Over 15 free VPN apps found on Google Play were found to be malicious, turning Android devices into residential proxies, likely used for cybercrime and shopping bots.

Residential proxies are devices that route internet traffic through devices located in homes, for other remote users, with the aim of making the traffic appear legitimate and reducing the chances of it being blocked.
These devices have legitimate uses (e.g. for market research, ad verification, and SEO), but are often used by cybercriminals who want to hide their malicious activities, such as ad fraud, spamming, phishing, credential stuffing, and password spraying.
See also: Anatsa: Android banking trojan has made its way to Google Play and is targeting more countries
Users can voluntarily sign up for services to receive monetary or other rewards, but some of these services use unethical means to secretly install proxying tools on users' devices.
After being installed on their devices, the internet bandwidth is compromised without their knowledge, while they risk facing legal problemsdue to its appearance as a source of malicious activity.
HUMAN's Satori research team identified 28 apps on Google Play that secretly turned Android devices into proxy servers, and 17 of them were posing as free software .
Satori analysts report that the malicious applications used a software development kit (SDK) from LumiApps that contained “Proxylib,” a Golang library for performing proxying.
Researchers discovered the first applications in May 2023. At the end of the same month, they noticed activity on hacking forums and new Android VPN applications.
See also: Aircove Go: ExpressVPN's portable Wi-Fi 6 router with built-in VPN
A subsequent investigation revealed a set of 28 apps that used the ProxyLib library to turn devices into proxies:
- Lite VPN
- Anims Keyboard
- Blaze Stride
- Byte Blade VPN
- Android 12 Launcher (by CaptainDroid)
- Android 13 Launcher (by CaptainDroid)
- Android 14 Launcher (by CaptainDroid)
- CaptainDroid Feeds
- Free Old Classic Movies (by CaptainDroid)
- Phone Comparison (by CaptainDroid)
- Fast Fly VPN
- Fast Fox VPN
- Fast Line VPN
- Funny Char Ging Animation
- Limo Edges
- Ok VPN
- Phone App Launcher
- Quick Flow VPN
- Sample VPN
- Secure Thunder
- Shine Secure
- Speed Surf
- Swift Shield VPN
- Turbo Track VPN
- Turbo Tunnel VPN
- Yellow Flash VPN
- VPN Ultra
- Run VPN
LumiApps is an Android app monetization platform that states that its SDK will use a device's IP address to load web pages in the background and send the retrieved data to companies.

“Lumiapps helps companies collect information that is publicly available on the internet. It uses the user’s IP address to load multiple web pages in the background from well-known websites,” the website states.
“This is done in a way that never interrupts the user and is fully GDPR/CCPA compliant. The web pages are then sent to companies, who use them to improve their databases, offering better products, services and prices,” he says.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: TMChecker exploit for attacks against VPNs and email
However, it is unclear whether the developers of the free VPN apps were aware that the SDK was turning Android devices into proxy servers (which could be used for unwanted and malicious activities).
HUMAN believes the malicious applications are linked to the Russian proxy service “Asocks,” according to an investigation. The Asocks service is commonly promoted to cybercriminals on hacking forums.
In January 2024, LumiApps released the second major version of the SDK along with Proxylib v2.
Google removed Android VPN apps that use the LumiApps SDK from the Play Storein February 2024. It also updated Google Play Protect to detect LumiApp libraries used in apps.
However, many of the above apps are back on Google Play, after their developers apparently removed the malicious SDK.
Those who have downloaded any of these applications should remove them from device or at least update them to the latest version, which presumably does not contain the malicious SDK.

If the app is no longer available on Google Play, it means that there is no safe version, so it should definitely be uninstalled from the device.
It is necessary to be careful with the applications we download on our Android devices. We should only choose trusted sources, such as the Google Play Store or the Apple App Store. But even on these platforms, we should carefully check the ratings and comments of other users.
See also: Iran bans “unauthorized” VPN use
It is safer to Android VPN paid instead of free services, as many free products can be malicious.
It's also important to keep devices up to date. Software updates often include security that can protect devices from the latest threats.
Finally, using a security app or antivirus software can provide additional protection. These apps can detect and remove malware before it can cause damage.
Source: www.bleepingcomputer.com
