Google Takes Legal Action Against Massive Chinese Botnet That Hijacked 10 Million Android Devices


# Google Takes Legal Action Against BADBOX 2.0 Botnet Operators

Google has filed a lawsuit in New York federal court against 25 unnamed individuals and entities in China for operating the BADBOX 2.0 botnet, one of the largest cybercriminal networks ever discovered.

## The Scale of the Attack

The BADBOX 2.0 botnet compromised over 10 million devices running uncertified Android software that lacked Google’s security protections. Cybercriminals infected these devices with pre-installed malware to conduct large-scale advertising fraud and other digital crimes.

First detected in late 2022, BADBOX spreads through Internet of Things (IoT) devices including TV streaming devices, digital projectors, vehicle infotainment systems, and digital picture frames—most manufactured in China. The majority of infections occurred in Brazil, the United States, Mexico, and Argentina.

## How the Botnet Operates

According to HUMAN Security, BADBOX represents the largest botnet of infected connected TV devices ever uncovered. Criminals gain access to home networks through two primary methods:

– Installing malicious software before users purchase the devices
– Infecting devices during setup when they download required applications containing backdoors

The botnet operators then sell access to these compromised home networks to other cybercriminals for various illegal activities.

## Criminal Enterprise Structure

Google’s complaint reveals that BADBOX 2.0 operates as an organized criminal enterprise with specialized groups:

– **Infrastructure Group**: Manages the botnet’s command-and-control systems
– **Backdoor Malware Group**: Develops and installs malware in devices
– **Evil Twin Group**: Creates fake versions of legitimate Google Play Store apps for ad fraud
– **Ad Games Group**: Uses fraudulent games to generate advertisements

## Profit Methods

The criminals profit from Google’s ad network in three ways:
1. Using fake apps to secretly load hidden advertisements
2. Opening hidden web browsers to interact with ads on their game websites
3. Using infected devices to conduct click fraud

Google pays the criminals for these fraudulent ad impressions, unknowingly funding their illegal operations.

## Legal Response

The court issued a preliminary injunction ordering the BADBOX 2.0 operators to immediately cease their botnet operations globally. Third-party internet service providers and domain registries must assist in dismantling the infrastructure by blocking traffic to specified domains.

Google has also updated Google Play Protect to automatically detect and block BADBOX-related applications.

## Industry Impact

Stu Solomon, CEO of HUMAN Security, praised Google’s action as “a significant step forward in the ongoing battle to secure the internet from sophisticated fraud operations that hijack devices, steal money, and exploit consumers without their knowledge.”

This legal action demonstrates the importance of collaboration between technology companies and law enforcement in combating large-scale cyber threats that affect millions of users worldwide.

Share This Article