Free VPN apps on Google Play turned Android phones into proxies (2024)

Free VPN apps on Google Play turned Android phones into proxies (1)

Over 15 free VPN apps on Google Play were found using a malicious software development kit that turned Android devices into unwitting residential proxies, likely used for cybercrime and shopping bots.

Residential proxies are devices that route internet traffic through devices located in homes for other remote users, making the traffic appear legitimate and less likely to be blocked.

While they have legitimate uses for market research, ad verification, and SEO, many cybercriminals use them toconceal malicious activities, including ad fraud, spamming, phishing, credential stuffing, and password spraying.

Users may voluntarily register on proxy services to get monetary or other rewards in return, butsome of these proxy servicesemploy unethical andshady meansto install their proxying tools on people's devices secretly.

When secretly installed, victims will have their internet bandwidth hijacked without their knowledge and risk legal trouble due to appearing as the source of malicious activity.

Proxying Android VPN apps

A report published today by HUMAN's Satori threat intelligence team lists 28 applications on Google Play that secretly turned Android devices into proxy servers. Of these 28 applications, 17 were passed off as free VPN software.

Satori analysts report that the offending apps were all using a software development kit (SDK) by LumiApps that contained "Proxylib," a Golang library to perform the proxying.

HUMAN discovered the first PROXYLIB carrier app in May 2023, a free Android VPN app named "Oko VPN." The researchers later found the same library used by the LumiApps Android app monetization service.

"In late May 2023, Satori researchers observed activity on hacker forums and new VPN applications referencing a monetization SDK,lumiapps[.]io," explains theSatori report.

"Upon further investigation, the team determined that this SDK has exactly the same functionality and uses the same server infrastructure as the malicious applications analyzed as part of the investigation into the earlier version of PROXYLIB. "

A subsequent investigation revealed a set of 28 apps that utilized the ProxyLib library to convert Android devices into proxies, which are listed below:

  1. Lite VPN
  2. Anims Keyboard
  3. Blaze Stride
  4. Byte Blade VPN
  5. Android 12 Launcher (by CaptainDroid)
  6. Android 13 Launcher (by CaptainDroid)
  7. Android 14 Launcher (by CaptainDroid)
  8. CaptainDroid Feeds
  9. Free Old Classic Movies (by CaptainDroid)
  10. Phone Comparison (by CaptainDroid)
  11. Fast Fly VPN
  12. Fast Fox VPN
  13. Fast Line VPN
  14. Funny Char Ging Animation
  15. Limo Edges
  16. Oko VPN
  17. Phone App Launcher
  18. Quick Flow VPN
  19. Sample VPN
  20. Secure Thunder
  21. Shine Secure
  22. Speed Surf
  23. Swift Shield VPN
  24. Turbo Track VPN
  25. Turbo Tunnel VPN
  26. Yellow Flash VPN
  27. VPN Ultra
  28. Run VPN

LumiApps is an Android app monetization platform that states its SDK will use a device's IP address to load webpages in the background and send the retrieved data to companies.

"Lumiapps helps companies gather information that is publicly available on the internet. It uses the user's IP address to load several web pages in the background from well-known websites," reads the LumiApps website.

"This is done in a way that never interrupts the user and fully complies with GDPR/CCPA. The web pages are then sent to companies, who use them to improve their databases, offering better products, services, and pricing."

However, it is unclear if the free app developers knew that the SDK was converting their users' devices into proxy servers that could be used for unwanted activities.

HUMAN believes the malicious apps are linked to the Russian residential proxy service provider 'Asocks' after observing connections made to the proxy provider's website. The Asocks service is commonly promoted to cybercriminals on hacking forums.

Free VPN apps on Google Play turned Android phones into proxies (3)

In January 2024, LumiApps released the second major version of its SDK along with Proxylib v2. According to the firm, this addressed "integration issues," and it now supports Java, Kotlin, and Unity projects.

Following HUMAN's report, Google removed any new and remaining apps using the LumiApps SDK from the Play Store in February 2024 and updated Google Play Protect to detect the LumiApp libraries used in the apps.

Free VPN apps on Google Play turned Android phones into proxies (4)

Meanwhile, many apps listed above are now available again on the Google Play store, presumably after their developers removed the offending SDK. They were sometimes published from different developer accounts, potentially indicating previous account bans.

Free VPN apps on Google Play turned Android phones into proxies (5)

BleepingComputer has reached out to Google for a comment on the status of the currently available apps using the same names and whether they are now safe, but we have yet to hear back.

If you have used one of the listed apps, updating to the newest version that does not use the particular SDK will stop the proxying activity. However, out of an abundance of caution, it may be safer to remove them altogether.

If the app was removed from Google Play and no safe version exists, you are recommended to uninstall it. Play Protect should also warn users in that case.

Finally, it is likely safer to use paid VPN apps instead of free services as many products in the latter category are more eager to implement indirect monetization systems, including data collection/selling, advertising, and enrollment in proxy services.

Related Articles:

More Android apps riddled with malware spotted on Google Play

Google tests blocking side-loaded Android apps with risky permissions

Google says spyware vendors behind most zero-days it discovers

Google paid $10 million in bug bounty rewards last year

Google Pay app shutting down in US, users have till June to move funds

Free VPN apps on Google Play turned Android phones into proxies (2024)

FAQs

Free VPN apps on Google Play turned Android phones into proxies? ›

In May 2023, HUMAN's Satori Threat Intelligence team discovered that Oko VPN, a free VPN app offered through the Google Play store, utilized a Golang library that performed proxy node enrollment. Further investigation unearthed connections to 'Asocks,' a shady residential proxy seller, suggesting a monetization scheme.

