Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Furthermore, operators built those routines using a customised version of Blockly, a visual programming system commonly used to teach children how to code. Dragging blocks together allowed workers with limited technical knowledge to prepare new advertising campaigns without writing each routine from the beginning.
...бюджетные ТВ-приставки на Android имитируют смартфоны Samsung, Huawei, Xiaomi и Vivo. ... приложения, которые полностью переписывают их аппаратный профиль: управляющий сервер передает им конфигурацию выбранной модели смартфона, а малварь подменяет свойства, способные выдать настоящую плату...
This app ecosystem also sends logs, periodic screenshots, and can even livestream the ‘screen’ back to the C2.
...получив контроль над освободившимся доменом, который использовался операторами кампании для сбора телеметрии и поддержания работы «вшитого» в приставки бэкдора.
The system relies on a set of hardcoded IP addresses and ports for initial contact and to establish persistent WebSocket connections.
Если приставка обнаруживает активное HDMI-подключение, она превращается в SOCKS5-прокси и пропускает чужой трафик через домашний интернет владельца.
When an HDMI cable is connected, the device tends to operate as a residential SOCKS5 proxy, forwarding third-party internet traffic through the owner’s home network.
While a television was in use, the software could operate the box as a SOCKS5 residential proxy. Traffic from customers of a proxy service would then leave through the device owner’s home internet address, making it appear to originate from an ordinary residential connection.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware campaign affecting low-cost Android TV boxes that rewrites device hardware profiles to impersonate smartphones, performs ad fraud, and turns infected devices into SOCKS5 proxies routing third-party traffic through victims’ home internet connections. The devices also contain an embedded backdoor used for telemetry and tasking.
Preinstalled or firmware-embedded Android TV box malware that rewrites device identity to impersonate smartphones, performs automated ad fraud, and turns infected devices into SOCKS5 residential proxies. It can also send logs and screenshots to command servers and livestream the virtual screen through WebRTC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.