Researchers and independent analysts linked a large Android supply-chain botnet known as BADBOX to preinfected TV boxes, smart TVs, and some smartphones, with malware embedded in firmware or silently installed through privileged system components. Reports described more than 190,000 compromised devices, including low-cost Android TV boxes built on AllWinner and RockChip platforms as well as higher-profile products such as Yandex 4K QLED TVs and the Hisense/Instawall T963. The malware survives factory resets, contacts command-and-control servers at boot, uploads device identifiers and telemetry, and can fetch secondary payloads used for ad fraud, account abuse, remote code installation, and residential proxying.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-09, Nokia Deepfield ERT observed the TigerTV IPTV app family retrieving staged BADBOX 2.0 payload configuration over the network and recovered a plaintext t1 module descriptor for MoYu’s zhima residential-proxy component. The analysis showed the apps acted as clean delivery vehicles, dynamically loading com.miyc.transfer.Client from a downloaded JAR to turn Android TV devices into outbound residential proxy exit nodes.
In June 2026, researchers identified a BADBOX-linked malware campaign targeting Android-based automotive head units using DoFun software, abusing the TWCore firmware auto-update mechanism to install the JarService dropper and ultimately the zhima residential-proxy module. Kaspersky attributed the activity to MoYu Group based on code traits and overlapping infrastructure, and said the vendor was notified and fixed the identified issues.
In February 2025, Censys reported that pivoting on a distinctive BADBOX TLS certificate identified five IP addresses and 25 domains likely tied to the botnet. The infrastructure also shared the same SSH host key, supporting the assessment that a single actor or small group operated a templated environment.
In December 2024, Bitsight reported new telemetry showing more than 192,000 BADBOX-infected devices and over 160,000 unique IPs contacting BADBOX infrastructure daily. The report said the operation had expanded beyond low-cost TV boxes into devices such as Yandex 4K QLED smart TVs and the Hisense/Instawall T963 smartphone.
In October 2023, HUMAN’s Satori Threat Intelligence and Research Team published a report on BADBOX and PEACHPIT that corroborated earlier findings. This is cited as a major public reporting milestone in the BADBOX story.
A June 2023 public analysis described preinstalled malware in T95, T95Max, X12-Plus, and X88-Pro-10 Android TV boxes built on AllWinner H616/H618 and RockChip RK3328 platforms. The report detailed system_server hooking, staged payload delivery, and command-and-control domains including ycxrl.com and cbphe.com.
On 2023-05-04, the domain adc.flyermobi.com and IP address 128.199.97.77 were reported offline. These were described as Stage 1/Stage 2 infrastructure used by the Android TV box malware.
On 2023-04-24, Akamai/Linode reportedly terminated remaining command-and-control servers associated with the infected Android TV box malware after abuse complaints and public pressure. The report says the botnet infrastructure went dark temporarily afterward.
In April 2023, researcher Daniel Milisic observed suspicious communications from a T95 Android TV box he had purchased, helping bring BADBOX to light. The traffic was tied to preinstalled compromise on the device.
Bitsight reported sinkholing a BADBOX domain and observing more than 160,000 unique IPs in a 24-hour period. The sinkhole traffic included BADBOX-like POST requests to /terminal/client/apiInfo and /terminal/client/register.
German authorities recently disrupted an operation affecting 30,000 BADBOX devices. Bitsight said this action did not materially change its telemetry outside Germany, indicating the botnet remained active.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 113 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
kaspersky.ru
Open sourcegithub.com
Open sourcecensys.com
Open sourcebitsight.com
Open sourcegithub.com
Open sourcexdaforums.com
Open sourcevb2020.vblocalhost.com
Open sourcehumansecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.