SECNORA experts are committed to keeping your digital world secure, which is why we’re sounding the alarm on BADBOX 2.0 which is a malicious botnet that has silently infected over 1.6 million Android devices worldwide. Discovered in 2023 on a T95 Android TV box, this malware targets smart TVs, streaming boxes, and tablets, turning them into tools for cybercriminals. The FBI’s June 2025 warning underscores the urgency of this threat, as it continues to spread across 222 countries. In this blog series, we’ll break down how BADBOX 2.0 works, its devastating impact, and actionable steps to keep your devices safe.
This dangerous malware, which has infected over 1.6 million Android devices worldwide, is a growing concern for anyone using smart TVs, streaming boxes, or tablets. Let’s dive into what BADBOX 2.0 is, where it came from, and why its global reach is so alarming.
BADBOX 2.0 traces its roots to 2023, when the original BADBOX malware was discovered on a T95 Android TV box sold on Amazon. That early version already showed its potential to hijack low-cost devices, but BADBOX 2.0 takes it to another level. Evolving from its predecessor, this malware has become more sophisticated, evading disruptions by cybersecurity experts and spreading rapidly. In 2024, Germany’s cybersecurity agency temporarily disrupted the botnet, but it bounced back, infecting 192,000 devices within a week. By March 2025, HUMAN’s Satori Threat Intelligence reported over 1.6 million compromised devices. At its core, BADBOX 2.0 is a botnet, a network of infected devices controlled by cybercriminals. It primarily targets Android-based Internet of Things (IoT) devices, such as smart TVs, streaming boxes, projectors, and tablets. These are often low-cost, unbranded devices running the Android Open Source Project (AOSP), which lack Google Play Protect certification. While most infections occur on lesser-known brands, even some devices from companies like Hisense and Yandex have been affected, showing no one is entirely safe.
The global reach of BADBOX 2.0 is staggering. It has spread to 222 countries, with Brazil accounting for 37.6% of infections and the United States 18.2%, according to HUMAN’s data. Other heavily impacted countries include Mexico, Argentina, India, Russia, and China. This widespread presence, combined with the malware’s ability to operate silently, makes BADBOX 2.0 a serious threat to global cybersecurity.
Lets understand how cyber threats like BADBOX 2.0 infiltrate devices is key to staying protected. This malicious botnet, which has compromised over 1.6 million Android devices worldwide, spreads through sneaky and sophisticated methods. From tampered hardware to deceptive apps, BADBOX 2.0 exploits vulnerabilities at every stage. Let’s break down how it infects devices, which ones are at risk, and why even trusted brands aren’t immune.
BADBOX 2.0 spreads in two primary ways.
The malware targets a wide range of Android-based Internet of Things (IoT) devices, including smart TVs, streaming boxes, tablets, digital projectors, and digital picture frames. Most affected devices are low-cost, unbranded models running the Android Open Source Project (AOSP), which lack Google Play Protect certification. Specific models known to be compromised include TV98, X96Q, X96mini, TX3mini, MX10PRO, X96Q_PRO, and KM9PRO, among others. A full list of over 40 affected models has been documented by cybersecurity researchers, highlighting the scale of the issue.
Shockingly, BADBOX 2.0 doesn’t limit itself to obscure brands. Devices from mainstream manufacturers like Hisense and Yandex have also been infected, according to reports from HUMAN’s Satori Threat Intelligence. This suggests that even reputable brands can fall victim if their supply chains or apps include compromised components. The involvement of these brands underscores the malware’s ability to infiltrate a broad range of devices, making vigilance critical for all Android users.
Beyond simply infecting devices, this malware carries out a range of harmful activities, from stealing your money to enabling large-scale cyberattacks. In this part, we’ll explore what BADBOX 2.0 does, including its primary goals, secondary threats, and how it uses compromised devices to hide its tracks.

