BADBOX
- Malware type
- trojan, spyware
- Family
- Malware family
- Last IoC activity
- 2026-06-04 15:58:50
- Profile updated
- 2026-07-07 14:04:20
Targeted industries: retail-and-hospitality technology-and-telecommunications
Context
According to BitSight, BADBOX is a large-scale cybercriminal operation selling off-brand Android TV boxes, smartphones, and other Android electronics with preinstalled malware.
Related threat objects
- BadBox (infrastructure)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Badbox (report)
- humansecurity.com — Satori Threat Intelligence Disruption Badbox 2 0 (report)
- krebsonsecurity.com — Who Operates The Badbox 2 0 Botnet (report)
- bleepingcomputer.com — Android Tv Box On Amazon Came Pre Installed With Malware (report)
- bitsight.com — Badbox Botnet Back (report)
- ic3.gov — Psa250605 (report)
- github.com — T95 H616 Malware (report)
- bleepingcomputer.com — Germany Blocks Badbox Malware Loaded On 30 000 Android Devices (report)
- xdaforums.com — Owner Of An Android Tv Box May Want To Check If Its An Active Botnet Member.4519567 (report)
- censys.com — Unpacking The Badbox Botnet (report)
- badbox2serviceofprocess.com (report)
- bleepingcomputer.com — Badbox Malware Botnet Infects 192 000 Android Devices Despite Disruption (report)