30,000 infected devices: how Germany neutralized the BadBox malware!

Share:

The German authorities have managed to disrupt the activity of the cybercriminals behind the BadBox malware! This is malware that comes pre-installed on Android devices. Let’s take a look at this threat.

  • The BadBox malware: what is it used for?
  • BSI’s action in Germany
  • Which devices are infected?
  • How do I avoid buying an infected device?

The BadBox malware: what is it used for?

The BadBox malware is designed for Android. It is directly integrated into the firmware and it has been used to infect different devices such as digital photo frames, media players, and even some smartphones and tablets. It cannot be ruled out that it is also present on other types of devices (Smart TVs, Android boxes, surveillance cameras, etc.).

When a BadBox-infected device connects to the internet for the first time, the malware directly attempts to establish a connection with the attackers’ C2 (command and control) server. From there, hackers can interact with that device.

EzoicBadBox aims to steal data from the infected device, while also allowing attackers to deploy other malware or remotely access the network to which the device is connected. According to the German Federal Office for Information Security (BSI), this malware is capable of stealing MFA authentication codes and clicking on ads in the background to generate revenue.

In addition, BadBox would allow the infected device to be used as a proxy, allowing attackers to use the victim’s internet connection to perform illegal actions more discreetly.

BSI’s action in Germany

The German agency BSI managed to block communication between the devices infected by BadBox and the hackers’ C2 server infrastructure. To do this, they used the mechanism called “DNS sinkhole” in order to hijack DNS requests.

EzoicThis way, infected devices communicate with police-controlled servers, rather than those controlled by attackers. As a result, attackers no longer receive the data stolen by the malware.

Which devices are infected?

The report published by the BSI mentions 30,000 devices infected by BadBox, in Germany alone. At the global level, this number must be much higher. In addition, in His report, the BSI says: “International reports suggest that smartphones and tablets can also be infected devices.

What is certain is that the owners of devices affected by this DNS sinkholing operation will be notified by their Internet service provider based on their IP address. Then, it will remain to identify the problematic equipment at home. Once this is done, the recommendation of the German authorities is clear: “The BSI therefore considers the number of unreported cases to be very high and requests that the corresponding devices be disconnected from the internet or no longer be used.

How do I avoid buying an infected device?

Devices offered by little-known brands or at a very attractive price are more likely to be infected by malware. There may not be the same controls, especially in terms of security.

EzoicMoreover, on this subject, Google has provided additional information to the BleepingComputer website: “These devices of another brand whose infection was discovered were not Play Protect certified Android devices. If a device isn’t Play Protect certified, Google doesn’t have the results of the security and compatibility tests.

Play Protect certified Android devices undergo extensive testing to ensure their quality and user safety. To help you check if a device is built with Android TV OS and Play Protect certified, our Android TV website provides the most up-to-date list of partners. You can also proceed as follows to check if your device is Play Protect certified.

This isn’t the first time malware has been preloaded on Android devices. We remember in particular a case involving multiple Android TV boxes infected with malware.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:51 am, Jan 15, 2025
weather icon 9°C
L: 9° | H: 10°
overcast clouds
Humidity: 92 %
Pressure: 1035 mb
Wind: 3 mph WNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:59 am
Sunset: 4:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
9° | 10°°C 0 mm 0% 3 mph 98 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 9°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Fri Jan 17 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 4 mph 93 % 1036 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 3 mph 89 % 1033 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 89 % 1024 mb 0 mm/h
Today 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 2 mph 92 % 1034 mb 0 mm/h
Today 3:00 pm
weather icon
9° | 9°°C 0 mm 0% 3 mph 91 % 1034 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 8°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 98 % 1034 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 95 % 1033 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€94,123.07
0.32%
Ethereum(ETH)
€3,116.50
-0.52%
XRP(XRP)
€2.74
8.96%
Tether(USDT)
€0.97
-0.01%
Solana(SOL)
€181.93
-0.30%
Dogecoin(DOGE)
€0.344627
0.97%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000020
-1.13%
Pepe(PEPE)
€0.000016
-1.54%
Peanut the Squirrel(PNUT)
€0.54
-9.04%
Scroll to Top