But even then, shouldn't this show the same permission prompt for the user that anything else trying to connect to port 5555 would?
Not the least because most of our industry relies on it to make money. Marketing and advertising themselves are institutionalized forms of "do this thing that's actually harmful to you to get free coins / be safe / get laid".
I mean, this seems more like one of the root causes for a lot of bad things in the industry me...
- the app embedding the proxyware SDK for money
- the proxy operators
- the attackers/botnets using the proxy to access ADB.
The botnet has no access to the app, so it can't show any messages.
The app can show messages, but probably has no connection to the botnet. (I hope)
The proxy operators could show a message by abusing the SDK even more, but that would mean they actively colluded with the botnet. Is that likely? Then they could just give the botnet direct access to the app, no need to do the whole proxy thing.
It's one more revenue stream to be able to remote control real android phones to pass device attestation checks etc.
It's marketed to users with phrases like "earn money from your phone whilst you sleep".