logo

Germany cuts hacker access to 30,000 devices infected with BadBox malware

ID: 809c91c5-2890-5b07-b3a1-d4bf35db8e87

STIX ID: report--809c91c5-2890-5b07-b3a1-d4bf35db8e87

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2024-12-13

Date Updated: 2026-05-01

...
...

Germany's Federal Office for Information Security (BSI) discovered at least 30,000 internet-connected devices sold in the country preinstalled with BadBox/Triada malware; the agency sinkholed C2 traffic and ordered large ISPs to redirect infected-device traffic, advising users to disconnect affected devices while warning that outdated firmware still poses a risk. The malware—linked to actors likely operating from China and previously found on tens of thousands of low-cost Android devices—provides a persistent backdoor used for account creation, proxying, advertising fraud and distribution of illicit content.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.