Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Researchers find alarming overlaps among 18 popular VPNs

Tech Wavo by Tech Wavo
September 4, 2025
in Computers
0


A new alleges that 18 of the 100 most-downloaded virtual private network (VPN) apps on the Google Play Store are secretly connected in three large families, despite claiming to be independent providers. The paper doesn’t indict any of our picks for the , but the services it investigates are popular, with 700 million collective downloads on Android alone.

The study, published in the journal of the Privacy Enhancing Technologies Symposium (PETS), doesn’t just find that the VPNs in question failed to disclose behind-the-scenes relationships, but also that their shared infrastructures contain serious security flaws. Well-known services like Turbo VPN, VPN Proxy Master and X-VPN were found to be vulnerable to attacks capable of exposing a user’s browsing activity and injecting corrupted data.

Titled “Hidden Links: Analyzing Secret Families of VPN apps,” the paper was inspired by , which found that several VPN companies each were selling multiple apps without identifying the connections between them. This spurred the “Hidden Links” researchers to ask whether the relationships between secretly co-owned VPNs could be documented systematically.

Starting from the list of the most-downloaded VPNs on Android, the researchers compiled data from each VPN’s business paperwork, web presence and codebase and sifted through it for connections. Primarily through identifying suspicious similarities in the code, they were able to sort 18 VPN apps into three groups.

Family A consists of Turbo VPN, Turbo VPN Lite, VPN Monster, VPN Proxy Master, VPN Proxy Master Lite, Snap VPN, Robot VPN and SuperNet VPN. These were found to be shared between three providers — Innovative Connecting, Lemon Clove and Autumn Breeze. All three , a firm based in mainland China and identified as a “Chinese military company” .

Family B consists of Global VPN, XY VPN, Super Z VPN, Touch VPN, VPN ProMaster, 3X VPN, VPN Inf and Melon VPN. These eight services, which are shared between five providers, all use the same IP addresses from the same hosting company.

Family C consists of X-VPN and Fast Potato VPN. Although these two apps each come from a different provider, the researchers found that both used very similar code and included the same custom VPN protocol.

If you’re a VPN user, this study should concern you for two reasons. The first problem is that companies entrusted with your private activities and personal data are not being honest about where they’re based, who owns them or who they might be sharing your sensitive information with. Even if their apps were all perfect, this would be a severe breach of trust.

But their apps are far from perfect, which is the second problem. All 18 VPNs across all three families use the Shadowsocks protocol with a hard-coded password, which makes them susceptible to takeover from both the server side (which can be used for malware attacks) and the client side (which can be used to eavesdrop on web activity).

Ultimately, a VPN provider being dishonest about its background and a VPN client running on slapdash infrastructure are symptoms of the same problem: these are apps designed to do something other than keep you safe online. Since all 18 were listed as unrelated products, it’s also clear that app stores are not an effective line of defense. The “Hidden Links” paper makes it all the more imperative to without vetting it first, and to only use free VPNs that are supported by paid subscriptions, like Proton VPN.

Previous Post

Should AI Get Legal Rights?

Next Post

Older coders prove unstoppable as a new study shows AI vibe coding delivers bigger dopamine hits than old-school programming ever did

Next Post
A shocking amount of companies are knowingly shipping insecure code – and it might be hard to recover

Older coders prove unstoppable as a new study shows AI vibe coding delivers bigger dopamine hits than old-school programming ever did

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

DOCU Stock Pops After Strong Q2 Results and Platform Uptake

by Tech Wavo
September 6, 2025
0
DOCU Stock Pops After Strong Q2 Results and Platform Uptake
Financial

Docusign Today$79.86 +3.62 (+4.75%) As of 09/5/2025 04:00 PM Eastern52-Week Range$54.31▼$107.86P/E Ratio60.05Price Target$93.14 Heading into its second-quarter earnings report for its 2026...

Read more

Slumber Deep Zzzs Line – CBD CBN THC Gummies & Tinctures For Sleep

by Tech Wavo
September 6, 2025
0
Slumber Deep Zzzs Line – CBD CBN THC Gummies & Tinctures For Sleep
Gadgets

Getting a good night’s rest can be a challenge, especially if you’re stressed, feeling restless, or have something in your...

Read more

NYT Strands hints and answers for Saturday, September 6 (game #552)

by Tech Wavo
September 6, 2025
0
NYT Strands hints and answers for Monday, August 11 (game #526)
Computers

Looking for a different day?A new NYT Strands puzzle appears at midnight each day for your time zone – which...

Read more

Quordle hints and answers for Saturday, September 6 (game #1321)

by Tech Wavo
September 6, 2025
0
Quordle hints and answers for Monday, August 11 (game #1295)
Computers

Looking for a different day?A new Quordle puzzle appears at midnight each day for your time zone – which means...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock