The BadBox Android malware botnet has been disrupted again by removing 24 malicious apps from Google Play and sinkholing communications for half a million infected devices. The BadBox botnet is a cyber-fraud operation targeting primarily low-cost Android-based devices like TV streaming boxes, tablets, smart TVs, and smartphones. These devices either come pre-loaded with the BadBox malware from the manufacturer or are infected by malicious apps or firmware downloads. The malware then turns the devices into residential proxies, generates fake ad impressions on the infected devices, redirects users to low-quality domains as part of fraudulent traffic distribution operations, and uses people's IPs to create fake accounts and perform credential stuffing attacks. Last December, German authorities disrupted the malware for infected devices in the country. However, a few days later, BitSight reported that the malware had been found in at least 192,000 devices, showing resilience against law enforcement action. Since then, it is estimated that the botnet has grown to over 1,000,000 infections, impacting Android devices in 222 countries, with most located in Brazil (37.6%), the United States (18.2%), Mexico (6.3%), and Argentina (5.3%). HUMAN's Satori Threat Intelligence team led the latest disruption operation in collaboration with Google, Trend Micro, The Shadowserver Foundation, and other partners. Due to the botnet's sudden size inflation, HUMAN now calls it 'BadBox 2.0,' indicati...
BadBox malware disrupted on 500K infected Android devices
BleepingComputer
·Bill Toulas
·Published Mar 5, 2025
·Updated
Affected Software
4 affected components
Google Google Play
Seekiny Studio Earn Extra Income
Seekiny Studio Pregnancy Ovulation Calculator
Google Play
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses the disruption of the BadBox malware botnet affecting 500,000 Android devices.
2
What actions were taken against the BadBox malware?
Authorities removed 24 malicious apps from Google Play and sinkholed the communications of the infected devices.
3
Who is primarily targeted by the BadBox malware?
The BadBox malware primarily targets low-income individuals.
4
Which applications from Google Play were associated with the BadBox malware?
The malware was associated with apps such as 'Earn Extra Income' and 'Pregnancy Ovulation Calculator' from Seekiny Studio.
5
What is the impact of the BadBox malware disruption?
The disruption aims to protect users by preventing further infections and fraudulent activities linked to the botnet.