logo

Unpacking the BADBOX Botnet with Censys

ID: c0d82c28-b0c3-5d7b-8083-74c8151c8327

STIX ID: report--c0d82c28-b0c3-5d7b-8083-74c8151c8327

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2025-02-04

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; Aidan Holland; Senior Security Researcher

...
...

Executive Summary: BADBOX is a recently identified botnet infecting primarily Android devices — often appearing pre-installed in firmware or introduced through the supply chain — with over 190,000 compromised devices observed, including higher-end smart TVs. Analysis using Censys identified a single suspicious self-signed certificate (issuer DN and SHA-256 fingerprint) and a reused SSH host key presented across multiple Singapore-based IPs and numerous domains, indicating templated instances controlled by a common actor; the report includes IPs, domains, certificate and SSH fingerprints as IOCs for tracking and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.