Skip to content

BADBOX

BADBOX is an Android malware and botnet ecosystem associated with large-scale compromise of consumer devices, especially low-cost Android-based products such as TV boxes, tablets, smartphones, smart TVs, digital media devices, picture frames, and aftermarket automotive head units.

Profile source: Mallory opens in a new tab

BADBOX

Family profile

BADBOX is an Android malware and botnet ecosystem associated with large-scale compromise of consumer devices, especially low-cost Android-based products such as TV boxes, tablets, smartphones, smart TVs, digital media devices, picture frames, and aftermarket automotive head units. The operation has been linked to the MoYu Group and is notable for supply-chain-style distribution, including firmware backdoors present before sale, as well as later campaigns that abused legitimate update mechanisms to silently install malicious applications.

BADBOX has been described as a global network of compromised Android devices used for covert monetization and criminal infrastructure. Reported capabilities include downloading and installing additional malware, collecting device and network information, enabling remote tasking, conducting ad fraud and click fraud, and converting infected devices into residential or reverse-proxy nodes that relay third-party traffic. Earlier reporting also tied BADBOX to account abuse and interception of one-time passwords on some infected Android devices. The ecosystem has been associated with proxy services such as PXYEDGE and ProxyForU.

A notable 2026 evolution targeted Android-based DoFun automotive head units through the legitimate TWCore updater path, in what was described as the first documented malware infection chain specifically built for car head units. In that campaign, attackers abused the built-in update workflow to deliver a multi-stage Android malware chain including a dropper known as JarService, a loader, and a final payload that supported ad-fraud activity and deployment of the zhima reverse-proxy module. Observed operator activity primarily involved loading the proxy component, indicating an objective of enrolling devices into a proxy botnet rather than interfering with vehicle control systems.

BADBOX has also been linked to firmware-level compromise resembling Triada-derived backdoor behavior on Android devices, allowing persistence and post-sale activation when devices first connect to the internet. The operation has survived multiple disruption efforts and has been observed at substantial scale, with reporting over time describing tens of thousands to millions of affected devices depending on campaign phase and measurement method. The malware primarily targets Android-based consumer and embedded devices and represents a persistent supply-chain and post-sale abuse threat focused on fraud, proxy monetization, and follow-on payload delivery.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Spoofing

Reported operators

Threat actors

6 named in public reporting
MoYu Group

Kaspersky researchers have come across what appears to be the first malware specifically designed for car head units, and have found links to the notorious BadBox botnet.

MoYu

Kaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet.

LongTV

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse

Lemon Group

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse

SalesTracker Group

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse

BadBox 2.0 Enterprise

"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."

MITRE ATT&CK

BADBOX in ATT&CK

36 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.