Your streaming stick has one job: make it easier to watch TV. But if that device has been compromised, it could be doing something very different in the background by helping a cybercriminal hide.
In March 2026, the FBI warned that compromised internet-connected devices, including TV streaming devices, can become part of residential proxy networks. These networks allow threat actors to route their internet traffic through someone else's home internet connection, making it appear as though the activity is coming from an ordinary residential user.
You could be watching a movie while your internet connection is being used to conduct illegal activity you know nothing about, and you may never notice.
A residential proxy is essentially a middleman between an internet user and the websites or online services they access. Instead of connecting directly to a website, traffic is routed through another internet-connected device. To the website, the request appears to come from the device's IP address rather than the person actually making the request.
That's not inherently malicious; residential proxies can have legitimate uses. However, the problem starts when criminals gain access to residential IP addresses without the owner's knowledge.
According to the FBI, threat actors can compromise IoT devices, including TV streaming devices, and use them to route their traffic. Once compromised, the device's IP address can help conceal the attacker's identity and location. In other words, your streaming stick can become the cover for someone else's activity.
A residential IP address looks like a normal person's internet connection. That can make malicious activity harder to trace and, in some cases, less likely to trigger security controls designed to identify suspicious traffic.
Residential proxies can be used for a wide range of criminal activity, including:
For example, if criminals obtain stolen banking credentials, they could use a residential proxy in the victim's city to make a login attempt appear less suspicious.
Your device doesn't have to contain your banking information to become part of the problem.
This is where streaming devices become particularly interesting: Compromised IoT devices, including TV streaming devices, as a means that criminals use to obtain residential IP addresses. Threat actors can infect devices with malware or install a backdoor that allows them to control the device, and there are several ways this can happen.
Some devices may already contain malicious software before they reach the consumer.
Certain internet-connected devices can come from the factory with malware installed, and in some cases, that malware can remain even after a factory reset. Unfortunately, these infections can be difficult to spot. Unusual network activity, slower performance, unexpected pop-ups, or unfamiliar apps and settings can be potential warning signs, but some malware may run quietly in the background. That makes it especially important to consider where you buy a device and what signs to watch for after setting it up.
A cheap streaming stick advertised online as providing unlimited access to premium movies, television, or sports may not be the bargain it appears to be.
A legitimate streaming device can also become compromised through the software installed on it. Unofficial app stores and sideloaded applications can introduce malicious software, particularly when users download applications from unknown sources.
The FBI specifically warns that sideloading unofficial applications onto devices such as streaming sticks and Android TV boxes increases the chances of installing malware or backdoors.
Free movies, sports, software, and other pirated content can also be used to distribute malware. Malicious software associated with free or pirated content can turn an unsuspecting device into part of a residential proxy network.
The FTC has previously warned that illegal streaming applications can contain malware that may expose sensitive information, monitor activity, steal credentials, or potentially spread to other devices connected to the same network.
The issue isn't simply that someone downloaded an unauthorized streaming app. The software running behind the stream could be collecting information, communicating with an attacker, or using the device's internet connection for malicious activity without the user's knowledge.
One of the most concerning aspects of a compromised streaming device is how little may change from the user's perspective. The TV still turns on, the streaming apps still work, and the remote still works. There may be no obvious pop-up announcing that your device has been compromised.
Meanwhile, someone else could be routing traffic through your internet connection.
That's what makes residential proxy networks particularly concerning, the device owner may not realize their IP address is being used at all. It’s worth noting that individuals can unknowingly become part of these networks when criminals compromise their IoT devices.
The streaming stick doesn't have to look broken; it just has to be connected.
A compromised streaming stick is also part of a larger environment: your home or business network.
That network may include laptops, phones, smart speakers, security cameras, printers, gaming consoles, and other connected devices. The risk can extend into the workplace, too. Employees may connect work devices from home, and businesses may have streaming devices or other IoT devices connected to their office networks. If one of those devices is compromised, it could create another potential pathway into the broader business environment.
A compromised IoT device doesn't automatically mean every device on the network has been compromised. But it does illustrate why connected devices should not be treated as harmless just because they aren't computers in the traditional sense.
The FTC has warned that malware associated with illegal streaming applications can potentially spread to other devices on the same network. That’s why an inexpensive streaming device can create a cybersecurity concern that extends beyond the television.
The good news is that avoiding the most common risks doesn't require turning your living room into a security operations center.
To avoid risks, you can take several basic precautions:
The FBI also recommends that businesses use network segmentation, enforce policies on unauthorized devices, and implement firewall rules to prevent unauthorized applications and services from communicating across the network.
Cybersecurity isn't limited to the devices we think of as computers; anything connected to a network can become part of your personal attack surface, including the small device sitting behind your television at home or in the office.
A streaming stick may seem insignificant. But when compromised, it can provide a threat actor with something valuable: a legitimate residential IP address that helps hide where their activity is actually coming from.
Unusual activity from any device can be a clue that something else is happening inside your environment. The challenge is knowing what normal looks like, recognizing when something deviates from it, and having someone investigate when it does.
RADICL helps organizations do exactly that. Through 24/7 managed detection and response and our Virtual Security Operations Center (vSOC), our team continuously monitors environments for suspicious activity, investigates potential threats, and helps organizations respond when something doesn't add up. Because a device doesn't have to look compromised to be part of an attack.
Want to better understand what’s happening in your environment? Let’s talk.