logo

Who Operates the Badbox 2.0 Botnet?

ID: 4396e4dd-cfa1-535c-b56b-ab720414e675

STIX ID: report--4396e4dd-cfa1-535c-b56b-ab720414e675

Feed Name: Krebs on Security

Threat Score
78/100

Date Published: 2026-01-26

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

The report describes how Kimwolf botnet operators purportedly gained unauthorized access to the Badbox 2.0 control panel, potentially allowing them to push Kimwolf malware directly onto millions of compromised Android TV boxes. The article presents OSINT linking qq.com email addresses, domains and individual names to Badbox infrastructure, outlines Badbox’s history of pre‑installed/backdoored devices and advertising-fraud activity, and explains how insecure IoT devices and residential proxy abuse enable the large-scale spread of these botnets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.