Is there a 100% free VPN for Android? ›

Proton VPN's free tier is the only truly free VPN we've encountered that's worth using. True, it lacks support for torrenting and doesn't include all the bells and whistles as its paid subscriptions, but Proton VPN's free tier is secure and doesn't put limits on speed, data or usage time like most other free VPNs do.

How to use VPN proxy on Android? ›

  1. Open your device's Settings app.
  2. Tap Network & internet. VPN. If you can't find it, search for "VPN." If you still can't find it, get help from your device manufacturer.
  3. Tap the VPN you want.
  4. Enter your username and password.
  5. Tap Connect. If you use a VPN app, the app opens.

What is the safest VPN for Android? ›

Proton VPN is very privacy-focused with an open-source Android app and an always-on VPN feature for 24/7 security. You can get started with its free plan, and to experience its top-notch unblocking capabilities, try its premium plan on for size with a 30-day money-back guarantee.

How to free VPN for Android? ›

The best free unlimited VPN without a data cap is Proton VPN. However, the speeds are not the fastest, and there are only 3 countries to choose from. For the best free unlimited VPN for Android without device limitation, it's best to choose Surfshark with its free trial and a 30-day money-back guarantee.

Is there a 100 free VPN? ›

Proton VPN — Completely Free VPN Without Data Caps for Unlimited and Safe Browsing. While most free VPNs impose caps, Proton VPN is a 100% free VPN that offers unlimited monthly data.

Which is the best free unlimited VPN for Android without registration? ›

The Best Free VPNs of 2024
  • Surfshark - Best VPN Free Trial.
  • Hotspot Shield - Fastest Free VPN.
  • NordVPN - Best Full-Featured VPN with Free Offers.
  • PrivadoVPN - Best Free VPN for Unlimited Devices.
  • Atlas VPN - Best Free VPN for Privacy.
  • TunnelBear - Best Server Network.
Mar 22, 2024

Does Android have proxy settings? ›

A proxy server is an intermediary between a user and a destination server (the internet). Such an additional inbetweener adds an extra layer of security and anonymity. On Android, you can configure proxies for both mobile and Wi-Fi network connections.

What is the best VPN proxy for Android? ›

Best Free VPN for Android: Quick Recap
  • Atlas VPN – best performance overall.
  • ProtonVPN – the most secure free VPN.
  • Hide.me – best free no-log VPN for Android.
  • TunnelBear – servers in almost 50 countries.
  • Hotspot Shield – applications for all platforms.
  • Windscribe – offers advanced security features.

How do I get a VPN proxy? ›

To set up a proxy server for a VPN connection
  1. Select the Start button, then select Settings > Network & Internet > VPN.
  2. Select the VPN connection, then select Advanced options.
  3. Under VPN proxy settings, select the type of proxy setup you want to use, then enter the proxy server information for that VPN connection.

What is the number 1 free VPN for Android? ›

My VPN industry rankings
VPN serviceRatingReviews
1. NordVPN⭐⭐⭐⭐½Check out our NordVPN review
2. ExpressVPN⭐⭐⭐⭐½Check out our ExpressVPN review
3. Surfshark⭐⭐⭐⭐½Check out our Surfshark review
4. Private Internet Access⭐⭐⭐⭐½Check out our Private Internet Access review
7 more rows
Apr 11, 2024

What is the strongest free VPN app? ›

Forbes Advisor Ratings
CompanyPricingData Limit
ProtonVPNForever freeNo limit
hide.meForever freeNo limit
WindscribeForever free10 GB per month
VPN UnlimitedSeven-day free trialNo limit
4 more rows
Apr 6, 2024

Does Google offer a VPN? ›

If you're a Google One member with a 100 GB, 200 GB, or Premium plan, we include the VPN at no charge. Learn how to check your storage or change your plan. If you're interested in an upgrade to your Google One membership, you can upgrade your plan.

How to setup free VPN on Android without app? ›

Go into your Android settings. Click Network & Internet. Click Advanced. Select VPN.

Which is the unlimited free VPN? ›

Best free internet VPNs compared
Data limitDevice limit
Proton VPNUnlimited10
NordVPNUnlimited10
SurfsharkUnlimitedUnlimited
Norton VPNUnlimited10
1 more row
Mar 20, 2024

Is there a free unlimited VPN? ›

Proton VPN and hide.me are both 100% free VPNs because they offer free unlimited data. They restrict access to a few other features, but you can use the VPN as much as needed without worrying about running out of data.

Which VPN app is free for Android? ›

Hotspot Shield Basic is a popular free VPN plan with a very major plus: last year, the provider began upgrading the service to offer unlimited data across all platforms. Mac, Android, and iOS now support unlimited data, with Windows joining the party later.

Is there a VPN I can try for free? ›

NordVPN has a 7-day free trial on Android. You can try the app on your Android device free of charge for a week, then decide if you want to buy a subscription. Alternatively, you can try NordVPN risk free for a month, thanks to our 30-day money-back guarantee.

Top Articles
Latest Posts
Article information

Author: The Hon. Margery Christiansen

Last Updated:

Views: 5533

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: The Hon. Margery Christiansen

Birthday: 2000-07-07

Address: 5050 Breitenberg Knoll, New Robert, MI 45409

Phone: +2556892639372

Job: Investor Mining Engineer

Hobby: Sketching, Cosplaying, Glassblowing, Genealogy, Crocheting, Archery, Skateboarding

Introduction: My name is The Hon. Margery Christiansen, I am a bright, adorable, precious, inexpensive, gorgeous, comfortable, happy person who loves writing and wants to share my knowledge and understanding with you.