What is BADBOX 2.0?
BADBOX 2.0 is a network of Android devices infected with malware installed before the user ever buys them. It's not a virus you download by accident: according to research by HUMAN Security (Satori Threat Intelligence team), it's the largest botnet of infected connected TV (CTV) devices ever uncovered, and a much larger continuation of an original 2023 campaign that had already been partially disrupted.
It mainly affects TV boxes, tablets, digital projectors, and other generic "off-brand" Android devices running the Android Open Source Project (AOSP) without Google certification — most manufactured in China and sold at low prices worldwide.
The scale of the problem, in real numbers
- Over 1 million devices infected detected worldwide, per Satori's count as of January 20251,2.
- More than a third of infected devices observed by HUMAN are located in Brazil, where low-cost AOSP devices are especially popular. The United States, Mexico, Argentina, and Colombia also rank among the countries with significant numbers1.
- In July 2025, Google filed a federal lawsuit against the network's operators, describing an infection of more than 10 million Android open-source IoT devices3.
- On June 5, 2025, the FBI (via its Internet Crime Complaint Center) released public alert PSA I-060525-PSA, confirming that BADBOX 2.0 had compromised millions of smart-TV boxes, digital projectors, vehicle infotainment systems, digital picture frames, and other IoT devices4.
How it gets installed: 3 distinct methods
What makes BADBOX 2.0 particularly hard to eradicate is that Satori researchers identified three distinct infection paths, not just one1:
- Pre-installed at the factory: the backdoor ships inside the device's firmware image before it ever leaves the production line. The user never installed anything — the device arrives infected inside the box.
- Triggered by a command-and-control (C2) server: the device contacts an external server the moment it's first powered on, which orchestrates the backdoor's installation remotely.
- Installed as an app from an unofficial marketplace: the user, without knowing it, installs an app from an alternative store that contains the backdoor.
This variety of methods is exactly why a traditional Play Store antivirus isn't enough: the malware can live in the firmware itself, with system-level privileges, before any security app ever gets a chance to scan anything.
What it actually does to your device
BADBOX 2.0 isn't a single type of attack — it's a platform running several fraud schemes in parallel1,5:
- Large-scale ad fraud: Satori identified 24 "evil twin" apps with identical decoy versions published on Google Play, used to generate fake clicks and impressions. At its peak, this scheme generated 5 billion fraudulent ad-bid requests per week.
- Password theft: researchers found evidence that the malware captures credentials typed on the infected device.
- Residential proxy: the device resells your home connection's bandwidth to third parties, without your knowledge (see the note below on the real impact on your internet).
Have a generic TV box and don't know if it's affected? AMK scans it free in minutes.
Scan my deviceWhy doesn't a regular antivirus see it?
Because it lives in system components with privileges a Play Store antivirus never gets to touch. Infected devices are typically not certified by Google's Play Protect — a certification that requires, among other things, that the device "ship without pre-installed malware" and receive recent security updates6. A device without that certification has none of those guarantees, and the average user has no way to know just by looking at the box.
Is it still active?
Yes. HUMAN Security published its disruption research in 2025, and as early as March of that year, The Register reported the network had grown back after an initial disruption attempt, with another million compromised devices7. The nature of the infection (firmware + C2 + alternative-marketplace apps) means a single legal or technical action isn't enough to eliminate it entirely — the malware keeps reappearing in new batches of cheap hardware.
What you can do
If you have a generic TV box, without a recognized brand, bought cheap, or that promised unlimited free streaming, it's a reasonable candidate for this type of infection. AMK compares your device's actual system against a threat catalog built from this same kind of field research, and applies the correct cleanup method for your specific brand and model — without you needing to know anything about technology.
Scanning is free. You only pay if we find a real threat.
Scan my device for free