Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

IoT Security

Botnet of 190,000 BadBox-Infected Android Devices Discovered

Bitsight has discovered a BadBox botnet consisting of over 190,000 Android devices, mainly Yandex smart TVs and Hisense smartphones.

More than 190,000 Android devices have been observed connecting to newly uncovered BadBox botnet infrastructure, cybersecurity firm Bitsight reports.

The sinkholing of a BadBox domain has revealed that most of the infected devices are unique models not seen before, such as Yandex 4K QLED smart TVs and Hisense T963 smartphones, with Russia, China, India, Belarus, Brazil, and Ukraine affected the most.

Initially detailed in October 2023, the BadBox malware comes pre-installed on the firmware of low-cost Android-based devices, including TV boxes, smartphones, and other products, likely through a supply chain compromise.

Last year, Human Security identified over 70,000 infected devices being abused for various types of fraud and which could be turned into residential proxies. Last week, Germany’s cybersecurity agency found 30,000 BadBox bots after sinkholing the communication with a command-and-control (C&C) server.

Now, Bitsight warns of a new widespread BadBox infection involving more than 100,000 unique IPs associated with Yandex 4K QLED smart TVs, pointing out that this is the first time numerous high-end Android devices have been seen communicating with a BadBox C&C server.

Overall, the cybersecurity firm observed more than 160,000 unique IPs communicating daily with the server, with 98% of the traffic coming from Yandex smart TVs and Hisense T963 smartphones.

Advertisement. Scroll to continue reading.

“BadBox exploits devices for activities such as residential proxying (using backdoored devices as exit points), remote code installation, account abuse, and ad fraud. One of its most dangerous features is the ability to install additional code/modules without the user’s consent, enabling threat actors to deploy new schemes,” Bitsight says.

According to the cybersecurity firm, the out-of-the-box BadBox infections suggest either that manufacturers could be involved, allowing remote attackers to install malicious code, or that the infection is performed during the development, manufacturing, shipping, and/or sales stages.

“We cannot determine if these vectors are mutually exclusive in the case of BadBox,” Bitsight says, pointing out that it is crucial for consumers and enterprises to choose trusted brands and partners to keep their data and devices protected.

Related: Germany Sinkholes Botnet of 30,000 BadBox-Infected Devices

Related: Juniper Warns of Mirai Botnet Targeting Session Smart Routers

Related: Lots and Lots of Bots: Looking at Botnet Activity in 2021

Related: What Makes an Effective Anti-Bot Solution?

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.