BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0
BadBox 2.0 is an Android malware and botnet ecosystem centered on consumer devices that are compromised before or shortly after purchase, especially low-cost TV streaming boxes, Android TV devices, tablets, projectors, and related embedded consumer hardware.
Profile source: Mallory opens in a new tabBADBOX 2.0
Family profile
BadBox 2.0 is an Android malware and botnet ecosystem centered on consumer devices that are compromised before or shortly after purchase, especially low-cost TV streaming boxes, Android TV devices, tablets, projectors, and related embedded consumer hardware. It has been widely characterized as a large-scale operation affecting millions of devices and is notable for firmware-level or supply-chain compromise, in which malicious components are embedded in device software images or bundled applications. Some infections also occur through trojanized applications installed during setup or afterward.
The malware is used to conscript devices into a botnet and residential proxy infrastructure without meaningful user awareness or consent. Infected devices can relay third-party traffic through the victim’s residential connection, supporting downstream criminal use while masking attacker origin behind legitimate household IP space. BadBox 2.0 has also been associated with ad fraud activity, including monetization schemes that abuse compromised devices as an ad fraud engine in parallel with proxy operations. Public reporting further links the ecosystem to plugin-based proxy functionality and overlap with other Android botnet and proxy frameworks, including Vo1d and Popa/NetNut.
BadBox 2.0 primarily targets Android-based consumer electronics, with particular concentration in uncertified or off-brand devices lacking strong platform protections. Multiple reports describe the malware as embedded in firmware or preloaded system components, making remediation difficult or impossible for end users and allowing execution with elevated privileges. This placement enables persistent compromise and continued enrollment of devices into criminal infrastructure even after normal user actions such as app removal or factory reset attempts.
The ecosystem has been linked to broader abuse of hijacked consumer devices for proxy resale, fraud operations, and incorporation into larger botnet activity. Industry and law-enforcement actions have targeted operators associated with BadBox 2.0, and public reporting has described legal and technical disruption efforts by Google, HUMAN Security, Trend Micro, and the FBI. The campaign has been repeatedly cited as a prominent example of Android supply-chain compromise affecting consumer-grade connected devices at scale.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
Reported operators
Threat actors
5 named in public reportingBADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."
MITRE ATT&CK