logo

BadBox malware botnet infects 192,000 Android devices despite disruption

ID: d36324cd-cff7-51f9-948e-c117221a63cd

STIX ID: report--d36324cd-cff7-51f9-948e-c117221a63cd

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-19

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

The report details the active BadBox Android botnet (likely Triada-derived) that has infected around 192,000 devices — including mainstream Yandex 4K Smart TVs and Hisense phones — and is used to run residential proxies and ad fraud; BitSight and Germany's BSI sinkholing/telemetry revealed large-scale, geographically distributed infections and provide indicators of compromise (overheating, high CPU/network usage, changed settings) and mitigation advice such as applying firmware updates or disconnecting vulnerable devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.