Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

BADBOX Turns 1M+ IoT Devices Into Proxies

June 6, 2025
Reading Time: 2 mins read
in Alerts
Chrome Extensions Leak Data And API Keys

A sophisticated new variant of the BADBOX malware has successfully compromised over one million Android devices across many different continents. The Federal Bureau of Investigation is now warning that this campaign has infected millions of home Internet-connected consumer electronics. This widespread BADBOX botnet is commonly found on many Chinese Android-based smart TVs, various streaming boxes, projectors, and tablets. The campaign represents one of the most significant mobile security breaches of 2025, with active infections reported in 222 countries. The highest concentration of these compromised devices are currently located in Brazil, the United States, Mexico, and also in Argentina.

These various consumer electronic devices often come preloaded with the BADBOX 2.0 malware botnet before they are even purchased by users. They can also become infected after installing certain malicious firmware updates or through various Android applications that sneak onto app stores. The FBI explains that many cybercriminals gain unauthorized access to home networks by configuring the product with malicious software before its sale. Once these compromised Internet of Things devices are connected to home networks, they become part of the botnet’s residential proxy services. These infected devices then connect to the attacker’s command and control servers, where they await commands to execute various malicious activities.

Once under the attacker’s full control, the botnet is then used for several malicious activities, including creating large-scale residential proxy networks. This malware routes internet traffic from other cybercriminals through the victims’ home IP addresses, effectively masking their own malicious online activity. The botnet also regularly performs ad fraud by loading and clicking on advertisements in the background, generating illicit ad revenue for operators. BADBOX 2.0 evolved from the original malware which was first identified in 2023, and despite a German disruption effort, it grew. A recent joint operation has since disrupted over 500,000 infected devices, but the botnet unfortunately continues to expand its global reach.

The most concerning aspect of BADBOX 2.0 lies in its highly sophisticated persistence mechanisms that allow it to survive factory resets. The malware effectively achieves this by exploiting previously unknown vulnerabilities within the standard Android bootloader verification process to install itself deeply. It installs as a persistent system-level service that masquerades as legitimate Android framework components and even creates backup copies of itself. The FBI strongly advises all consumers to assess IoT devices connected to their home networks for any kind of suspicious online activity. Users should never download applications from unofficial marketplaces and always keep all of their various devices updated with the latest security patches.

Reference:

  • Millions Of Android IoT Devices Hijacked By BADBOX 2.0 Malware Botnet
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityJune 2025
ADVERTISEMENT

Related Posts

New Godfather Trojan Hijacks Banking Apps

Winos 4.0 Malware Hits Taiwan Via Tax Phish

June 20, 2025
New Godfather Trojan Hijacks Banking Apps

New Godfather Trojan Hijacks Banking Apps

June 20, 2025
New Godfather Trojan Hijacks Banking Apps

New Amatera Stealer Delivered By ClearFake

June 20, 2025
Fake Invoices Deliver Sorillus RAT In Europe

Fake Minecraft Mods On GitHub Spread Malware

June 19, 2025
Russian Phishing Scam Bypasses Google 2FA

Russian Phishing Scam Bypasses Google 2FA

June 19, 2025
Fake Invoices Deliver Sorillus RAT In Europe

Fake Invoices Deliver Sorillus RAT In Europe

June 19, 2025

Latest Alerts

Winos 4.0 Malware Hits Taiwan Via Tax Phish

New Amatera Stealer Delivered By ClearFake

New Godfather Trojan Hijacks Banking Apps

Fake Minecraft Mods On GitHub Spread Malware

Fake Invoices Deliver Sorillus RAT In Europe

Russian Phishing Scam Bypasses Google 2FA

Subscribe to our newsletter

    Latest Incidents

    Massive Leak Exposes 16 Billion Credentials

    Tonga Health System Down After Ransomware

    Chinese Spies Target Satellite Giant Viasat

    German Dealer Leymann Hacked Closes Stores

    Hacker Mints $27M From Meta Pool Gets 132K

    UBS and Pictet Hit By Vendor Data Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial