Millions of Low-Cost Android Devices Turn Home Networks Into Crime Platforms
- The original BADBOX malware targeting cheap Android devices was detected in 2023 and evolved into the BADBOX 2.0 botnet by early 2025.
- German authorities disrupted the BADBOX botnet in December 2024, but the malware persisted and expanded globally, infecting millions of devices.
- BADBOX 2.0 infects mainly low-cost Chinese Android IoT devices, often preloaded or infected during setup through malicious apps found even on Google Play.
- The FBI warned that millions of infected devices form a residential proxy network exploited by criminals for illegal activities, urging users to monitor devices closely.
- A joint cybersecurity operation disrupted BADBOX 2.0 communications in 2025, blocking over 500,000 devices, but continued vigilance is needed as the botnet still grows worldwide.
16 Articles
16 Articles
Millions of low-cost Android devices turn home networks into crime platforms
Millions of low-cost devices for media streaming, in-vehicle entertainment, and video projection are infected with malware that turns consumer networks into platforms for distributing malware, concealing nefarious communications, and performing other illicit activities, the FBI has warned. The malware infecting these devices, known as BadBox, is based on Triada, a malware strain discovered in 2016 by Kaspersky Lab, which called it "one of the mo…
FBI: BadBox 2.0 Android Malware Infects Millions of Consumer Devices
An anonymous reader quotes a report from BleepingComputer: The FBI is warning that the BADBOX 2.0 malware campaign has infected over 1 million home Internet-connected devices, converting consumer electronics into residential proxies that are used for malicious activity. The BADBOX botnet is commonly...
Coverage Details
Bias Distribution
- 80% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage