Massive Cybercrime Ring: BADBOX 2.0 Botnet Hijacks 1 Million Android Devices in Sophisticated Ad Fraud Scheme


# BADBOX 2.0: Inside the Largest CTV Botnet Operation

A sophisticated ad fraud and residential proxy scheme dubbed BADBOX 2.0 has been uncovered, involving at least four distinct but cooperative threat actors. According to research from HUMAN Satori Threat Intelligence team, in collaboration with Google, Trend Micro, and Shadowserver, this operation represents the largest botnet of infected connected TV (CTV) devices ever discovered.

## The Threat Actors

The cybercrime ecosystem includes four main groups:
– SalesTracker Group
– MoYu Group
– Lemon Group
– LongTV

## How BADBOX 2.0 Works

The operation begins with backdoors installed on low-cost consumer devices, enabling remote loading of fraud modules. Threat actors compromise devices through:
– Hardware supply chain vulnerabilities
– Third-party marketplaces
– Seemingly benign applications containing hidden “loader” functionality

Once infected, devices become part of a botnet used for:
– Programmatic ad fraud and click fraud
– Hidden WebViews generating fake ad revenue
– Traffic routing through compromised devices
– Account takeover attempts
– Fake account creation
– Malware distribution
– DDoS attacks

## Scope of the Infection

Approximately one million devices have been compromised, primarily:
– Inexpensive Android tablets
– Connected TV boxes
– Digital projectors
– Car infotainment systems

All affected devices are manufactured in mainland China and distributed globally, with highest infection rates in Brazil (37.6%), United States (18.2%), Mexico (6.3%), and Argentina (5.3%).

## The Malware Component

The core backdoor, codenamed BB2DOOR, is based on the Triada Android malware and propagates through:
1. Pre-installed components
2. Remote server fetches during first boot
3. Over 200 trojanized versions of popular apps from third-party stores

The MoYu Group is believed to be responsible for this component, while other groups manage different aspects of the operation.

## Disruption Efforts

Authorities have partially disrupted the operation by:
– Sinkholing BADBOX 2.0 domains
– Google removing 24 malicious apps from the Play Store
– German government taking down infrastructure in December 2024

Google noted that infected devices are primarily Android Open Source Project devices without Play Protect certification, highlighting the security risks of uncertified devices.

The sophisticated nature of BADBOX 2.0, with its ability to execute any cyber attack developed by threat actors, represents a significant evolution in malware capabilities targeting consumer devices.

Share This Article