Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 5 actors

BADBOX 2.0

Also known asBADBOX

BadBox 2.0 is an Android malware campaign and botnet, also described as a backdoor/fraud scheme, that primarily affects low-cost, often non-Play-Protect-certified Android consumer devices. Reported targets include TV streaming boxes, Android TV boxes, digital projectors, tablets, smartphones, smart devices, and aftermarket vehicle entertainment systems, with many affected devices described as manufactured in China and sold through online stores, electronics retailers, and other distribution channels. Multiple sources state the malware is frequently preinstalled during the supply chain or manufacturing process before the user powers on the device, though some infections may also occur during setup via malicious app downloads, suspicious websites, or unofficial app marketplaces.

The malware operates with elevated or root-level privileges and is described as extremely difficult or practically impossible for users to remove when embedded in firmware. One reported BADBOX variant was embedded in a malicious native library, librescache.so, loaded by the Android system framework; Kaspersky reported this caused a copy of the Trojan to infiltrate every running process on the device. The campaign has also been associated with the Triada Trojan lineage, and some reporting states Triada was detected on Badbox-infected devices.

Documented capabilities include silently installing additional applications or modules, remote execution of additional modules, collecting data, displaying or clicking ads for ad fraud, spying on users, and enrolling devices into a broader botnet. BadBox 2.0 has been repeatedly described as functioning both as an ad fraud engine and as a residential proxy network, allowing compromised devices to relay traffic for other criminal activity. Reported monetization and downstream abuse include advertising fraud, phishing, denial-of-service activity, bandwidth resale, and use of infected devices as proxy infrastructure. Some reporting also notes that infected devices may appear to function normally while malicious activity occurs in the background.

The campaign has been described at very large scale. Google stated in a July 2025 lawsuit that operators of the BadBox 2.0 enterprise had compromised over 10 million Android devices. The FBI warned that millions of internet-connected devices were infected. Other reporting cited around 200 Android device models affected in one case, mostly cheap TV set-top boxes under various brands, with some tablets and smartphones also impacted, including devices purchased for schools. Human Security described BadBox 2.0 as the largest botnet of infected connected TV devices uncovered, and reporting noted significant impact in Brazil and the United States. The Estonian Information System Authority reportedly detected more than 7,000 infected devices in Estonia, and Ireland and Finland also reported BADBOX-related activity or warnings.

BadBox 2.0 is closely associated in the reporting with the Vo1d ecosystem, and some disrupted infrastructure was linked to related proxy and ad-fraud operations. Google, HUMAN Security, and Trend Micro were reported to have disrupted BadBox 2.0 in July 2025, and Google filed suit against alleged operators described as being in China. High-confidence indicators and artifacts directly mentioned in the content include the malicious library librescache.so, affected device/model references such as TV98 and X96, and repeated association with cheap Android TV boxes lacking Google Play Protect certification.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
LongTV

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse

via cloudatg insightscloudatg.com
Lemon Group

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse

via cloudatg insightscloudatg.com
MoYu Group

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse

via cloudatg insightscloudatg.com
SalesTracker Group

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse

via cloudatg insightscloudatg.com
BadBox 2.0 Enterprise

"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."

via krebs on securitykrebsonsecurity.com
MITRE ATT&CK

Techniques & procedures

20 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1584.005BotnetEvidence1

Haittaohjelmalla laite voidaan liittää osaksi bottiverkkoa. Bottiverkkoon liitettyjä laitteita voidaan käyttää rikolliseen toimintaan, esimerkiksi palvelunestohyökkäyksiin.

Initial Access

3 techniques
T1189Drive-by CompromiseEvidence4

or “infecting the device as it downloads required applications that contain backdoors, usually during the setup process,”

T1195Supply Chain CompromiseEvidence13

the affected devices were manufactured in China and secretly backdoored to host malware. This can include installing the malware before the product's sale

T1566PhishingEvidence1

rikolliset voivat vuokrata pääsyn bottiverkkoon ja käyttää sitä esimerkiksi mainospetoksiin tai tietojenkalasteluun...

