FBI: BadBox 2.0 Android Malware Warning
- The FBI has issued a warning regarding the BADBOX 2.0 malware campaign, which has compromised more than 1 million Internet-connected devices.
- The BADBOX 2.0 botnet commonly targets Chinese Android-based smart TVs, streaming boxes, projectors, tablets, and other Internet of Things (IoT) devices.
- These devices are either preloaded with the BADBOX 2.0 malware or become infected through firmware updates and malicious Android applications downloaded from Google Play and third-party app stores.
The FBI urgently warns of the BADBOX 2.0 malware campaign, which already infects over one million devices, transforming them into residential proxies for cybercrime. This sophisticated threat primarily targets Chinese Android-based IoT devices, including smart TVs and streaming boxes, frequently enough infected before purchase or through malicious app downloads. Hackers exploit these compromised devices to route malicious traffic, generate fraudulent ad revenue, and launch credential-stuffing attacks. The primarykeyword,BADBOX 2.0 botnet, maintains numerous backdoors, selling access to compromised home networks worldwide. This news comes from News Directory 3.Safeguard your devices against secondarykeyword by downloading apps from trusted sources.Discover what’s next for this rapidly evolving digital threat.
FBI Warns: BADBOX 2.0 Malware Infects Over 1 Million Devices
Updated June 06, 2025
The FBI has issued a warning regarding the BADBOX 2.0 malware campaign, which has compromised more than 1 million Internet-connected devices. This malware converts consumer electronics into residential proxies used for malicious activities, according to the agency.
The BADBOX 2.0 botnet commonly targets Chinese Android-based smart TVs, streaming boxes, projectors, tablets, and other Internet of Things (IoT) devices. The FBI stated that the botnet maintains numerous backdoors to proxy services, which cybercriminals exploit by selling or providing free access to compromised home networks for various criminal activities.
These devices are either preloaded with the BADBOX 2.0 malware or become infected through firmware updates and malicious Android applications downloaded from Google Play and third-party app stores. Cybercriminals gain unauthorized access to home networks by configuring products with malicious software before purchase or infecting devices during the setup process when downloading applications containing backdoors, the FBI explained.
Once infected, these IoT devices connect to the attacker’s command and control (C2) servers, receiving commands to execute malicious activities. These activities include routing malicious traffic through residential IPs to obscure cybercriminal activity, performing background ad fraud to generate revenue, and launching credential-stuffing attacks using stolen login data.
In 2024, Germany’s cybersecurity agency disrupted the botnet by sinkholing communication between infected devices and the attacker’s infrastructure. Though, researchers soon found the malware installed on 192,000 devices a week later, even on mainstream brands like Yandex TVs and Hisense smartphones. By March 2025, HUMAN’s Satori Threat Intelligence reported that over 1 million consumer devices had been infected, leading to the designation BADBOX 2.0 to track this new, larger campaign.
HUMAN noted that the infected devices are Android Open Source Project devices, not Android TV OS devices or Play Protect certified Android devices, manufactured in mainland China and shipped globally. Traffic associated with BADBOX 2.0 has been observed from 222 countries and territories worldwide.
What’s next
Consumers should exercise caution when purchasing low-priced, uncertified Android devices and ensure they download applications only from trusted sources to mitigate the risk of infection from the BADBOX 2.0 malware.
