logo

BadBox Malware Compromises 30,000 Devices in Germany

ID: 31f6eb97-8a34-5a40-9e5a-4430dd7b8edf

STIX ID: report--31f6eb97-8a34-5a40-9e5a-4430dd7b8edf

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2024-12-14

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

The BSI disrupted the BadBox malware campaign after discovery of firmware-embedded malware pre-installed on Android IoT devices (digital photo frames, media players and possibly smartphones) affecting ~30,000 devices in Germany; BadBox maintains C2 connectivity to steal 2FA credentials, create fraudulent accounts, perform advertising fraud and provide residential proxying, and the BSI sinkholed infrastructure and instructed ISPs to notify owners to disconnect or discard compromised hardware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.