Target Industry
Indiscriminate, opportunistic targeting.
Overview
Over a million Android devices have been compromised by a large-scale botnet operation known as BadBox 2.0. Initially discovered in 2023, the botnet involves low-cost Android devices with backdoored firmware, including smartphones, CTV boxes, and tablets. The malware on these devices integrated them into a network called Peachpit, which was designed to generate fake ad interactions. This could result in the threat actors fraudulently earning money from advertisers.
Impact
The devices targeted are typically products that are not from well-known or reputable manufacturers. They include cheap, lesser-known Android hardware such as phones, TV boxes, tablets, and digital projectors. BadBox 2.0 targets these devices because they may have weaker security measures and are more susceptible to being compromised through supply–chain interventions or by downloading malicious apps from third-party app stores.
Exploitation
The malware is often pre-installed on devices via supply chain interventions, meaning it is embedded in the device’s firmware before it even reaches the consumer. Additionally, the malware can be disguised as legitimate apps and distributed through third-party app stores, tricking users into downloading it.
BadBox 2.0 engages in fraudulent activities such as programmatic ad fraud, click fraud, and creating residential proxy nodes using infected devices. It also facilitates account takeovers, fake account creation, credential theft, sensitive information exfiltration, and Distributed Denial of-Service (DDoS) attacks which are frequently executed by secondary threat actors. They utilise residential proxy services, which route their malicious traffic through compromised devices, making it harder to trace the source of the attack. Allowing them to overwhelm targeted servers or networks with a flood of traffic, causing disruption and potential downtime.
Containment, Mitigations & Remediations
For mitigation against BadBox 2.0, it is recommended to shut down command-and-control (C2) servers, monitoring suspicious Android traffic, and alerting companies to ad fraud. Additionally, educating users about the risks of using off-brand hardware and third-party app stores can help prevent the spread of such malware. These proactive measures are crucial in enhancing overall security and resilience against cyber threats.
Threat Landscape
This can pose a massive threat as there are so many off-brand android devices. And with the widespread nature of these devices, combined with their typically weaker security measures, it makes them particularly vulnerable to such exploitation. There is the added risk that the botnet’s operators can remotely load and execute any code they choose on the infected devices. As a result, the devices are open to a wide range of malicious activities beyond the initial purpose of the botnet.
Threat Group
BadBox 2.0 is linked to four major cybercriminal groups, each with specific roles. SalesTracker Group managed the C2 infrastructure and distributed the malware, while MoYu Group developed the BadBox 2.0 backdoor and operated the botnets. It is unknown where SalesTracker Group and MoYu Group carry out their operations.
The Lemon Group focused on residential proxy services and ad fraud, using infected devices for fraudulent traffic. The Lemon group is believed to be based in Chinese. LongTV, a Malaysia-based company, had apps linked to hidden ad fraud campaigns. The four groups have a shared infrastructure to maximise their financial gain.
Further Information













