30,000 infected devices: how Germany neutralized the BadBox malware!

Teilen:

The German authorities have managed to disrupt the activity of the cybercriminals behind the BadBox malware! This is malware that comes pre-installed on Android devices. Let’s take a look at this threat.

  • The BadBox malware: what is it used for?
  • BSI’s action in Germany
  • Which devices are infected?
  • How do I avoid buying an infected device?

The BadBox malware: what is it used for?

The BadBox malware is designed for Android. It is directly integrated into the firmware and it has been used to infect different devices such as digital photo frames, media players, and even some smartphones und tablets. It cannot be ruled out that it is also present on other types of devices (Smart TVs, Android boxes, surveillance cameras, etc.).

When a BadBox-infected device connects to the internet for the first time, the malware directly attempts to establish a connection with the attackers’ C2 (command and control) server. From there, hackers can interact with that device.

EzoicBadBox aims to steal data from the infected device, while also allowing attackers to deploy other malware oder remotely access the network to which the device is connected. According to the German Federal Office for Information Security (BSI), this malware is capable of stealing MFA authentication codes und clicking on ads in the background to generate revenue.

In addition, BadBox would allow the infected device to be used as a proxy, allowing attackers to use the victim’s internet connection to perform illegal actions more discreetly.

BSI’s action in Germany

The German agency BSI managed to block communication between the devices infected by BadBox and the hackers’ C2 server infrastructure. To do this, they used the mechanism called “DNS sinkhole” in order to hijack DNS requests.

EzoicThis way, infected devices communicate with police-controlled servers, rather than those controlled by attackers. As a result, attackers no longer receive the data stolen by the malware.

Which devices are infected?

The report published by the BSI mentions 30,000 devices infected by BadBox, in Germany alone. At the global level, this number must be much higher. In addition, in His report, the BSI says: “International reports suggest that smartphones and tablets can also be infected devices.

What is certain is that the owners of devices affected by this DNS sinkholing operation will be notified by their Internet service provider based on their IP address. Then, it will remain to identify the problematic equipment at home. Once this is done, the recommendation of the German authorities is clear: “The BSI therefore considers the number of unreported cases to be very high and requests that the corresponding devices be disconnected from the internet or no longer be used.

How do I avoid buying an infected device?

Devices offered by little-known brands or at a very attractive price are more likely to be infected by malware. There may not be the same controls, especially in terms of security.

EzoicMoreover, on this subject, Google has provided additional information to the BleepingComputer website: “These devices of another brand whose infection was discovered were not Play Protect certified Android devices. If a device isn’t Play Protect certified, Google doesn’t have the results of the security and compatibility tests.

Play Protect certified Android devices undergo extensive testing to ensure their quality and user safety. To help you check if a device is built with Android TV OS and Play Protect certified, our Android TV website provides the most up-to-date list of partners. You can also proceed as follows to check if your device is Play Protect certified.

This isn’t the first time malware has been preloaded on Android devices. We remember in particular a case involving multiple Android TV boxes infected with malware.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
17:00 Uhr, März 27, 2025
Wetter-Symbol 14°C
L: 14° | H: 14°
klarer Himmel
Luftfeuchtigkeit: 65 %
Druck: 1017 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 6%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:46 am
Sonnenuntergang: 6:24 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
10° | 13°°C 0 mm 0% 7 mph 81 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 13°°C 0.38 mm 38% 13 mph 86 % 1016 mb 0 mm/h
Sa. März 29 9:00 pm
Wetter-Symbol
4° | 13°°C 0 mm 0% 9 mph 78 % 1022 mb 0 mm/h
So. März 30 9:00 pm
Wetter-Symbol
8° | 17°°C 0 mm 0% 11 mph 93 % 1025 mb 0 mm/h
Mo. März 31 9:00 pm
Wetter-Symbol
8° | 15°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 66 % 1017 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 81 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 7 mph 85 % 1015 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 8 mph 84 % 1013 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 9 mph 86 % 1012 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
10° | 10°°C 0.28 mm 28% 9 mph 85 % 1011 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
13° | 13°°C 0.38 mm 38% 12 mph 49 % 1012 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 13 mph 42 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€80,735.37
0.41%
Ethereum(ETH)
€1,862.79
-0.34%
Fesseln(USDT)
€0.93
-0.02%
XRP(XRP)
€2.18
-2.31%
Solana(SOL)
€128.25
-0.86%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.177448
-2.74%
Shiba Inu(SHIB)
€0.000013
-2.99%
Pepe(PEPE)
€0.000008
-1.79%
Peanut das Eichhörnchen(PNUT)
€0.213778
7.85%
Nach oben scrollen