BADBOX is a large Android-focused malicious platform and botnet ecosystem associated with the compromise of consumer and embedded devices, especially uncertified Android TV boxes, streaming devices, tablets, smartphones, and other internet-connected products. The operation has also been linked to malware delivered through supply-chain compromise and trojanized applications, including preinstalled malware on devices before purchase and malicious apps installed during device setup or update workflows. More recent activity has expanded to Android-based automotive infotainment head units through abuse of legitimate update components, indicating continued adaptation after prior disruption efforts. BADBOX is widely associated with monetization through residential proxy services and ad fraud. Infected devices are enrolled into hidden proxy networks that relay third-party traffic through victims’ residential or mobile connections, while other payloads support advertisement display, fraudulent ad clicks, hidden web activity, and staged delivery of additional malware. The ecosystem has been linked to reverse-proxy modules such as zhima and to broader proxy-service infrastructure and brands used to commercialize access to compromised devices. The actor cluster most directly tied to BADBOX in the supplied facts is MoYu Group, which has been attributed with high confidence in multiple BADBOX-linked campaigns. MoYu-linked activity has used multi-stage Android malware chains, downloader components, dynamic configuration updates, command-based tasking, and infrastructure overlap across campaigns targeting TV boxes and automotive head units. Observed behaviors include covert installation via legitimate system applications, payload retrieval, device profiling, remote command execution, arbitrary code loading, and conversion of infected devices into proxy exit nodes. BADBOX has persisted despite disruption by defenders and law enforcement. The original operation was identified in 2023 and later disrupted in 2024, after which operators resurfaced with BADBOX 2.0. BADBOX 2.0 has been described as compromising millions of Android-based IoT devices globally, particularly smart TVs and streaming boxes, and has been linked to overlapping components in the wider malicious residential proxy ecosystem. The dominant motivation evidenced by the operation is financial gain through fraud and proxy monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware operation/botnet linked to MoYu Group and prior compromises of Android smartphones, tablets, streaming devices, TV boxes, and other IoT products, including resurgence as BadBox 2.0.
Referenced as a related Android-device criminal ecosystem/campaign with shared infrastructure and linkage to the MoYu Group activity.
A malicious platform centered on infecting Android devices and covertly monetizing their resources, including through proxy botnet activity.
A malicious platform/ecosystem tied to Android device infections and covert monetization of compromised device resources; the described automotive head-unit campaign is linked to this platform through MoYu Group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.