BADBOX Botnet Hacked 74,000 Android Devices With Customizable Remote Codes
ID: 3249dc26-f882-5aa4-844e-1109c75e1692
STIX ID: report--3249dc26-f882-5aa4-844e-1109c75e1692
Feed Name: cybersecurityNews.com
BADBOX is a firmware-level Android backdoor/botnet preinstalled on consumer devices via supply-chain or manufacturing compromise and observed on roughly 192,000 devices worldwide; on boot infected devices immediately contact C2 servers enabling residential proxying, remote code installation, interception of 2FA, account abuse and ad fraud, and are difficult to remediate because the malware resides on non-writable firmware partitions, prompting warnings from authorities and calls for improved supply-chain and firmware security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
