Approximately 20 million smart home devices in the United States may be infected with hidden malware, according to a Wall Street Journal report. This malware, often referred to as residential proxy software, creates a secret "backdoor" that enables hackers to hijack a device's internet connection. This allows them to route their own internet traffic through the unsuspecting owner's home network, making it appear as if their illegal activities originated from that home. These activities can include launching cyberattacks, sending spam, creating fake online accounts, and masking their true location for various crimes.
The infected devices typically continue to function normally, so owners are often unaware that their internet is being misused. This problem is particularly prevalent in cheaper or off-brand internet-connected gadgets. One reporter, as part of an investigation mentioned in the WSJ report, purchased two digital photo frames from Amazon and three "super boxes" from Walmart for less than $800. Upon connecting these devices, he observed them immediately linking to residential proxy servers and generating suspicious traffic, including visits to gambling, pornography, and cryptocurrency websites.
The residential proxy software essentially rents out the owner's internet connection to third parties without their consent. Law enforcement faces challenges in these cases because the IP address of an innocent device owner often takes the blame for criminal activity. In controlled tests, some of these devices were found to be actively participating in denial-of-service (DDoS) attacks and attempting to breach hardware controls. The scale of the issue is significant, with estimates suggesting tens to hundreds of millions of such infected devices globally, which can be pooled to form vast, untraceable networks for fraud and even state-sponsored operations.