundreds of Tizen-based smart TV applications that contain code that’s able to route third-party web traffic through internet-connected TVs. These “residential proxy networks,” to give them their correct name, are becoming increasingly popular with bad guys as a way to try and hide their cybercrime activities. Basically, what happens is that they get people to unwittingly download a smart TV app, and once that app starts running, the resproxy code within them hijacks the TV’s web connection to funnel malicious traffic through the TV.

Cybercriminals do this because resproxies provide them with a way to hide cyberattacks and make it look as if the traffic they generate is coming from a normal household, when in fact it’s all part of a larger, orchestrated botnet. It’s a way to avoid being traced.

One of the applications containing resproxy code that Mnemonic discovered was a popular Pac-Man game that had once been featured by Samsung in its app marketplace. It contained resproxy code from a company called Bright Data, which wrote the code for legitimate web scraping applications.

Mnemonic isn’t the only security firm to have highlighted resproxies. Research published by Spur in July revealed that more than 42.5% of all of the applications available for LG’s webOS platform contained resproxy code, enabling hackers to route their botnet traffic through that company’s TVs. In Samsung’s case, the resproxies weren’t as commonplace, as Spur identified the code in “just” 26.5% of all Tizen-based smart TV apps.

Naturally, when these reports first emerged, many Samsung and LG TV owners raised concerns about the resproxies on public forums like Reddit. While the nature of resproxies means the TV owners are likely unaware that their TV is being used as part of a botnet, it does have a negative impact on the TV’s performance, likely slowing down whatever shows they’re streaming. So it’s not something you really want your TV to be a part of.

Fortunately, LG and Samsung have both responded, assuring TV owners that they’re doing their utmost to get resproxy code removed from smart TV applications.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” a spokesperson for LG told KrebsOnSecurity. “If this option is not removed, these apps will be suspended.”

Last month, Samsung told TechCrunch that it’s also taking action, telling app developers in no uncertain terms that resproxies are no longer allowed in Tizen applications.

“We have already restricted new app registrations that incorporate such proxy functionalities on our smart TV platform,” a company spokesperson said. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently in our store that contain these components.”