BadBox 2.0 is a large-scale Android malware and botnet ecosystem centered on supply-chain compromise and trojanized applications, primarily affecting low-cost consumer devices such as Android TV boxes, streaming devices, tablets, digital projectors, and related smart hardware. The malware has been observed preinstalled on devices before sale or introduced during initial setup through malicious or modified applications, giving operators persistent control very early in the device lifecycle. In many cases it runs with elevated or root-level privileges, making remediation difficult and allowing the compromise to survive ordinary user actions.
The malware is associated with multiple monetization and abuse models. Documented capabilities include silently installing additional applications, ad fraud through hidden ad loading and click activity, use of infected devices as residential proxy or relay nodes, and enrollment of devices into broader botnet infrastructure. Infected systems can be rented or otherwise leveraged by downstream actors for masking malicious traffic, phishing support, credential attacks, scraping, and denial-of-service activity. Public reporting also describes overlap between BadBox 2.0 and broader Android proxy ecosystems, including plugin relationships with networks linked to Vo1d and Popa/NetNut, indicating that compromised devices may be repurposed across interconnected criminal services.
BadBox 2.0 has been described as one of the largest botnets affecting connected TV and Android-based consumer devices, with estimates ranging into the millions of compromised systems and some reporting citing more than 10 million affected devices. The campaign has been tied especially to inexpensive, off-brand, or uncertified Android hardware lacking strong platform protections and reliable update support. Targeting is opportunistic and global rather than sector-specific, but the impact extends to households, schools, and enterprises when compromised devices are introduced into trusted networks.
The ecosystem has been publicly linked to ad fraud operations, proxy-for-hire services, and broader criminal infrastructure. Industry and law-enforcement actions have disrupted portions of the operation, and legal action has been taken against alleged operators, but reporting indicates these efforts have degraded rather than fully eliminated the threat. BadBox 2.0 remains a notable example of Android supply-chain malware that blends firmware or preload compromise, botnet functionality, and proxy monetization at scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
or “infecting the device as it downloads required applications that contain backdoors, usually during the setup process,”
...haittaohjelman takaovi sijaitsee laiteohjelmistossa, jota ei voi kirjoittaa uudelleen ilman valmistajan erillisiä toimenpiteitä.
We conducted an investigation, discovering a new version of the BADBOX backdoor, preloaded on the device. This backdoor is a multi-level loader embedded in a malicious native library, librescache.so, which was loaded by the system framework. As a result, a copy of the Trojan infiltrated every process running on the device.
Toisin kuin monissa muissa haittaohjelmissa, BadBox 2.0 toimii laitteen juuritason oikeuksilla, mikä tekee sen poistamisesta käytännössä mahdotonta ilman erikoistoimenpiteitä.
We conducted an investigation, discovering a new version of the BADBOX backdoor, preloaded on the device. This backdoor is a multi-level loader embedded in a malicious native library, librescache.so, which was loaded by the system framework. As a result, a copy of the Trojan infiltrated every process running on the device.
Once contacted, the Popa plugin retrieves the address of an operational backend server of the form s####.backend_domain and then establishes communications, typically observed over TCP port 6000.
Because the infected devices have access to the internet, the hackers can harness the botnet as a proxy service, creating a launching pad for other cybercriminal activities
Popa is an architecture designed to enroll devices so that they can later participate in a residential proxy network... Once enrolled, a device can act as a relay or exit node, allowing third parties to route their traffic through what appears to be a normal residential Internet connection.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
67 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated botnet referenced as integrating proxy plugins and contributing infected devices into the broader residential proxy ecosystem discussed in the article.
An Android TV-focused botnet with infrastructure similar to Popa, mentioned as a comparable residential proxy/botnet ecosystem in prior disruption efforts.
Malware cited as one of the infection sources used to compromise Android devices that became part of the NetNut residential proxy network.
Android-based botnet, largely composed of compromised TV boxes, mentioned as overlapping partially with the Popa/NetNut network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.