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1

BadBox 2.0 mahdollistaa lisämoduulien etäkäynnistyksen...

T1204.002Malicious FileEvidence2

The same marketplaces could have the ability to download malware that’s been disguised to look like apps from official vendors.

Persistence

2 techniques
T1542.001System FirmwareEvidence1

...haittaohjelman takaovi sijaitsee laiteohjelmistossa, jota ei voi kirjoittaa uudelleen ilman valmistajan erillisiä toimenpiteitä.

T1546Event Triggered ExecutionEvidence1

Haittaohjelman asentamista varten laitteisiin on upotettu takaovi jo tuotantoketjussa, eikä sitä voi poistaa.

Privilege Escalation

2 techniques
T1055Process InjectionEvidence1

We conducted an investigation, discovering a new version of the BADBOX backdoor, preloaded on the device. This backdoor is a multi-level loader embedded in a malicious native library, librescache.so, which was loaded by the system framework. As a result, a copy of the Trojan infiltrated every process running on the device.

T1546Event Triggered ExecutionEvidence1

Haittaohjelman asentamista varten laitteisiin on upotettu takaovi jo tuotantoketjussa, eikä sitä voi poistaa.

Stealth

4 techniques
T1014RootkitEvidence1

Toisin kuin monissa muissa haittaohjelmissa, BadBox 2.0 toimii laitteen juuritason oikeuksilla, mikä tekee sen poistamisesta käytännössä mahdotonta ilman erikoistoimenpiteitä.

T1027Obfuscated Files or InformationEvidence1

“decrypted data… using RC4… payload… loaded via DexClassLoader… C2 server addresses… Base64… gzip… AES-128… Another backdoor… single-byte XOR and executes it…”

T1055Process InjectionEvidence1

We conducted an investigation, discovering a new version of the BADBOX backdoor, preloaded on the device. This backdoor is a multi-level loader embedded in a malicious native library, librescache.so, which was loaded by the system framework. As a result, a copy of the Trojan infiltrated every process running on the device.

T1542.001System FirmwareEvidence1

...haittaohjelman takaovi sijaitsee laiteohjelmistossa, jota ei voi kirjoittaa uudelleen ilman valmistajan erillisiä toimenpiteitä.

Credential Access

1 technique
T1555Credentials from Password StoresEvidence1

“Triada… allowed the Trojan to exfiltrate credentials from messaging apps and social media platforms… payload… designed to steal victims’ account credentials… Telegram and Instagram… code for WhatsApp…”

Collection

1 technique
T1005Data from Local SystemEvidence2

Haittaohjelma voi asentaa sovelluksia, klikata mainoksia, vakoilla käyttäjää...

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence1

"establishes a client-server architecture"; "queries C2 servers"; "Domain keepgo123.com, gsonx.com"; "Path /ak/api/pts/v4"

T1090ProxyEvidence1

Because the infected devices have access to the internet, the hackers can harness the botnet as a proxy service, creating a launching pad for other cybercriminal activities

T1090.003Multi-hop ProxyEvidence4

Once those custom apps are installed, the device doesn't just stream video but also begins routing internet traffic through third-party proxy networks. What this means is that your home internet connection may be used to relay traffic for other people.

T1105Ingress Tool TransferEvidence1

Haittaohjelma voi asentaa sovelluksia...

Impact

2 techniques
T1498Network Denial of ServiceEvidence2

Haitallinen koodi ohjaa tartunnan saanutta laitetta välittämään verkkoliikennettä ja osallistumaan hajautettuihin palvelunestohyökkäyksiin (DDoS).

T1499Endpoint Denial of ServiceEvidence1

Bottiverkkoon liitettyjä laitteita voidaan käyttää rikolliseen toimintaan, esimerkiksi palvelunestohyökkäyksiin.

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

FBI indicators include: "Requiring Google Play Protect settings to be disabled."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping20

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.