BADBOX

Malware type
trojan, spyware
Family
Malware family
Last IoC activity
2026-06-04 15:58:50
Profile updated
2026-07-07 14:04:20

Targeted industries: retail-and-hospitality technology-and-telecommunications

Context

According to BitSight, BADBOX is a large-scale cybercriminal operation selling off-brand Android TV boxes, smartphones, and other Android electronics with preinstalled malware.

Related threat objects

  • BadBox (infrastructure)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Badbox (report)
  • humansecurity.com — Satori Threat Intelligence Disruption Badbox 2 0 (report)
  • krebsonsecurity.com — Who Operates The Badbox 2 0 Botnet (report)
  • bleepingcomputer.com — Android Tv Box On Amazon Came Pre Installed With Malware (report)
  • bitsight.com — Badbox Botnet Back (report)
  • ic3.gov — Psa250605 (report)
  • github.com — T95 H616 Malware (report)
  • bleepingcomputer.com — Germany Blocks Badbox Malware Loaded On 30 000 Android Devices (report)
  • xdaforums.com — Owner Of An Android Tv Box May Want To Check If Its An Active Botnet Member.4519567 (report)
  • censys.com — Unpacking The Badbox Botnet (report)
  • badbox2serviceofprocess.com (report)
  • bleepingcomputer.com — Badbox Malware Botnet Infects 192 000 Android Devices Despite Disruption (report)

External references