Target Industry

Indiscriminate, opportunistic targeting.

Overview

Over a million Android devices have been compromised by a large-scale botnet operation known as BadBox 2.0. Initially discovered in 2023, the botnet involves low-cost Android devices with backdoored firmware, including smartphones, CTV boxes, and tablets. The malware on these devices integrated them into a network called Peachpit, which was designed to generate fake ad interactions. This could result in the threat actors fraudulently earning money from advertisers. 

Impact

The devices targeted are typically products that are not from well-known or reputable manufacturers. They include cheap, lesser-known Android hardware such as phones, TV boxes, tablets, and digital projectors. BadBox 2.0 targets these devices because they may have weaker security measures and are more susceptible to being compromised through supplychain interventions or by downloading malicious apps from third-party app stores. 

Exploitation

The malware is often pre-installed on devices via supply chain interventions, meaning it is embedded in the device’s firmware before it even reaches the consumer. Additionally, the malware can be disguised as legitimate apps and distributed through third-party app stores, tricking users into downloading it.  

BadBox 2.0 engages in fraudulent activities such as programmatic ad fraud, click fraud, and creating residential proxy nodes using infected devices. It also facilitates account takeovers, fake account creation, credential theft, sensitive information exfiltration, and Distributed Denial of-Service (DDoS) attacks which are frequently executed by secondary threat actors. They utilise residential proxy services, which route their malicious traffic through compromised devices, making it harder to trace the source of the attack. Allowing them to overwhelm targeted servers or networks with a flood of traffic, causing disruption and potential downtime. 

Containment, Mitigations & Remediations

For mitigation against BadBox 2.0, it is recommended to shut down command-and-control (C2) servers, monitoring suspicious Android traffic, and alerting companies to ad fraud. Additionally, educating users about the risks of using off-brand hardware and third-party app stores can help prevent the spread of such malware. These proactive measures are crucial in enhancing overall security and resilience against cyber threats. 

Threat Landscape

This can pose a massive threat as there are so many off-brand android devices. And with the widespread nature of these devices, combined with their typically weaker security measures, it makes them particularly vulnerable to such exploitation. There is the added risk that the botnet’s operators can remotely load and execute any code they choose on the infected devices. As a result, the devices are open to a wide range of malicious activities beyond the initial purpose of the botnet.  

Threat Group

BadBox 2.0 is linked to four major cybercriminal groups, each with specific roles. SalesTracker Group managed the C2 infrastructure and distributed the malware, while MoYu Group developed the BadBox 2.0 backdoor and operated the botnets. It is unknown where SalesTracker Group and MoYu Group carry out their operations. 

The Lemon Group focused on residential proxy services and ad fraud, using infected devices for fraudulent traffic. The Lemon group is believed to be based in Chinese. LongTV, a Malaysia-based company, had apps linked to hidden ad fraud campaigns. The four groups have a shared infrastructure to maximise their financial gain. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content