BADBOX is an Android-focused botnet and cybercriminal malware ecosystem first identified in 2023. It compromises consumer devices, including smartphones, tablets, connected televisions, streaming boxes, digital picture frames, projectors, and aftermarket vehicle infotainment systems. Its original operation relied on firmware backdoors installed before purchase through the hardware supply chain. Infected devices contact command-and-control infrastructure on first boot and receive instructions to activate malicious services or install additional code.
The original BADBOX backdoor is based on Triada and modifies core Android runtime components, injecting malicious code into process memory. Its residence in a read-only firmware partition makes removal difficult and allows compromise to persist beyond ordinary application removal. Supported abuses include advertising fraud, residential proxy services, covert creation of email and messaging accounts, interception of SMS-based one-time passwords, data theft, and unauthorized installation of additional malware. Its residential proxy functionality routes third-party traffic through victims’ internet connections, which operators commercially offer for criminal abuse. PEACHPIT, an associated advertising-fraud component, generates hidden advertising impressions and clicks through WebViews while spoofing application, referrer, and device information.
German authorities disrupted BADBOX command-and-control communications in December 2024. The subsequent BADBOX 2.0 operation compromised more than one million Android-based devices, using both preinstalled malware and backdoored applications downloaded during device setup from unofficial marketplaces. The operation primarily affects consumer hardware and home networks, although infected products have also appeared on school networks.
MoYu Group is associated with the BADBOX ecosystem. In 2026, a related campaign attributed to this group abused the legitimate TWCore updater on DoFun Android automotive head units to install JarService and additional payloads. That separate multistage infection chain supported advertising fraud and deployed the zhima reverse-proxy module, extending the associated proxy-botnet activity into vehicle infotainment systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky researchers tied the JarService infections to a familiar foe: the MoYu Group, which was also behind the notorious BadBox botnet.
Kaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet.
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors exploited a vulnerability in a system designed to handle software updates, enabling them to deliver malware to vehicle head units
The attackers compromised the update distribution channel to deliver stealthy malicious Android applications that served as droppers, loaders, clickers, and reverse-proxy loaders.
Le malware est distribué via TWCore ( com.tw.core ), une application système légitime responsable des mises à jour du firmware. TWCore reçoit des instructions via un broker MQTT hébergé sur cardoor[.]cn , qui lui ordonne de télécharger et d’installer des APK malveillants.
copy — sets the contents of the clipboard, optionally pulling in extra data from a link
Stage three checks in with a remote server every 90 minutes... then waits for commands from the attackers’ server. ... http — sends a request to a server and can save the response
Kaspersky researchers have observed only commands to download a reverse proxy module, suggesting that the main goal is to ensnare devices in a proxy botnet.
Stage 3 – Clicker / Reverse proxy loader : ... télécharge et exécute le module zhima (proxy inversé).
Only loadlib2 and http were seen in use, with loadlib2 pulling down zhima, the reverse proxy module... This confirms that the attackers’ ultimate goal is building a proxy botnet.
171 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
92 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android-device botnet operation cited as an example of large-scale IoT compromise, with many affected devices reportedly infected before reaching buyers.
Android-device botnet associated with proxy activity and click fraud that has rebounded from takedown efforts. Its revamped BadBox 2.0 variant infected aftermarket vehicle infotainment systems, smart TVs, digital projectors, and other consumer IoT devices. Human Security described suspected supply-chain infections involving firmware images containing the BadBox backdoor. The article connects BadBox to JarService through their shared operator, but does not identify BadBox as a JarService payload.
Android-focused botnet malware linked to fraud and proxy-botnet activity. In this case, attackers compromised a software update distribution channel for car head units to deliver malicious Android apps acting as droppers, loaders, clickers, and reverse-proxy loaders. The malware can display ads, conduct ad fraud, download additional components, and appears primarily aimed at enrolling devices into a proxy botnet.
Malicious platform/botnet referenced as linked to the MoYu-attributed activity behind the Android head-unit malware campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.