logo

Bigpanzi botnet infects 170,000 Android TV boxes with malware

ID: ce0089e0-ceef-5120-8717-fa3605c1d0d1

STIX ID: report--ce0089e0-ceef-5120-8717-fa3605c1d0d1

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Bigpanzi** is a long-running cybercrime syndicate that has infected Android TV and eCos set-top boxes since at least 2015 using backdoored firmware and malicious apps; researchers observed custom malware (pandoraspear and pcdn) that establishes C2, hijacks DNS, supports reverse shells and DDoS, and builds a P2P CDN, with an estimated peak of ~170,000 daily active bots and 1.3 million unique IPs observed globally (notably Brazil).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.