logo

The Badbox botnet is back, powered by up to a million backdoored Androids

ID: fac10347-1278-5da8-91c7-b2b41881a790

STIX ID: report--fac10347-1278-5da8-91c7-b2b41881a790

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-03-07

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Human Security's Satori team has identified Badbox 2.0, a remote-controllable Android/AOSP malware variant infecting cheap, China-made devices (phones, TV boxes, tablets, projectors) and hundreds of third-party Android apps to build a botnet that conducted large-scale ad fraud, ad-click fraud, and credential theft; the botnet peaked at nearly one million devices but has been partially disrupted by coordination between Human Security, Google, Trend Micro, and Shadowserver.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.