Proprietary · · 614 days
Off-brand Android devices shipped BADBOX
BADBOX and BADBOX 2.0 turned off-brand AOSP devices into fraud nodes, with many devices preinfected before consumers connected them.
BADBOX is a device supply-chain problem, not just another malicious app. HUMAN described off-brand, uncertified Android Open Source Project devices that arrived backdoored and joined fraud infrastructure once powered on.
BADBOX 2.0 expanded the operation. HUMAN, Google, Trend Micro, Shadowserver, and other partners found up to 10 million infected devices across connected TVs, TV boxes, tablets, projectors, and other AOSP products. Google later described the affected hardware as uncertified AOSP devices, not Android TV OS or Play Protect certified devices.
The monetization was industrial. The devices were used for ad fraud, click fraud, proxyjacking, and botnet services. HUMAN also found parallel delivery through infected apps from unofficial stores, so this record tracks only the preinfected device path and leaves app-only infections out of scope.
Vo1d is related in shape but weaker as a supply-chain record. Dr.Web found it in system storage on many Android TV boxes, but public reporting leaves the infection vector open: exploitation, unofficial firmware, or another path. BADBOX has clearer preinfection evidence and is the canonical record here.
Appendix · Affected releases
- HUMAN described more than one million infected devices in BADBOX 2.0 and said many were preinfected; some infections also came from unofficial-app delivery.
- The affected device population included connected TV devices, TV boxes, tablets, projectors, car infotainment systems, and other uncertified AOSP devices.
References
- HUMAN Exposes BADBOX 2.0 Scheme Infecting 1 Million Off-Brand Android Open Source Project Deviceshumansecurity.com
- BADBOX 2.0: The sequel no one wantedhumansecurity.com
- We're taking legal action against the BadBox 2.0 botnetblog.google
- Google Sues Operators of 10M-Device Badbox 2.0 Botnetsecurityweek.com
- Who Operates the Badbox 2.0 Botnet?krebsonsecurity.com
- FBI: Badbox 2.0 Android malware infects consumer devicesbleepingcomputer.com
Source record: proprietary/badbox/meta.yaml