Finnish authorities warned that some Android smart devices sold to consumers, particularly televisions, TV boxes, and other home-networked endpoints, have been found with BadBox 2.0 malware already present before purchase. The malware has been linked especially to low-cost products from lesser-known manufacturers and can also spread through malicious apps and suspicious websites. Officials said the backdoor may be inserted during the production chain, turning affected devices into covert criminal infrastructure while they continue to appear to function normally.
BadBox 2.0 allows attackers to remotely load additional modules, collect data, and abuse infected devices for operations including botnet activity and denial-of-service attacks. The malware is considered especially hard to detect and effectively impossible for users to remove because the backdoor resides in firmware that cannot be rewritten without manufacturer support. Estonia's Information System Authority reported more than 7,000 infected devices in the country, underscoring the broader supply-chain security problem. Finland's Cyber Security Centre urged consumers to disconnect suspected devices immediately, install official vendor updates if available, and stop using and dispose of devices if the manufacturer does not provide a fix.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The Finnish Cyber Security Centre advised consumers to immediately disconnect suspected devices, install official vendor updates if available, and dispose of devices if no official fix exists. It also urged buyers to avoid cheap, anonymous, or poorly supported products that lack trustworthy security updates.
Finland's Cyber Security Centre warned that some Android smart devices sold on the Finnish consumer market, especially televisions, TV boxes, and other home-networked devices, were found to be infected before purchase. The advisory said the embedded backdoor cannot be removed by users and may allow devices to be abused as part of criminal infrastructure such as botnets.
The Estonian Information System Authority (RIA) reported observing more than 7,000 infected devices in Estonia. This highlighted the scale of the BadBox 2.0 problem and its spread in consumer Android devices.
BadBox 2.0 was identified in multiple incidents involving inexpensive Android devices from lesser-known manufacturers, with malware either preinstalled during manufacturing or later delivered through malicious apps and suspicious websites. The malware enables remote module execution, data collection, and other malicious activity while remaining difficult to detect and remove because the backdoor resides in device firmware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.