BADBOX 2.0 Android malware infects millions of consumer devices

SECNORA experts are committed to keeping your digital world secure, which is why we’re sounding the alarm on BADBOX 2.0 which is a malicious botnet that has silently infected over 1.6 million Android devices worldwide. Discovered in 2023 on a T95 Android TV box, this malware targets smart TVs, streaming boxes, and tablets, turning them into tools for cybercriminals. The FBI’s June 2025 warning underscores the urgency of this threat, as it continues to spread across 222 countries. In this blog series, we’ll break down how BADBOX 2.0 works, its devastating impact, and actionable steps to keep your devices safe.

What is BADBOX 2.0?

This dangerous malware, which has infected over 1.6 million Android devices worldwide, is a growing concern for anyone using smart TVs, streaming boxes, or tablets. Let’s dive into what BADBOX 2.0 is, where it came from, and why its global reach is so alarming.

BADBOX 2.0 traces its roots to 2023, when the original BADBOX malware was discovered on a T95 Android TV box sold on Amazon. That early version already showed its potential to hijack low-cost devices, but BADBOX 2.0 takes it to another level. Evolving from its predecessor, this malware has become more sophisticated, evading disruptions by cybersecurity experts and spreading rapidly. In 2024, Germany’s cybersecurity agency temporarily disrupted the botnet, but it bounced back, infecting 192,000 devices within a week. By March 2025, HUMAN’s Satori Threat Intelligence reported over 1.6 million compromised devices. At its core, BADBOX 2.0 is a botnet, a network of infected devices controlled by cybercriminals. It primarily targets Android-based Internet of Things (IoT) devices, such as smart TVs, streaming boxes, projectors, and tablets. These are often low-cost, unbranded devices running the Android Open Source Project (AOSP), which lack Google Play Protect certification. While most infections occur on lesser-known brands, even some devices from companies like Hisense and Yandex have been affected, showing no one is entirely safe.

The global reach of BADBOX 2.0 is staggering. It has spread to 222 countries, with Brazil accounting for 37.6% of infections and the United States 18.2%, according to HUMAN’s data. Other heavily impacted countries include Mexico, Argentina, India, Russia, and China. This widespread presence, combined with the malware’s ability to operate silently, makes BADBOX 2.0 a serious threat to global cybersecurity.

How BADBOX 2.0 Spreads?

Lets understand how cyber threats like BADBOX 2.0 infiltrate devices is key to staying protected. This malicious botnet, which has compromised over 1.6 million Android devices worldwide, spreads through sneaky and sophisticated methods. From tampered hardware to deceptive apps, BADBOX 2.0 exploits vulnerabilities at every stage. Let’s break down how it infects devices, which ones are at risk, and why even trusted brands aren’t immune.

BADBOX 2.0 spreads in two primary ways.

  • First, it often comes pre-installed on devices through supply chain attacks. This means the malware is embedded in the device’s firmware before it even reaches the store, a tactic seen in many low-cost, Chinese-made Android devices. For example, the T95 Android TV box, identified in 2023 as an early carrier of BADBOX, was sold on Amazon with the malware already built in. These attacks exploit weak oversight in the manufacturing process, allowing cybercriminals to compromise devices before consumers ever power them on.
  • The second method is post-purchase infection through malicious apps. These apps, disguised as legitimate software or firmware updates, sneak onto devices via third-party app stores or, in some cases, even Google Play. Users may unknowingly download an app promising free streaming or enhanced features, only to install BADBOX 2.0. This method is particularly effective because it preys on users’ trust, especially during device setup when apps are often required.

The malware targets a wide range of Android-based Internet of Things (IoT) devices, including smart TVs, streaming boxes, tablets, digital projectors, and digital picture frames. Most affected devices are low-cost, unbranded models running the Android Open Source Project (AOSP), which lack Google Play Protect certification. Specific models known to be compromised include TV98, X96Q, X96mini, TX3mini, MX10PRO, X96Q_PRO, and KM9PRO, among others. A full list of over 40 affected models has been documented by cybersecurity researchers, highlighting the scale of the issue.

Shockingly, BADBOX 2.0 doesn’t limit itself to obscure brands. Devices from mainstream manufacturers like Hisense and Yandex have also been infected, according to reports from HUMAN’s Satori Threat Intelligence. This suggests that even reputable brands can fall victim if their supply chains or apps include compromised components. The involvement of these brands underscores the malware’s ability to infiltrate a broad range of devices, making vigilance critical for all Android users.

