← Back to context

Comment by xg15

11 hours ago

Told by whom though? If it's through proxyware, then there are three parties who mostly don't know each other:

- the app embedding the proxyware SDK for money

- the proxy operators

- the attackers/botnets using the proxy to access ADB.

The botnet has no access to the app, so it can't show any messages.

The app can show messages, but probably has no connection to the botnet. (I hope)

The proxy operators could show a message by abusing the SDK even more, but that would mean they actively colluded with the botnet. Is that likely? Then they could just give the botnet direct access to the app, no need to do the whole proxy thing.

It isn't being done behind-the-back of proxy operators.

It's one more revenue stream to be able to remote control real android phones to pass device attestation checks etc.

It's marketed to users with phrases like "earn money from your phone whilst you sleep".

  • And it's entirely Cloudflare's and Google's fault. When you say you need to have X to do Y, people are going to find ways to get X.