State-sponsored cyberattackers have found a quiet new way to disguise themselves: the inexpensive smart gadgets sitting in ordinary people's homes.

According to a report by Robert McMillan in the Wall Street Journal, nation-state hackers are increasingly exploiting software that comes preinstalled on low-cost home devices. They use it to build what are known as residential proxy networks — and then route their attack traffic through those networks to hide where it really comes from.

The trick works because of how internet traffic is judged. Connections coming from a normal home internet address tend to look trustworthy and routine. Traffic coming from a known data center or a flagged server, by contrast, is more likely to be blocked or scrutinized. By bouncing their activity through everyday household devices, the Wall Street Journal reports, attackers can make malicious traffic blend in with the ordinary online behavior of real residential users.

The Wall Street Journal frames this as a growing tactic among nation-state attackers, who are turning to residential proxy networks specifically to mask their traffic and frustrate efforts to trace it back to them.

For the owners of these gadgets, the unsettling part is that the capability is described as already built in — riding on software that ships with the devices rather than something a user knowingly installs. That makes the abuse hard to notice and hard to stop from the consumer's side.

Why it matters: when state-backed hackers can borrow the trusted reputation of millions of ordinary home devices, the usual defenses that rely on spotting suspicious internet addresses become far less reliable — turning everyday consumer electronics into unwitting cover for serious cyberattacks.