Plume Identifies Security Flaws in SuperBox Android Streaming Devices
Plume Design, Inc. has uncovered significant security vulnerabilities in SuperBox Android streaming devices, which are sold at major U.S. retailers. These devices contain dormant software that, when activated, turns home internet connections into nodes in a residential proxy network. This proxy network routes potentially malicious third-party traffic, including stolen credentials and security bypass operations, through unsuspecting subscriber homes. Plume's investigation revealed that the SuperBox's custom app store bypasses standard Android safety checks, allowing software installation without user consent. The findings highlight the risks associated with unverified third-party applications and the potential for widespread security breaches.