What BADBOX 2.0 Does?

Beyond simply infecting devices, this malware carries out a range of harmful activities, from stealing your money to enabling large-scale cyberattacks. In this part, we’ll explore what BADBOX 2.0 does, including its primary goals, secondary threats, and how it uses compromised devices to hide its tracks.

badbox

First, it engages in ad fraud, generating fake ad clicks in the background on infected devices like smart TVs and streaming boxes. For example, a compromised T95 Android TV box might silently load ads, tricking advertisers into paying cybercriminals for views that never happened. This scheme has defrauded companies worldwide, with losses tied to the botnet’s massive scale.

Second, BADBOX 2.0 focuses on credential theft. By stealing login details from infected devices, it enables attackers to take over user accounts. Reports from HUMAN’s Satori Threat Intelligence confirm that the botnet uses stolen credentials for “credential stuffing,” where attackers test stolen login details on various platforms to gain unauthorized access. This puts your personal accounts, from streaming services to online banking, at risk.

Third, the botnet creates residential proxy networks. It turns infected devices, such as tablets or projectors, into proxy nodes that route internet traffic for cybercriminals. This allows attackers to hide their activities behind the IP addresses of everyday users. For instance, a streaming box in your home could be used to mask illegal transactions, making it nearly impossible to trace back to the perpetrators.

Secondary Threats: DDoS Attacks and Data Exfiltration

Beyond its primary goals, BADBOX 2.0 enables secondary threats that amplify its danger. One major threat is Distributed Denial-of-Service (DDoS) attacks. In a DDoS attack, cybercriminals flood a target server or network with traffic from thousands of compromised devices, overwhelming it and causing downtime. With over 1.6 million infected devices, BADBOX 2.0 has the potential to launch massive DDoS attacks. For example, in similar botnet campaigns, infected IoT devices have been used to disrupt websites, online services, or even critical infrastructure, costing businesses millions and interrupting user access.

Another serious threat is data exfiltration, where sensitive information is stolen from infected devices. BADBOX 2.0 can extract personal data, such as login credentials, browsing histories, or even financial details, from devices like smart TVs or tablets. This stolen data can be sold on the dark web or used for further attacks, such as identity theft. Cybersecurity reports note that the botnet’s ability to remotely execute arbitrary code makes it particularly effective at harvesting data without users noticing. For instance, a compromised Hisense smart TV could quietly send your streaming account details to attackers, exposing your personal information.

How BADBOX 2.0 Masks Malicious Activities

BADBOX 2.0’s ability to hide its operations is what makes it so dangerous. By turning infected devices into residential proxies, the malware routes malicious traffic through the IP addresses of unsuspecting users. For example, a tablet infected with BADBOX 2.0 in Brazil might be used to relay traffic for a cyberattack originating in another country, making it appear as though the attack comes from a legitimate home network. This tactic was observed in the botnet’s activities across 222 countries, with Brazil and the United States being major hubs due to their high infection rates (37.6% and 18.2%, respectively).

The botnet communicates with command-and-control (C2) servers to receive instructions, such as launching ad fraud campaigns or initiating DDoS attacks. These servers allow attackers to control millions of devices remotely, exploiting their processing power and internet connections. By blending malicious traffic with normal household internet activity, BADBOX 2.0 evades detection by traditional cybersecurity measures, making it a persistent and elusive threat.

Signs of Infection

We empower you to protect your devices by recognizing threats like BADBOX 2.0, a botnet that has compromised over 1.6 million Android devices worldwide. Identifying an infection early can prevent cybercriminals from exploiting your smart TVs, streaming boxes, or tablets for ad fraud or data theft. In this part, we’ll detail the key indicators of compromise (IoCs) and performance issues linked to BADBOX 2.0, using precise cybersecurity terms to help you spot this malware in action.

