• News/
  • https://www.bleepingcomputer.com/news/security/badbox-malware-disrupted-on-500k-infected-android-devices/

BadBox malware disrupted on 500K infected Android devices

BleepingComputer
·
Bill Toulas
·
Published Mar 5, 2025
·
Updated

The BadBox Android malware botnet has been disrupted again by removing 24 malicious apps from Google Play and sinkholing communications for half a million infected devices. The BadBox botnet is a cyber-fraud operation targeting primarily low-cost Android-based devices like TV streaming boxes, tablets, smart TVs, and smartphones. These devices either come pre-loaded with the BadBox malware from the manufacturer or are infected by malicious apps or firmware downloads. The malware then turns the devices into residential proxies, generates fake ad impressions on the infected devices, redirects users to low-quality domains as part of fraudulent traffic distribution operations, and uses people's IPs to create fake accounts and perform credential stuffing attacks. Last December, German authorities disrupted the malware for infected devices in the country. However, a few days later, BitSight reported that the malware had been found in at least 192,000 devices, showing resilience against law enforcement action. Since then, it is estimated that the botnet has grown to over 1,000,000 infections, impacting Android devices in 222 countries, with most located in Brazil (37.6%), the United States (18.2%), Mexico (6.3%), and Argentina (5.3%). HUMAN's Satori Threat Intelligence team led the latest disruption operation in collaboration with Google, Trend Micro, The Shadowserver Foundation, and other partners. Due to the botnet's sudden size inflation, HUMAN now calls it 'BadBox 2.0,' indicati...

Read full article

Affected Software

4 affected components
Google Google Play
Seekiny Studio Earn Extra Income
Seekiny Studio Pregnancy Ovulation Calculator
Google Play
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main focus of the article?

The article discusses the disruption of the BadBox malware botnet affecting 500,000 Android devices.

2

What actions were taken against the BadBox malware?

Authorities removed 24 malicious apps from Google Play and sinkholed the communications of the infected devices.

3

Who is primarily targeted by the BadBox malware?

The BadBox malware primarily targets low-income individuals.

4

Which applications from Google Play were associated with the BadBox malware?

The malware was associated with apps such as 'Earn Extra Income' and 'Pregnancy Ovulation Calculator' from Seekiny Studio.

5

What is the impact of the BadBox malware disruption?

The disruption aims to protect users by preventing further infections and fraudulent activities linked to the botnet.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203