A Canadian security expert has discovered that a specific Android TV box available on Amazon had malware.
The malware was quite advanced and designed to remain on the device forever.
Daniel Milisic, a security researcher at the company, has created a list of instructions to help users remove the malware and prevent it from communicating with a remote server.

The Android TV box found to contain the malware is the T95 model with an AllWinner T616 processor. You'll usually find it on Amazon and AliExpress. It's not certain if this particular device is the only one affected or if all devices of this model or brand have been "infected".
See also: Cisco warns of critical vulnerability in EoL routers

The T95 streaming TV box runs on Android 10 and has a ROM signed with test keys. Additionally, ADB (Android Debug Bridge) is open over both Ethernet and WiFi connections.
This is considered a suspicious setting, as ADB allows unrestricted access to the device’s file system, executing commands, installing software, modifying data, and remote control.
However, since most consumer streaming devices are behind a firewall, threat actors will likely not be able to connect to ADB remotely.
Daniel Milisic originally purchased the device to use with the Pi-hole DNS sinkhole, which is a tool that protects devices from unwanted content, ads, and malicious websites without requiring any software installation.
While analyzing the DNS requests in Pi-hole, Milisic found that the device was trying to connect to several IP addresses associated with active malware. He believes the malware on the device is similar to “CopyCat,” which is a sophisticated Android malware first discovered by tech firm Check Point in 2017 – it had previously appeared in an adware campaign where it infected 14 million Android devices and generated over $1.5 million in profits for its operators.

Milisic ran a test on a malware sample via VirusTotal and found 13 detections out of 61 scans by AV engines.
The malware was classified as an Android trojan downloader.
In a post on GitHub, the analyst explained that he used tools like “tcpflow” and “nethogs” to monitor traffic and located the malware in the specific process/APK, which he then removed from the ROM.
He found several layers of malware, but the last piece he couldn’t detect, injects the ‘system_server’ process and appears to be deeply embedded in the ROM.
He also noticed that the malware was trying to download additional payloads from sites like: ‘ycxrl.com’, ‘cbphe.com’ and ‘cbpheback.com’.
Since finding a clean ROM to replace the infected one was difficult, Milisic decided to change the C2 server to route requests through the Pi-hole browser, which allowed him to block the requests.
See also: Even the US government uses weak passwords
If you own this Android TV box, we recommend that you follow these 2 steps mentioned by Milisic:
Reboot into recovery mode or “Factory reset” from the settings menu.
After rebooting, connect to ADB via USB or WiFi/Ethernet and run the script provided by the analyst. To confirm that the malware has been neutralized, you can run the command “adb logcat | grep Corejava” and make sure command chmod was not executed.
He also recommended that owners stop using these TV boxes, as they are relatively cheap on Amazon, and buy a new one, if they can afford it.
Unfortunately, these low-cost Android TV boxes often follow an unclear path from being manufactured in China to being distributed worldwide.
In many cases, these devices are sold under various brands and names, which makes it difficult to determine their origin. Furthermore, as these devices pass through many hands, sellers and resellers have many opportunities to install custom ROMs, including “maybe” some malicious ones.
Even though most commercial sites have policies to prevent the sale of devices that come pre-installed with malware, it is practically impossible to check all products.
To avoid such risks, we recommend that you choose streaming TV boxes from reputable suppliers.
Source of information: bleepingcomputer.com
