Germany's Federal Office for Information Security (BSI) disrupted the BadBox malware operation by sinkholing command-and-control DNS traffic from more than 30,000 infected Android-based IoT devices sold in the country. The malware was found preinstalled in device firmware, particularly on internet-connected products such as digital picture frames, media players, and streaming devices, with officials warning that additional categories may also be affected, including smartphones and tablets. BSI said the compromised devices often run outdated Android versions and old firmware, increasing exposure to further botnet activity beyond BadBox.
Authorities said BadBox can steal data, capture two-factor authentication codes, download additional malware, create email and messaging accounts for disinformation campaigns, commit ad fraud, and turn devices into residential proxies for criminal abuse. Internet service providers are expected to notify affected owners, and BSI advised consumers to disconnect suspected devices and consider returning or discarding them because the firmware itself cannot be trusted. Google said the impacted off-brand products were not Play Protect-certified Android devices.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
BSI said internet providers would notify affected customers and urged owners to disconnect suspected devices immediately. Because the malware was embedded in firmware, the agency warned the devices should not be trusted and recommended returning or discarding them.
BSI said it disrupted communications between up to 30,000 BadBox-infected devices in Germany and attacker-controlled infrastructure by redirecting the malware's traffic to sinkhole servers under Section 7c of the BSI Act. The action prevented infected devices from receiving commands and exfiltrating data while the measure remained active.
On 12 December 2024, Germany's Federal Office for Information Security warned that internet-connected IoT devices, especially digital picture frames and media players, were being sold with BadBox malware preinstalled and outdated Android versions.
Google later stated that the compromised off-brand devices were not Play Protect certified Android devices and therefore lacked recorded Android security and compatibility test results.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.