BadBox 2.0 is a large-scale Android-based botnet and fraud ecosystem centered on compromised consumer IoT devices, especially uncertified Android TV boxes, streaming devices, smart TVs, and related set-top hardware. It emerged after disruption of the original BADBOX campaign, which was identified in 2023 as involving Android devices compromised with backdoor malware before purchase. BadBox 2.0 has been described as compromising millions of devices globally, often through supply-chain preinstallation of malware or through trojanized and backdoored applications during device setup. The operation has been linked to China-based actors at the ecosystem level, but public attribution remains unattributed rather than tied to a specific named state or criminal group. Its infrastructure and components have been associated with residential proxy monetization, ad-fraud patterns, and overlap with other Android botnet and proxy ecosystems. Public reporting has also noted technical and operational overlap between BadBox 2.0 and proxy-network components used in broader residential proxy services. BadBox 2.0 primarily abuses infected devices as residential proxy exit nodes, allowing third parties to route traffic through victims’ home connections to conceal origin, support fraud, and facilitate other malicious activity. The botnet has also been associated with backdoor functionality on infected Android devices and with plugin or SDK-based mechanisms that enroll devices into proxy networks. Related reporting connects the ecosystem to HTML5-based cashout infrastructure and monetization patterns previously observed in mobile ad-fraud clusters. Victim devices are typically low-cost, off-brand, or uncertified Android Open Source Project devices, with compromise occurring either before sale through the supply chain or after activation through malicious applications. The actor’s tradecraft therefore spans initial access via supply-chain compromise and trojanized apps, persistence on embedded Android devices, defense evasion through blending into consumer hardware and app ecosystems, and post-compromise monetization through proxy resale and fraud enablement. Known aliases include BADBOX and BadBox 2.0.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet associated with packaging proxy plugins that help power the NetNut residential proxy ecosystem.
A botnet of hijacked Android TV devices mentioned as overlapping in components with Popa/NetNut.
A large-scale botnet materially connected to NetNut through plugin components tied to the proxy network.
Prior threat cluster associated with HTML5-based cashout sites in ad fraud and malvertising activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.