First, it engages in ad fraud, generating fake ad clicks in the background on infected devices like smart TVs and streaming boxes. For example, a compromised T95 Android TV box might silently load ads, tricking advertisers into paying cybercriminals for views that never happened. This scheme has defrauded companies worldwide, with losses tied to the botnet’s massive scale.
Second, BADBOX 2.0 focuses on credential theft. By stealing login details from infected devices, it enables attackers to take over user accounts. Reports from HUMAN’s Satori Threat Intelligence confirm that the botnet uses stolen credentials for “credential stuffing,” where attackers test stolen login details on various platforms to gain unauthorized access. This puts your personal accounts, from streaming services to online banking, at risk.
Third, the botnet creates residential proxy networks. It turns infected devices, such as tablets or projectors, into proxy nodes that route internet traffic for cybercriminals. This allows attackers to hide their activities behind the IP addresses of everyday users. For instance, a streaming box in your home could be used to mask illegal transactions, making it nearly impossible to trace back to the perpetrators.
Beyond its primary goals, BADBOX 2.0 enables secondary threats that amplify its danger. One major threat is Distributed Denial-of-Service (DDoS) attacks. In a DDoS attack, cybercriminals flood a target server or network with traffic from thousands of compromised devices, overwhelming it and causing downtime. With over 1.6 million infected devices, BADBOX 2.0 has the potential to launch massive DDoS attacks. For example, in similar botnet campaigns, infected IoT devices have been used to disrupt websites, online services, or even critical infrastructure, costing businesses millions and interrupting user access.
Another serious threat is data exfiltration, where sensitive information is stolen from infected devices. BADBOX 2.0 can extract personal data, such as login credentials, browsing histories, or even financial details, from devices like smart TVs or tablets. This stolen data can be sold on the dark web or used for further attacks, such as identity theft. Cybersecurity reports note that the botnet’s ability to remotely execute arbitrary code makes it particularly effective at harvesting data without users noticing. For instance, a compromised Hisense smart TV could quietly send your streaming account details to attackers, exposing your personal information.
BADBOX 2.0’s ability to hide its operations is what makes it so dangerous. By turning infected devices into residential proxies, the malware routes malicious traffic through the IP addresses of unsuspecting users. For example, a tablet infected with BADBOX 2.0 in Brazil might be used to relay traffic for a cyberattack originating in another country, making it appear as though the attack comes from a legitimate home network. This tactic was observed in the botnet’s activities across 222 countries, with Brazil and the United States being major hubs due to their high infection rates (37.6% and 18.2%, respectively).
The botnet communicates with command-and-control (C2) servers to receive instructions, such as launching ad fraud campaigns or initiating DDoS attacks. These servers allow attackers to control millions of devices remotely, exploiting their processing power and internet connections. By blending malicious traffic with normal household internet activity, BADBOX 2.0 evades detection by traditional cybersecurity measures, making it a persistent and elusive threat.
We empower you to protect your devices by recognizing threats like BADBOX 2.0, a botnet that has compromised over 1.6 million Android devices worldwide. Identifying an infection early can prevent cybercriminals from exploiting your smart TVs, streaming boxes, or tablets for ad fraud or data theft. In this part, we’ll detail the key indicators of compromise (IoCs) and performance issues linked to BADBOX 2.0, using precise cybersecurity terms to help you spot this malware in action.
BADBOX 2.0 leaves specific traces that cybersecurity experts call indicators of compromise. These are red flags signaling a device may be part of the botnet. Based on reports from the FBI and HUMAN’s Satori Threat Intelligence, here are the primary IoCs to watch for:
In addition to these IoCs, BADBOX 2.0 causes noticeable performance degradation, often tied to its background activities like ad fraud or proxy networking. The following issues, reported across devices like the X96mini and KM9PRO, are telltale signs of infection:
These performance issues are critical because they not only degrade the user experience but also indicate that the device is being exploited for malicious purposes, such as launching Distributed Denial-of-Service (DDoS) attacks or stealing credentials.
By staying alert to these IoCs and performance symptoms, you can identify a potential BADBOX 2.0 infection before it causes serious harm. In our next part, we’ll explore how to protect your devices from this pervasive threat.
