What is BADBOX 2.0?

BADBOX 2.0 is a network of Android devices infected with malware installed before the user ever buys them. It's not a virus you download by accident: according to research by HUMAN Security (Satori Threat Intelligence team), it's the largest botnet of infected connected TV (CTV) devices ever uncovered, and a much larger continuation of an original 2023 campaign that had already been partially disrupted.

It mainly affects TV boxes, tablets, digital projectors, and other generic "off-brand" Android devices running the Android Open Source Project (AOSP) without Google certification — most manufactured in China and sold at low prices worldwide.

The scale of the problem, in real numbers

How it gets installed: 3 distinct methods

What makes BADBOX 2.0 particularly hard to eradicate is that Satori researchers identified three distinct infection paths, not just one1:

  1. Pre-installed at the factory: the backdoor ships inside the device's firmware image before it ever leaves the production line. The user never installed anything — the device arrives infected inside the box.
  2. Triggered by a command-and-control (C2) server: the device contacts an external server the moment it's first powered on, which orchestrates the backdoor's installation remotely.
  3. Installed as an app from an unofficial marketplace: the user, without knowing it, installs an app from an alternative store that contains the backdoor.

This variety of methods is exactly why a traditional Play Store antivirus isn't enough: the malware can live in the firmware itself, with system-level privileges, before any security app ever gets a chance to scan anything.

What it actually does to your device

BADBOX 2.0 isn't a single type of attack — it's a platform running several fraud schemes in parallel1,5:

Have a generic TV box and don't know if it's affected? AMK scans it free in minutes.

Scan my device

Why doesn't a regular antivirus see it?

Because it lives in system components with privileges a Play Store antivirus never gets to touch. Infected devices are typically not certified by Google's Play Protect — a certification that requires, among other things, that the device "ship without pre-installed malware" and receive recent security updates6. A device without that certification has none of those guarantees, and the average user has no way to know just by looking at the box.

Is it still active?

Yes. HUMAN Security published its disruption research in 2025, and as early as March of that year, The Register reported the network had grown back after an initial disruption attempt, with another million compromised devices7. The nature of the infection (firmware + C2 + alternative-marketplace apps) means a single legal or technical action isn't enough to eliminate it entirely — the malware keeps reappearing in new batches of cheap hardware.

What you can do

If you have a generic TV box, without a recognized brand, bought cheap, or that promised unlimited free streaming, it's a reasonable candidate for this type of infection. AMK compares your device's actual system against a threat catalog built from this same kind of field research, and applies the correct cleanup method for your specific brand and model — without you needing to know anything about technology.

Scanning is free. You only pay if we find a real threat.

Scan my device for free