SecurityBadbox Botnet Returns: Up to a Million Infected Androids Fuel Ad Fraud

Badbox Botnet Returns: Up to a Million Infected Androids Fuel Ad Fraud

A new variant of the Badbox malware, now dubbed Badbox 2.0, has been detected on up to a million backdoored Android devices—spreading across cheap hardware and third-party app stores to launch massive ad fraud campaigns.

Key Points at a Glance:
  • Badbox 2.0 infects up to a million Android devices, doubling its 2023 reach.
  • The botnet exploits off-brand devices and third-party app stores to spread malware.
  • Fraudulent ad clicks and views are concealed among legitimate traffic.
  • The operation appears orchestrated by multiple criminal groups collaborating.
  • Efforts by security firms and tech giants have already halved the active infections.

Security researchers from Human Security’s Satori team have uncovered a new variant of the notorious Badbox botnet, which now leverages up to a million infected Android devices to perpetrate widespread ad fraud. This resurgence marks a significant escalation from the initial outbreak in 2023, where around 74,000 devices—mainly off-brand internet-connected TV boxes—were compromised.

Badbox 2.0 specifically targets devices running the Android Open Source Project (AOSP). It has been found on cheap off-brand smartphones, additional internet-connected TV boxes, tablets used in vehicles, and even digital projectors. The malware spreads through supply chain manipulations: criminals purchase inexpensive hardware, rebrand it, install the malicious software—often embedded either in the firmware or bundled with popular apps from third-party stores—and then resell the tainted products. More than 200 apps on third-party Android app stores have been identified as “evil twins” of legitimate applications, deceiving users into unwittingly downloading and installing the malware.

Gavin Reid, CISO at Human Security, explained that the botnet’s operators have expanded both the range of targeted devices and the sophistication of their fraud schemes. “The Badbox 2.0 scheme is bigger and far worse than what we saw in 2023 in terms of the types of devices targeted, the number of devices infected, and the complexity of the fraud conducted,” he said.

Once active, the malware directs infected devices to conduct ad fraud by generating fraudulent ad clicks and views—traffic that blends into normal residential internet activity, thereby evading detection by traditional ad fraud prevention systems. The malware even goes as far as stealing passwords entered into compromised hardware. While the botnet could theoretically be used for denial-of-service attacks, its operators seem intent on keeping a low profile to avoid drawing attention.

Collaborative efforts among Human Security, Google, Trend Micro, and the non-profit Shadowserver Foundation have already disrupted the botnet, cutting the number of active infections by about half. However, security experts warn that the perpetrators are likely to adapt their tactics, given that many of the malware modules are currently labeled “test”—suggesting the botnet is still in its nascent stages.

For users, this serves as a stark reminder: buying cheap, off-brand hardware and downloading apps from third-party stores significantly increases the risk of infection. Taking precautions can help avoid becoming an unwitting participant in such large-scale ad fraud networks.

Enjoying our articles?

We don’t have ads, big sponsors, or a paywall. But we have you. If you'd like to help us keep going — buy us a coffee. It’s a small gesture that means a lot. Click here - Thank You!

Jacob Reed
Jacob Reed
A practical analyst specializing in cybersecurity. Delivers technical expertise with clarity and focus.

More from author

More like this

Hidden in Plain Sight with Hexagons

A revolutionary cryptographic system developed in Munich could reshape digital privacy: it proves your location—without revealing it. Discover how hexagons and floating-point math may redefine trust.

Cybersecurity CEO Caught Planting Malware in Hospital Systems

The CEO of a local cybersecurity firm has been arrested for planting malware in a hospital's computer systems, exposing new risks to healthcare cybersecurity.

When Earthquakes Hide Secrets: Seismic Noise and Hidden Explosions

Earthquakes might unintentionally hide underground explosions, complicating global monitoring efforts. New research reveals how seismic noise challenges our ability to detect secret nuclear tests.

FBI Offers $10 Million Bounty for Elusive Salt Typhoon Cybercriminals

The FBI has placed a $10 million bounty on Salt Typhoon cybercriminals linked to state-sponsored attacks on critical infrastructure, intensifying efforts to counter global cyber-espionage threats.

Latest news

Monkey Mayhem on Jicarón Island

On a remote island in Panama, young male capuchins have begun a disturbing new trend: abducting baby howler monkeys. What drives this strange and deadly fad?

Asthma’s Urban Trigger: One in Ten Cases Is Preventable

A sweeping study reveals that smart city planning—more green, less smog—could prevent one in ten asthma cases. Europe’s urban design might hold the key to cleaner lungs.

Cracking Quantum Mysteries with Light and Crystal

A powerful new laser-based imaging technique is making the invisible visible—from quantum fluctuations to real-time breath diagnostics. Discover how EOS could change everything.

Real-Time Clot Watch Could Revolutionize Heart Care

A cutting-edge microscope and AI system developed in Tokyo now tracks clotting activity in real time—paving the way for personalized, noninvasive heart disease care.

The Brain’s Hidden Switchboard for the Senses

Groundbreaking research from Yale reveals that all senses converge in two deep-brain regions tied to consciousness—unlocking new paths for treating focus and awareness disorders.

Hidden in Plain Sight with Hexagons

A revolutionary cryptographic system developed in Munich could reshape digital privacy: it proves your location—without revealing it. Discover how hexagons and floating-point math may redefine trust.

Amazon Forest May Survive Drought—But Not Unscathed

The Amazon may survive long-term drought, but new research shows that its resilience comes at the cost of massive tree loss and a reduced ability to slow climate change.

When the Brain’s Energy Fails: Neurons in Crisis

Leipzig researchers have visualized how neurons lose energy during stroke-like events—and discovered the brain may still have a window to recover if energy can be quickly restored.

NASA’s Europa Probe Just Opened Its Eyes in UV

NASA’s Europa Clipper mission just captured its first ultraviolet light, marking the beginning of a journey to uncover whether Jupiter’s icy moon Europa could support life.

Tropical Soils May Be Turbocharging Global Warming

A new study reveals tropical soils are far more sensitive to warming than expected—releasing ancient carbon and intensifying climate change in ways current models miss.