Bandwidth Supply

What is Proxyware?

Proxyware is software that turns a device into an exit point for a proxy network, relaying other people's traffic through that device's internet connection. The term comes from security research, where it covers legitimate bandwidth-sharing clients the owner chose to install and the same clients planted on machines without the owner's knowledge.

Security researchers use the word descriptively. Cisco Talos (Edmund Brumaghin and Vitor Ventura, 31 August 2021) wrote that "Proxyware platforms enable users to sell the use of their unused internet bandwidth, typically by running a client application". Trend Micro (7 February 2023) went further and called these network-sharing apps "riskware applications that we call proxyware". Neither treats a legitimately installed client as malware. The label says what the software does: it makes your connection somebody else's exit.

The trouble starts with how the software reaches a device. Talos documented three patterns: silent installation of a platform client to sell the victim's bandwidth, trojanized installers that add a legitimate client alongside cryptocurrency miners, and modified clients with hardcoded credentials that enrol the victim under the attacker's account. AhnLab ASEC reported on 17 September 2026 that a group it tracks as Larva-25012 was installing proxyware without the user's consent on Windows systems it had already infected, through a loader registered in Task Scheduler that ran PowerShell commands to install the proxyware clients. On mobile, Google's Threat Intelligence Group reported on 29 January 2026 that many apps carrying one network's SDKs "did not disclose that they enrolled devices" into it.

Installed with consent, proxyware still carries risk for the owner and for other users. Talos noted that it "may be possible to monitor the DNS activity of other platform users" and that unencrypted HTTP content "could be intercepted and manipulated in transit" by nodes. Trend Micro's concern was the reverse direction: the owner's IP is associated with whatever the network's customers do. Both point to the same checks before installing anything: who publishes the client, what it declares, whether it runs visibly, and how to remove it completely.

PROXIES.SX operates a bandwidth-sharing network, so its own clients are proxyware in this sense. They run visibly: the headless Linux build is a systemd service named proxies-peer that keeps its key in /etc/proxies-peer/peer.env with mode 0600 and runs unprivileged, and the Android SDK runs as a foreground service with a persistent notification. Stopping is always possible: on Linux, sudo systemctl disable --now proxies-peer stops the service and keeps it from starting again. A device reporting online again is restored automatically, so stop the software before deleting the device from the account.

Where you meet it

You meet the word proxyware in antivirus detections, in security write-ups about compromised servers and infected PCs, and in the fine print of apps that pay for bandwidth. If a detection names a client you did not install, treat it as a sign the machine was compromised, not as a nuisance to dismiss, because the installer may have brought other payloads with it.

Common questions

Is proxyware malware?

Not by itself. Talos and Trend Micro separate the legitimate client an owner chooses to run from the malware that installs it silently, though Trend Micro classes the apps as riskware. What makes an installation malicious is how it got there: without the owner's knowledge, or registered to an attacker's account.

How do I know if proxyware is running on my computer?

Check installed programs, services, scheduled tasks and startup items for anything you do not recognise, then look for a process holding a long-lived outbound connection and steady upload traffic you cannot explain. Security suites often flag these clients as potentially unwanted software. On Android, look for an unfamiliar persistent foreground-service notification.

How do I remove proxyware I did not install?

Remove the client, its service or scheduled task and any container that runs it, then find out how it arrived, because Talos and ASEC both describe it being delivered alongside other malware. Change credentials on the machine, and tell the vendor which account it was enrolled under so the account can be shut down.

Related terms

Proxyjacking
Proxyjacking is installing proxyware on a machine you have broken into, so that its bandwidth and IP address can be sold through a proxy network for the attacker's benefit. Sysdig's Threat Research Team defined the term in April 2023, comparing it to cryptojacking: the attacker profits from stolen network access instead of stolen processor time.
Bandwidth Sharing
Bandwidth sharing means letting a proxy network route other people's internet traffic through your connection, usually by running a small client on a phone, computer or server, in exchange for payment for the traffic carried. To the destination site, that traffic appears to come from your IP address, which is what the network actually sells.
Exit Node
An exit node is the device whose IP address a proxied request finally leaves from, so the destination site sees and logs that device's address instead of the customer's. In residential and mobile proxy networks the exit is usually a phone, computer or router running bandwidth-sharing software; in Tor the same term names a circuit's last relay.
Bandwidth-Sharing SDK
A bandwidth-sharing SDK is a library an app developer embeds so the app can relay proxy traffic through its users' connections, with the developer paid for the traffic carried. Google Play allows proxy services for third parties only in apps where that is the primary, user-facing core purpose, and holds developers responsible for the SDKs they ship.
Peer Relay
A peer relay is the server that bandwidth-sharing devices connect out to, and through which customer traffic is handed down to those devices. Because each device dials the relay and keeps the connection open, it needs no public address and no open port, which is how phones and home lines behind NAT or CGNAT can act as proxy exits.
Informed Consent
Informed consent, in bandwidth sharing, means the device owner understands that their connection will carry other people's internet traffic, what that involves and how to stop, and agrees before any traffic flows. It separates a bandwidth-sharing app a person chose to run from proxyware placed on their device without their knowledge.
USDC on Solana
USDC on Solana is Circle's dollar stablecoin issued as a token on the Solana blockchain, identified by the mint address EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v. A Solana wallet can hold it alongside native SOL, but they are different assets, so a payout setting has to name the currency and the network.

Real 4G/5G mobile and residential IPs

PROXIES.SX runs carrier IPs in 100+ countries with HTTP and SOCKS5 on every endpoint. $4/GB down to $2.40/GB at volume, free endpoints and rotation, and your GB never expire.