The Norwegian cybersecurity company Mnemonic identified Samsung smart TV applications that were establishing connections with residential proxy networks. This functionality allows the IP address of third parties to be hidden during illicit activities.
Samsung announced that it will prohibit the discovered applications and identify all those incorporating residential proxy components. The practice of residential proxy involves disguising a third party's IP using a common connection, which can even be used to cover up cybercrimes.
The issue was recently detected by Mnemonic, involving simple games intended for the brand's smart TVs. In communication with TechCrunch, Samsung informed about existing restrictions for new application registrations and for the use of development kits aimed at residential proxies.
Last month, this same technique was found in applications for LG TVs, which also initiated actions to solve the problem. Additionally, it was pointed out that illegal TV boxes may be contaminated with this type of malware.
What is the problem with the TV apps?
According to Mnemonic, several Samsung smart TV applications contained code that used the user's internet without their consent or knowledge. One example cited was the game Pac-Man, which appeared in the manufacturer's app store editorial recommendations.
The cybersecurity firm clarified that the game in question had codes from Bright Data, a company specializing in creating and managing proxy networks. Bright Data claims access to millions of global residential connections.
This implies that an application with residential proxy code can allow unknown people to access the user's home internet without the user knowing. In this way, these individuals can operate on the network simulating a common domestic IP address.
This methodology can be employed for various purposes, such as web data scraping and information gathering, geolocation-related research, attacks to test compromised passwords, and even to ensure anonymity in cyberattacks.
The user affected by malicious software can face everything from minor inconveniences, such as increased internet usage or a higher incidence of captchas, to more serious situations, such as being linked to illicit acts through their IP address.
What will Samsung do?
In response to TechCrunch, Samsung declared that it is in the process of identifying and removing all store applications that present these components. Furthermore, the brand mentioned that it has already implemented certain measures, such as blocking the registration of new applications that include proxy functionalities and establishing policies for developers that prohibit residential proxy development kits across the entire platform.
Competitor suffers from the same issue
The risk of residential proxy extends to other platforms. An analysis conducted in July 2025 revealed that 42% of applications available in the LG store had the ability to connect the smart TV to a proxy network. LG announced that it would ban all applications introducing such a feature.
However, solving the problem may be complex. As explained by Harrison Sand, a Mnemonic consultant, many applications have few lines of programming. To operate, they load their content from other websites. App store reviews usually consider only the app's code, ignoring additional downloads. Moreover, the loaded part can vary between the security review and the download made by the user themselves, and this type of trick might be precisely at that point.


