• News/
  • https://www.zdnet.com/article/newly-discovered-android-malware-has-infected-thousands-of-devices/

Newly discovered Android malware has infected thousands of devices

Jack Wallen
·
Published Oct 9, 2023
·
Updated

I'm not one to mince words or make you wait for the payoff, so I'll get right to the point. If you've purchased a T95 (or similar knockoff) streaming box that runs Android, chances are that your unit was shipped with pre-installed malware. But this isn't your ordinary piece of malware. Instead, we're looking at the possibility of two different Trojans: Badbox and Peachpit, both of which are pretty nasty bits of code. Also: Android 14 may have quietly fixed two major issues on the Google Pixel 6 and 7 One only needs to look at the extent of Badbox's spread, which has hit over 74,000 Android devices worldwide. But Badbox isn't just your average malware. Instead, we're looking at a rather complex, interconnected series of fraud schemes. Essentially, Badbox is a collection of firmware back doors that are installed via the regular hardware supply chain. Those devices get distributed into homes. Once booted and connected to a network, those devices immediately connect to what's called a command-and-control server, where they then receive their instructions. Badbox works with ad fraud, residential proxy services, fake email and messaging accounts, and the installation of malicious code. Peachpit is the ad fraud component of Badbox and can immediately start serving up ads for low-quality apps that, upon installation, will infect your devices with malicious code. This sort of attack has been around for years but they've grown more and more sophisticated. This time around, the cybercri...

Read full article

Affected Software

8 affected components
Android T95
Android T95Z
Android T95MAX
Android X88
Android Q9
Android X12PLUS
Android MXQ Pro 5G
Android J5-W
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered Android malware that has infected thousands of devices, particularly focusing on certain streaming boxes.

2

What Android devices are affected by this malware?

The malware has infected several models including T95, T95Z, T95MAX, X88, Q9, X12PLUS, MXQ Pro 5G, and J5-W.

3

What security implications are discussed in the article?

The article highlights the risks of using infected devices, such as unauthorized access to personal information and potential data breaches.

4

How was the malware distributed according to the article?

The malware was shipped pre-installed on certain streaming boxes that run the Android operating system.

5

What should users do if they have an affected device?

Users are advised to check their devices for malware, remove any unrecognized applications, and consider resetting the device to factory settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203