BADBOX 2.0 thrives because of vulnerabilities in low-cost Android devices, particularly those running the Android Open Source Project (AOSP). Unlike Google Play Protect-certified devices, AOSP devices often lack robust security features, such as regular firmware updates or malware scanning. For example, devices like the T95 Android TV box, first identified as infected in 2023, run outdated firmware, making them easy targets for attackers. These devices, typically manufactured in China and sold globally, are popular in regions like Brazil, where 37.6% of infections are reported, according to HUMAN’s Satori Threat Intelligence.
Supply chain vulnerabilities are another key factor. BADBOX 2.0 often comes pre-installed in device firmware, meaning devices like the X96Q streaming box or MX10PRO tablet are compromised before they reach consumers. This was evident in the original BADBOX campaign, where Chinese manufacturers embedded the Triada-inspired malware in hardware sold on platforms like Amazon. These supply chain attacks exploit poor oversight in production, allowing cybercriminals to tamper with devices at scale. Even mainstream brands like Hisense and Yandex have been affected, showing that no device is entirely safe if its supply chain is compromised.
The botnet’s open-season nature makes it particularly dangerous. Its backdoor, often dubbed BB2DOOR, allows attackers to remotely execute any code, enabling a range of malicious activities from ad fraud to credential theft. This flexibility, combined with the sheer number of infected devices—over 1.6 million—creates a massive platform for cybercriminals to exploit, impacting both individual users and businesses through fraudulent ad revenue and stolen data.
BADBOX 2.0’s ability to bounce back after major disruptions highlights its resilience. In December 2024, Germany’s Federal Office for Information Security (BSI) sinkholed the botnet’s command-and-control (C2) servers, cutting off communications for over 30,000 infected devices. Yet, within a week, Bitsight reported 192,000 newly infected devices, showing the botnet’s rapid recovery. By March 2025, HUMAN’s Satori Threat Intelligence team noted that the botnet had grown to over 1.6 million devices, despite a joint operation with Google, Trend Micro, and The Shadowserver Foundation that disrupted over 500,000 devices by sinkholing additional C2 servers.
This resilience stems from the botnet’s adaptable infrastructure and the continued sale of pre-infected devices. For example, Google removed 24 malicious apps from the Play Store, including apps like “Earn Extra Income” with over 50,000 downloads, but third-party app stores and ongoing supply chain attacks keep the malware spreading. The botnet’s operators also use “evil twin” apps, counterfeit versions of legitimate software to infect devices post-purchase, further fueling its growth. These adaptations make BADBOX 2.0 a persistent threat that requires constant vigilance.
This malware, found on devices like the T95 Android TV box and even some Hisense smart TVs, exploits vulnerabilities to fuel ad fraud and steal data. Fortunately, you can take practical steps to protect your devices and home network. Here’s how to shield yourself from BADBOX 2.0 with actionable measures and trusted tools. To keep BADBOX 2.0 at bay, follow these straightforward steps rooted in cybersecurity best practices:
Investing in reliable security tools can bolster your defenses against BADBOX 2.0 and similar threats:
Proactive monitoring and quick action are key to stopping BADBOX 2.0 from spreading within your network:
By combining these steps with the right tools, you can significantly reduce your risk of falling victim to BADBOX 2.0.
BADBOX 2.0 is a stark reminder of the dangers lurking in our connected world. With over 1.6 million Android devices infected across 222 countries, this botnet fuels ad fraud, steals credentials, and powers cyberattacks like DDoS through devices like the T95 and X96Q. Despite disruptions by Germany’s BSI in 2024 and a joint effort by HUMAN, Google, and Trend Micro in 2025, the botnet’s resilience reaching 192,000 new infections within a week of the 2024 crackdown shows it’s an ongoing threat. Its ability to exploit supply chain weaknesses and low-cost AOSP devices makes it a global cybersecurity challenge.
Copyright @ 2026 SECNORA®