BADBOX is an Android malware and botnet operation centered on consumer devices that are sold with a firmware-level backdoor already present or with malicious components embedded in the software supply chain. It has affected Android-based TV boxes, streaming devices, digital picture frames, media players, smartphones, tablets, smart TVs, and other IoT-style consumer hardware. Multiple investigations describe BADBOX as closely related to Triada-style Android compromise, including modification of core system components and early execution during device startup, allowing the malware to establish control immediately after first boot.
Once active, BADBOX contacts command-and-control infrastructure to register the device and retrieve instructions or secondary payloads. Reported capabilities include downloading and installing additional malware or modules without user consent, remote code installation, covert account creation for email and messaging platforms, interception of one-time passwords, ad fraud through hidden browsing or ad interaction, data theft, and operation as a residential proxy node. Through the proxy functionality, infected devices can relay third-party traffic and expose victims' residential IP addresses and local networks to abuse by criminal operators.
BADBOX has been described both as a firmware backdoor and as a large-scale Android botnet. Public reporting has tied associated modules and later variants to broader proxy and botnet ecosystems including PEACHPIT, Vo1d, Popa, and BadBox 2.0, with some overlap noted in infrastructure or plugin components. The operation has been disrupted multiple times by defenders and authorities, including sinkholing actions against infected devices and later legal and technical actions against related infrastructure, but reporting indicates the ecosystem has been resilient and has continued to evolve.
The malware is notable for its supply-chain distribution model rather than reliance solely on user-initiated installation. Infected devices have been observed reaching consumers through ordinary retail channels, and some reports also note trojanized applications or silently installed packages as additional infection paths. Because the compromise can reside in firmware or trusted system libraries, remediation is often difficult for end users, and affected devices may remain untrustworthy even if network communications are temporarily blocked.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."
20 distinct techniques documented for this family, organized by ATT&CK tactic.
BadBox ist in der Lage, unbemerkt Accounts für E-Mail- und Messenger-Dienste zu erstellen, über die anschließend Fake-News verbreitet werden können.
We conducted an investigation, discovering a new version of the BADBOX backdoor, preloaded on the device. This backdoor is a multi-level loader embedded in a malicious native library, librescache.so, which was loaded by the system framework. As a result, a copy of the Trojan infiltrated every process running on the device.
We conducted an investigation, discovering a new version of the BADBOX backdoor, preloaded on the device. This backdoor is a multi-level loader embedded in a malicious native library, librescache.so, which was loaded by the system framework. As a result, a copy of the Trojan infiltrated every process running on the device.
Data Harvesting Module, collects sensitive user and device information, including: Installed apps, IP and MAC addresses, Geolocation data, Device ID, IMEI, Android version, and more
Das BSI leitet derzeit im Rahmen einer Sinkholing-Maßnahme nach § 7c BSI-Gesetz (BSIG) die Kommunikation betroffener Geräte mit den Kontrollservern der Täter um.
Darüber hinaus kann die Schadsoftware als Residental-Proxy-Service fungieren. Dabei stellt sie die Internetverbindung der Nutzerinnen und Nutzer unbekannten Dritten zur Verfügung, die diese dann für kriminelle Aktivitäten nutzen können.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
75 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in appendix literature as part of prior reporting on proxy-related abuse.
Associated botnet referenced as integrating proxy plugins and contributing infected devices into the broader residential proxy ecosystem discussed in the article.
An Android TV-focused botnet with infrastructure similar to Popa, mentioned as a comparable residential proxy/botnet ecosystem in prior disruption efforts.
Malware cited as one of the infection sources used to compromise Android devices that became part of the NetNut residential proxy network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.