logo

Germany blocks BadBox malware loaded on 30,000 Android devices

ID: 50ccbc54-9df6-5804-9ede-fff230571c6f

STIX ID: report--50ccbc54-9df6-5804-9ede-fff230571c6f

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-12-13

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Germany's Federal Office for Information Security (BSI) disrupted the BadBox Android malware, found pre-installed in over 30,000 Android IoT devices (digital photo frames, media players/streamers and potentially other Android devices). BadBox can steal data including two-factor authentication codes, deploy additional malware, create accounts to spread disinformation, perform ad fraud, and operate as a residential proxy; BSI sinkholed the malware's C2 servers to block communications and is coordinating ISP notifications while advising affected users to disconnect or discard compromised devices due to outdated firmware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.