BadBox malware botnet infects 192,000 Android devices despite disruption
ID: d36324cd-cff7-51f9-948e-c117221a63cd
STIX ID: report--d36324cd-cff7-51f9-948e-c117221a63cd
Feed Name: Bleeping Computer
The report details the active BadBox Android botnet (likely Triada-derived) that has infected around 192,000 devices — including mainstream Yandex 4K Smart TVs and Hisense phones — and is used to run residential proxies and ad fraud; BitSight and Germany's BSI sinkholing/telemetry revealed large-scale, geographically distributed infections and provide indicators of compromise (overheating, high CPU/network usage, changed settings) and mitigation advice such as applying firmware updates or disconnecting vulnerable devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
