What a Botnet or Proxy Network Does to a Parent's Home

The scariest words in this story are also the vaguest: botnet, proxy, remote access. This page takes them apart. The point is not to frighten anyone. It is to explain, in ordinary language, what a compromised box actually does with a home internet connection and why the fix is to take it off the network.

Last reviewed: October 2026 Reading time: 8 minutes

One sentence: a residential proxy rents a home internet address to strangers so their activity looks like the family's, and a compromised TV box is one of the ways they get one.

What a proxy actually is

A proxy is a relay. Instead of a computer connecting directly to a website, it connects through a middle machine, and the website sees the middle machine's address instead. A residential proxy uses a real home internet connection as that middle machine. The traffic then looks like it came from an ordinary household, which is exactly why criminals want it: it is hard to block and hard to trace.

The FBI has published a warning about this, describing residential proxies as a way to route criminal traffic through legitimate consumer connections. It lists typical uses as credential stuffing (trying stolen logins at scale), account takeover, ad fraud, and dodging fraud controls that rely on internet addresses.

What a botnet is

A botnet is a network of many compromised devices all taking orders from the same controller. Individual devices are small; a million of them are not. When the internet of cheap TV boxes turned out to be easy to infect, it became a favorite target. Researchers have described a botnet of over a million infected TV boxes, and a separate one of about 1.8 million Android devices used to knock websites offline.

Why TV boxes are a favorite target

  • They sit behind the home router, so they inherit the home's trusted position.
  • They are often uncertified Android devices with protections stripped out, so they are easy to control remotely.
  • They run for hours and are rarely watched, so quiet activity goes unnoticed.
  • They are cheap, so one operator can buy them in bulk.

What this does to a household

  • The internet address gets a bad reputation. When a home IP is used for fraud, some sites and services start blocking or challenging it, which the family notices as mysterious logins, blocks, or worse service.
  • A rooted box is a foothold. If one device on the network has been taken over, it can scan and reach other devices: phones, laptops, cameras, even smart locks. That is a network problem, not just a TV problem.
  • Firmware malware can survive a reset. If the malicious code lives in the device firmware, restoring the device restores the tampering.

What is not documented for these specific boxes is a direct theft of a parent's saved passwords or card numbers. That is suspected, not confirmed. The honest picture is serious enough without inventing the scarier version: the home connection is being used, and the network has an open door in it.

Where this came from

The research points to a long-running family of Android malware first documented by Kaspersky in 2016, called Triada, which later branches include the BadBox device botnets and a firmware backdoor called Keenadu. Some of the proxy services involved trace back to networks the US Treasury has sanctioned. This is a mature criminal business, not a one-off bug.

What to do about it

You do not need to become a network engineer. For a documented risky box, the sequence is: take it off the network, and if you are unsure what it reached, change the home Wi-Fi password and reconnect trusted devices. The check-and-fix guide walks through it, and the SuperBox and vSeeBox explainer covers the specific devices.

Sources we checked

Found an error? Report it: we log and correct material mistakes.