The BadBox malware botnet has been disrupted again with the removal of 24 malicious apps from Google Play and the downing of communications for half a million infected Android devices
See also: New polyglot malware hits aviation and satellite communications companies

The BadBox botnet is a cyber fraud operation that primarily targets low-cost Android-based devices, such as TV streaming boxes, tablets, smart TVs, and smartphones.
These devices are either preloaded with the BadBox malware by the manufacturer or have been infected by malicious apps or firmware.
The malware then turns the devices into residential proxies, creates fake ad impressions on the infected devices, redirects users to low-quality domains as part of fraudulent traffic distribution operations, and uses individuals' IPs to create fake accounts and perform credential stuffing attacks.
See also: BackConnect malware links Black Basta and Cactus ransomware
Last December, German authorities stopped the malware from infecting devices in the country. However, a few days later, BitSight reported that the BadBox malware had been found on at least 192,000 devices , showing resilience to law enforcement efforts

Since then, it is estimated that the botnet has grown to over 1,000,000 infections, affecting Android devices in 222 countries, with the most being in Brazil (37.6%), the United States (18.2%), Mexico (6.3%), and Argentina (5.3%).
HUMAN ’s Satori Threat Intelligence team led the latest takedown operation in collaboration with Google, Trend Micro , The Shadowserver Foundation, and other partners. Due to the sudden increase in the size of the malware botnet, HUMAN is now calling it “ BadBox 2.0 ,” indicating a new era in its operation.
See also: Phishing: Fake CAPTCHAs deliver Lumma malware
Malware protection is very important for the security of your devices and data. Here are some basic steps you can take to protect yourself:
- Software Updates
- Antivirus Software
- Avoid Unknown Sources
- Email Protection
- Backups
- Strong Passwords
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
