s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.badbox

📛 Threat Title

Malware family: BADBOX

Category: BADBOX First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.badbox`. Printable name: BADBOX.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.badbox VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.badbox

IOC database

Type
domain
Value
apk.badbox
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.badbox

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.badbox

References (1)

Remediations (9)

  • web:blog.google

    The Badbox 2.0 botnet compromised over 10 million uncertified devices running Android's open-source software (Android Open Source Project), which lacks Google's security protections. Cybercriminals infected these devices with pre-installed malware and exploited them to conduct large-scale ad fraud and other digital crimes.

  • web:cybersecsentinel.com

    Overview BADBOX 2.0 is a critical evolution of a previously disrupted Android malware campaign, now representing a global cybercrime threat. First identified in 2023 and rapidly evolving post-disruption in late 2024, this campaign has infected over one million Android-based devices globally. Leveraging deep supply chain compromises and widespread distribution through malicious apps and drive ...

  • web:dailysecurityreview.com

    The BadBox malware , a notorious Android botnet, has been disrupted by cybersecurity experts, impacting over 500,000 infected devices globally. This operation involved the removal of 24 malicious applications from Google Play and sinkholing communications of the botnet.

  • web:thehackernews.com

    BADBOX 2.0 botnet infects 1M+ Android devices for ad fraud, proxy abuse, and cybercrime, leveraging pre-installed malware and trojanized apps

  • web:www.fbi.gov

    The FBI is warning the public about cyber criminals exploiting Internet of Things (IoT)1 devices connected to home networks to conduct criminal activity using the BADBOX 2.0 botnet2.

  • web:www.ic3.gov

    The BADBOX 2.0 botnet consists of millions of infected devices and maintains numerous backdoors to proxy services that cyber criminal actors exploit by either selling or providing free access to compromised home networks to be used for various criminal activity.

  • web:www.malwarebytes.com

    Removing 24 malicious apps from the Google Play store and silencing some servers almost halved a botnet known as BadBox . The BadBox botnet focuses on Android devices, but not just phones. It also affects other devices like TV streaming boxes, tablets, and smart TVs. The German BSI (Federal Office for Information Security) started the disruption campaign in December by blocking the malware on ...

  • web:www.ncsc.gov.ie

    Coordinated awareness and remediation efforts across all levels - individual, commercial, and national -are essential to limit the reach and impact of persistent and evolving malware ecosystems.

  • web:www.pointwild.com

    Introduction A dangerous malware family known as BADBOX 2.0 has been flagged by the FBI as a global cybersecurity threat. This Android-based malware infiltrates cheap IoT devices—such as smart TVs, streaming boxes, tablets, and IoT gadgets—turning them into malicious proxies and part of a residential proxy botnet used for criminal operations. Over 1 million devices […]

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.