Following revelations earlier this year, LG and Samsung vow to ban Smart TV apps containing 'resproxies' that can turn your TV and home network into a node in potentially malicious botnets.
In April 2026, Lowpass brought to light how numerous apps and games available for Amazon's Fire TV, Roku, LG's webOS and Samsung's Tizen had secretly been using users' Smart TVs to crawl the web for AI training and more malicious purposes.
In effect, hundreds of millions of Smart TVs – and household internet connections – serve as huge proxy botnets that can be directed to do almost anything their operators want, even when the apps are not open on the TV. There have been examples of these botnets being rented by hacking groups in China, North Korea, Iran and Russia.
One of the malware-infected apps is a Pac-Man game appealing to children, according to cybersecurity researcher Harrison Sand at Mnemonic, who added that Samsung featured it as an Editor's Choice on its Smart TVs,
Resproxies in 42% of all webOS apps
Amazon Fire TV, Roku and Google TV no longer allow the original malware botnet, IPIDEA, in apps, and have also restricted a more recent resproxy botnet from Bright Data, which nevertheless continued to list LG and Samsung as partners.
Apparently, more than 42.5% of apps and games available for LG's webOS contained code to allow botnets to route internet traffic through LG Smart TVs in homes around the world, while 26.5% of apps available for Samsung's Tizen Smart TVs allowed it, according to research by security firm Spur.
LG & Samsung finally vow to take action
Following the outrage over the published studies, LG said in late July that it was working to get developers to remove resproxies from their apps.
- "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," John Taylor, SVP at LG, told KrebsOnSecurity. "If this option is not removed, these apps will be suspended."
In early August, Samsung followed suit and issued this statement to TechCrunch:
- "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform. We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components."
The question becomes: why did they allow this to continue for so long? Meanwhile, LG is facing a series of allegations about its Smart TVs spying on and extensively tracking users.
- Source: KrebsOnSecurity, TechCrunch, Mnemonic