logo

Android botnet BadBox largely disrupted

ID: 26578a13-4f46-5526-aac2-ff82ac563e72

STIX ID: report--26578a13-4f46-5526-aac2-ff82ac563e72

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2025-03-06

Date Updated: 2026-04-28

...
...

Researchers and Germany’s BSI disrupted the BadBox botnet — malware preinstalled on lower-cost Android Open Source Project devices (TV boxes, tablets, projectors) that forms a proxy network used for DDoS, ad fraud, and stealing 2FA codes; sinkholing and removal of malicious apps reduced activity, but estimates suggest up to ~1 million devices may be affected and supply-chain firmware backdoors mean the threat may resurface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.