BadBox Malware Compromises 30,000 Devices in Germany
ID: 31f6eb97-8a34-5a40-9e5a-4430dd7b8edf
STIX ID: report--31f6eb97-8a34-5a40-9e5a-4430dd7b8edf
Feed Name: SOCRadar Blog
The BSI disrupted the BadBox malware campaign after discovery of firmware-embedded malware pre-installed on Android IoT devices (digital photo frames, media players and possibly smartphones) affecting ~30,000 devices in Germany; BadBox maintains C2 connectivity to steal 2FA credentials, create fraudulent accounts, perform advertising fraud and provide residential proxying, and the BSI sinkholed infrastructure and instructed ISPs to notify owners to disconnect or discard compromised hardware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