Indicators of Compromise (IoCs)

BADBOX 2.0 leaves specific traces that cybersecurity experts call indicators of compromise. These are red flags signaling a device may be part of the botnet. Based on reports from the FBI and HUMAN’s Satori Threat Intelligence, here are the primary IoCs to watch for:

  • Disabled Google Play Protect: BADBOX 2.0 often disables Google Play Protect, Android’s built-in security feature that scans for malicious apps. For example, devices like the T95 Android TV box, identified in 2023, were found with Google Play Protect turned off, allowing the malware to operate undetected.
  • Suspicious App Marketplaces: The malware automatically installs unverified app marketplaces, which are not affiliated with Google Play. These marketplaces often distribute malicious apps disguised as legitimate software. Users of infected devices, such as the X96Q streaming box, have reported unknown app stores appearing without their consent.
  • “Unlocked” Devices or Free Content Offers: Devices advertised as “unlocked” or promising free access to premium content, like streaming services, are common carriers of BADBOX 2.0. For instance, some low-cost smart TVs sold online were promoted with free streaming capabilities, only to be found pre-installed with the malware.
  • Devices from Unknown Brands: Many infected devices, such as the TV98 or MX10PRO, come from lesser-known manufacturers lacking Google Play Protect certification. These Android Open Source Project (AOSP) devices are prime targets due to their weak security. However, even reputable brands like Hisense and Yandex have reported infections, showing the malware’s broad reach.
  • Prompts to Disable Security Settings: During setup or app installation, BADBOX 2.0 may prompt users to disable security features, such as app verification or firewall protections. This was observed in infected tablets, where users were asked to turn off security to install seemingly legitimate updates.

Performance Issues

In addition to these IoCs, BADBOX 2.0 causes noticeable performance degradation, often tied to its background activities like ad fraud or proxy networking. The following issues, reported across devices like the X96mini and KM9PRO, are telltale signs of infection:

  • Overheating: Infected devices may overheat due to excessive background processes. For example, BADBOX 2.0’s ad fraud activities, which involve loading and clicking ads silently, can cause a device’s processor to work overtime, generating heat. Users of infected Hisense smart TVs have reported devices becoming unusually warm during normal use.
  • High CPU Usage: The malware consumes significant CPU resources to execute commands from its command-and-control (C2) servers. This leads to sluggish performance, such as slow app loading or delayed responses. Cybersecurity reports note that devices like the TX3mini exhibited high CPU usage when running malicious proxy traffic.
  • Unusual Network Traffic: BADBOX 2.0 generates unexpected spikes in internet traffic as it communicates with C2 servers or routes data through residential proxy networks. For instance, a compromised Yandex TV was found sending large amounts of data to unknown servers, a clear sign of botnet activity. Monitoring tools, like those offered by SECNORA, can detect these anomalies by tracking outbound connections.

These performance issues are critical because they not only degrade the user experience but also indicate that the device is being exploited for malicious purposes, such as launching Distributed Denial-of-Service (DDoS) attacks or stealing credentials.

By staying alert to these IoCs and performance symptoms, you can identify a potential BADBOX 2.0 infection before it causes serious harm. In our next part, we’ll explore how to protect your devices from this pervasive threat.

Why BADBOX 2.0 is a Significant Threat

BADBOX 2.0 thrives because of vulnerabilities in low-cost Android devices, particularly those running the Android Open Source Project (AOSP). Unlike Google Play Protect-certified devices, AOSP devices often lack robust security features, such as regular firmware updates or malware scanning. For example, devices like the T95 Android TV box, first identified as infected in 2023, run outdated firmware, making them easy targets for attackers. These devices, typically manufactured in China and sold globally, are popular in regions like Brazil, where 37.6% of infections are reported, according to HUMAN’s Satori Threat Intelligence.

Supply chain vulnerabilities are another key factor. BADBOX 2.0 often comes pre-installed in device firmware, meaning devices like the X96Q streaming box or MX10PRO tablet are compromised before they reach consumers. This was evident in the original BADBOX campaign, where Chinese manufacturers embedded the Triada-inspired malware in hardware sold on platforms like Amazon. These supply chain attacks exploit poor oversight in production, allowing cybercriminals to tamper with devices at scale. Even mainstream brands like Hisense and Yandex have been affected, showing that no device is entirely safe if its supply chain is compromised.

The botnet’s open-season nature makes it particularly dangerous. Its backdoor, often dubbed BB2DOOR, allows attackers to remotely execute any code, enabling a range of malicious activities from ad fraud to credential theft. This flexibility, combined with the sheer number of infected devices—over 1.6 million—creates a massive platform for cybercriminals to exploit, impacting both individual users and businesses through fraudulent ad revenue and stolen data.

