BADBOX is an Android malware and botnet ecosystem associated with large-scale compromise of consumer devices, especially low-cost Android-based products such as TV boxes, tablets, smartphones, smart TVs, digital media devices, picture frames, and aftermarket automotive head units. The operation has been linked to the MoYu Group and is notable for supply-chain-style distribution, including firmware backdoors present before sale, as well as later campaigns that abused legitimate update mechanisms to silently install malicious applications.
BADBOX has been described as a global network of compromised Android devices used for covert monetization and criminal infrastructure. Reported capabilities include downloading and installing additional malware, collecting device and network information, enabling remote tasking, conducting ad fraud and click fraud, and converting infected devices into residential or reverse-proxy nodes that relay third-party traffic. Earlier reporting also tied BADBOX to account abuse and interception of one-time passwords on some infected Android devices. The ecosystem has been associated with proxy services such as PXYEDGE and ProxyForU.
A notable 2026 evolution targeted Android-based DoFun automotive head units through the legitimate TWCore updater path, in what was described as the first documented malware infection chain specifically built for car head units. In that campaign, attackers abused the built-in update workflow to deliver a multi-stage Android malware chain including a dropper known as JarService, a loader, and a final payload that supported ad-fraud activity and deployment of the zhima reverse-proxy module. Observed operator activity primarily involved loading the proxy component, indicating an objective of enrolling devices into a proxy botnet rather than interfering with vehicle control systems.
BADBOX has also been linked to firmware-level compromise resembling Triada-derived backdoor behavior on Android devices, allowing persistence and post-sale activation when devices first connect to the internet. The operation has survived multiple disruption efforts and has been observed at substantial scale, with reporting over time describing tens of thousands to millions of affected devices depending on campaign phase and measurement method. The malware primarily targets Android-based consumer and embedded devices and represents a persistent supply-chain and post-sale abuse threat focused on fraud, proxy monetization, and follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky researchers have come across what appears to be the first malware specifically designed for car head units, and have found links to the notorious BadBox botnet.
Kaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet.
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors exploited a vulnerability in a system designed to handle software updates, enabling them to deliver malware to vehicle head units
The attackers compromised the update distribution channel to deliver stealthy malicious Android applications that served as droppers, loaders, clickers, and reverse-proxy loaders.
Le malware est distribué via TWCore ( com.tw.core ), une application système légitime responsable des mises à jour du firmware. TWCore reçoit des instructions via un broker MQTT hébergé sur cardoor[.]cn , qui lui ordonne de télécharger et d’installer des APK malveillants.
copy — sets the contents of the clipboard, optionally pulling in extra data from a link
Stage three checks in with a remote server every 90 minutes... then waits for commands from the attackers’ server. ... http — sends a request to a server and can save the response
Kaspersky researchers have observed only commands to download a reverse proxy module, suggesting that the main goal is to ensnare devices in a proxy botnet.
Stage 3 – Clicker / Reverse proxy loader : ... télécharge et exécute le module zhima (proxy inversé).
Only loadlib2 and http were seen in use, with loadlib2 pulling down zhima, the reverse proxy module... This confirms that the attackers’ ultimate goal is building a proxy botnet.
171 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
88 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android-focused botnet malware linked to fraud and proxy-botnet activity. In this case, attackers compromised a software update distribution channel for car head units to deliver malicious Android apps acting as droppers, loaders, clickers, and reverse-proxy loaders. The malware can display ads, conduct ad fraud, download additional components, and appears primarily aimed at enrolling devices into a proxy botnet.
Malicious platform/botnet referenced as linked to the MoYu-attributed activity behind the Android head-unit malware campaign.
Android-focused botnet malware operation previously linked to preinstalled malware on consumer devices and later resurfacing as BadBox 2.0 targeting IoT devices including streaming boxes, projectors, picture frames, and aftermarket vehicle infotainment systems.
A botnet associated with compromised consumer devices in the hardware supply chain, used here as context for the actor attribution behind malware targeting Android-based car head units.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.