A sophisticated ad fraud and residential proxy scheme dubbed BADBOX 2.0 has been uncovered, involving at least four distinct but cooperative threat actors. According to research from HUMAN Satori Threat Intelligence team, in collaboration with Google, Trend Micro, and Shadowserver, this operation represents the largest botnet of infected connected TV (CTV) devices ever discovered.
## The Threat Actors
The cybercrime ecosystem includes four main groups:
– SalesTracker Group
– MoYu Group
– Lemon Group
– LongTV
## How BADBOX 2.0 Works
The operation begins with backdoors installed on low-cost consumer devices, enabling remote loading of fraud modules. Threat actors compromise devices through:
– Hardware supply chain vulnerabilities
– Third-party marketplaces
– Seemingly benign applications containing hidden “loader” functionality
Once infected, devices become part of a botnet used for:
– Programmatic ad fraud and click fraud
– Hidden WebViews generating fake ad revenue
– Traffic routing through compromised devices
– Account takeover attempts
– Fake account creation
– Malware distribution
– DDoS attacks
## Scope of the Infection
Approximately one million devices have been compromised, primarily:
– Inexpensive Android tablets
– Connected TV boxes
– Digital projectors
– Car infotainment systems
All affected devices are manufactured in mainland China and distributed globally, with highest infection rates in Brazil (37.6%), United States (18.2%), Mexico (6.3%), and Argentina (5.3%).
## The Malware Component
The core backdoor, codenamed BB2DOOR, is based on the Triada Android malware and propagates through:
1. Pre-installed components
2. Remote server fetches during first boot
3. Over 200 trojanized versions of popular apps from third-party stores
The MoYu Group is believed to be responsible for this component, while other groups manage different aspects of the operation.
## Disruption Efforts
Authorities have partially disrupted the operation by:
– Sinkholing BADBOX 2.0 domains
– Google removing 24 malicious apps from the Play Store
– German government taking down infrastructure in December 2024
Google noted that infected devices are primarily Android Open Source Project devices without Play Protect certification, highlighting the security risks of uncertified devices.
The sophisticated nature of BADBOX 2.0, with its ability to execute any cyber attack developed by threat actors, represents a significant evolution in malware capabilities targeting consumer devices.