Resilience Despite Disruptions

BADBOX 2.0’s ability to bounce back after major disruptions highlights its resilience. In December 2024, Germany’s Federal Office for Information Security (BSI) sinkholed the botnet’s command-and-control (C2) servers, cutting off communications for over 30,000 infected devices. Yet, within a week, Bitsight reported 192,000 newly infected devices, showing the botnet’s rapid recovery. By March 2025, HUMAN’s Satori Threat Intelligence team noted that the botnet had grown to over 1.6 million devices, despite a joint operation with Google, Trend Micro, and The Shadowserver Foundation that disrupted over 500,000 devices by sinkholing additional C2 servers.

This resilience stems from the botnet’s adaptable infrastructure and the continued sale of pre-infected devices. For example, Google removed 24 malicious apps from the Play Store, including apps like “Earn Extra Income” with over 50,000 downloads, but third-party app stores and ongoing supply chain attacks keep the malware spreading. The botnet’s operators also use “evil twin” apps, counterfeit versions of legitimate software to infect devices post-purchase, further fueling its growth. These adaptations make BADBOX 2.0 a persistent threat that requires constant vigilance.

Protecting Yourself from BADBOX 2.0

This malware, found on devices like the T95 Android TV box and even some Hisense smart TVs, exploits vulnerabilities to fuel ad fraud and steal data. Fortunately, you can take practical steps to protect your devices and home network. Here’s how to shield yourself from BADBOX 2.0 with actionable measures and trusted tools. To keep BADBOX 2.0 at bay, follow these straightforward steps rooted in cybersecurity best practices:

  • Buy Certified Devices: Choose Android devices certified by Google Play Protect, such as those from reputable brands like Samsung or Sony. Unlike the X96Q or MX10PRO, which are often AOSP-based and lack certification, these devices undergo strict security checks. For example, Google Play Protect scans for malicious apps, reducing the risk of pre-installed malware like BADBOX 2.0.
  • Avoid Third-Party App Stores: Stick to downloading apps from Google Play, which has stronger vetting processes. Third-party stores, like those found on infected KM9PRO streaming boxes, often host malicious apps disguised as legitimate software. In 2025, Google removed 24 such apps, including “Earn Extra Income,” from the Play Store after they were linked to BADBOX 2.0.
  • Keep Devices Updated: Regularly update your device’s firmware and apps to patch security vulnerabilities. Many infected devices, such as the TX3mini, run outdated firmware, making them easy targets. Check for updates in your device’s settings or manufacturer’s website to stay protected.

Recommended Security Tools

Investing in reliable security tools can bolster your defenses against BADBOX 2.0 and similar threats:

  • Bitdefender Mobile Security: This Android-specific antivirus software detects and blocks malicious apps, including those tied to BADBOX 2.0. It also scans for suspicious behavior, such as unauthorized network connections, which was critical in identifying infections on devices like the X96mini.
  • NETGEAR Armor: Designed for home networks, NETGEAR Armor provides real-time threat detection and blocks botnet activity. It’s particularly effective for monitoring IoT devices, like smart TVs or projectors, which BADBOX 2.0 often targets. Users have reported it flagging unusual traffic from infected devices, helping to prevent further compromise.

Network Monitoring and Device Isolation

Proactive monitoring and quick action are key to stopping BADBOX 2.0 from spreading within your network:

  • Monitor Network Traffic: Use tools like NETGEAR Armor or free apps like Fing to track internet traffic from your devices. Unusual spikes, such as those seen on infected Yandex TVs sending data to unknown servers, can signal botnet activity. For instance, HUMAN’s Satori Threat Intelligence noted that BADBOX 2.0 devices in Brazil generated significant outbound traffic for proxy networks.
  • Isolate Suspected Devices: If you notice signs of infection, like disabled Google Play Protect or overheating, disconnect the device from your Wi-Fi immediately. For example, isolating a compromised TV98 streaming box can prevent it from communicating with command-and-control (C2) servers, disrupting the botnet’s operations. Reset the device to factory settings or contact the manufacturer for guidance if you suspect infection.

By combining these steps with the right tools, you can significantly reduce your risk of falling victim to BADBOX 2.0.

BADBOX 2.0 is a stark reminder of the dangers lurking in our connected world. With over 1.6 million Android devices infected across 222 countries, this botnet fuels ad fraud, steals credentials, and powers cyberattacks like DDoS through devices like the T95 and X96Q. Despite disruptions by Germany’s BSI in 2024 and a joint effort by HUMAN, Google, and Trend Micro in 2025, the botnet’s resilience reaching 192,000 new infections within a week of the 2024 crackdown shows it’s an ongoing threat. Its ability to exploit supply chain weaknesses and low-cost AOSP devices makes it a global cybersecurity challenge.