logo

German agency BSI sinkholed a botnet of 30,000 devices infected with BadBox

ID: c014ada3-acbb-5485-9229-7ce5a084fdbd

STIX ID: report--c014ada3-acbb-5485-9229-7ce5a084fdbd

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2024-12-13

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

The German Federal Office for Information Security (BSI) sinkholed a botnet of about 30,000 Germany-based devices that were shipped with BadBox backdoored firmware on outdated Android; BadBox performs ad fraud, acts as a residential proxy for criminal activity, can create accounts to spread disinformation and download additional payloads. BSI coordinated with ISPs to block C2 communications and notify potentially infected consumers, attributing the issue to pre-installed, supply-chain compromised firmware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.