botnet – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 09 Jun 2025 01:20:01 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 botnet – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Cybercriminals target smart homes as BadBox 2.0 botnet spreads globally https://earlybirdsinvest.com/cybercriminals-target-smart-homes-as-badbox-2-0-botnet-spreads-globally/ https://earlybirdsinvest.com/cybercriminals-target-smart-homes-as-badbox-2-0-botnet-spreads-globally/#respond Mon, 09 Jun 2025 01:20:01 +0000 https://earlybirdsinvest.com/cybercriminals-target-smart-homes-as-badbox-2-0-botnet-spreads-globally/

A hot potato: The resurgence of BadBox 2.0 poses new risks that consumers should be aware of. As unregulated, low-cost IoT devices become increasingly common in households around the world, it’s essential to understand the potential dangers they present.

A new wave of cyberattacks is targeting household technology, as the FBI has issued a warning about the resurgence of the BadBox 2.0 botnet. This sophisticated network of compromised Internet of Things devices is being exploited by cybercriminals to infiltrate home networks on a massive scale, raising fresh concerns about the security of everyday smart devices. The campaign’s global footprint spans more than 220 countries and territories, with infections reported in everything from budget streaming boxes to uncertified digital photo frames.

The original BadBox operation first came to light in 2023, when security researchers discovered that certain Android-based devices – primarily off-brand, low-cost gadgets not certified by Google Play Protect – were being sold with malware embedded directly in their firmware. These devices, often manufactured in China and shipped worldwide, included streaming boxes, digital projectors, and even vehicle infotainment systems.

While the initial BadBox campaign was partially disrupted in 2024 through coordinated action by cybersecurity firms, tech companies, and international law enforcement (including a joint operation between German authorities and Google), the threat quickly adapted. The botnet evolved to bypass many of the countermeasures deployed against it, signaling a dangerous new phase in IoT-focused cybercrime.

BadBox 2.0, the latest iteration of the botnet, has proven even more insidious than its predecessor. While the original version primarily infected devices during manufacturing, BadBox 2.0 can compromise hardware both at the factory and after it reaches consumers. Devices may arrive with firmware-level backdoors already installed or become infected during initial setup if users download apps from unofficial marketplaces.

Security analysts have identified at least four interconnected groups behind the botnet – SalesTracker, MoYu, Lemon, and LongTV – each specializing in a different phase of the operation, from malware distribution to monetizing stolen data.

Once a device is compromised, it becomes part of a sprawling botnet. Cybercriminals use these infected endpoints as residential proxies, allowing them to route illicit activity through home networks and obscure their true origins. In addition to facilitating ad fraud and DDoS attacks, the botnet enables credential stuffing to hijack online accounts, intercepts one-time passwords for financial fraud, and deploys malicious code to further expand its network. The malware’s ability to execute arbitrary commands gives attackers the flexibility to repurpose infected devices for virtually any cybercriminal goal.

The roots of BadBox trace back to earlier malware such as Triada, a sophisticated Android Trojan first discovered in 2016. Triada was known for deeply embedding itself into systems and evading detection. Over the years, its tactics have evolved into the modern supply chain attacks seen in BadBox and BadBox 2.0. This lineage helps explain the botnet’s resilience and adaptability, built on nearly a decade of development and refinement.

Detecting a BadBox 2.0 infection is difficult for most consumers. The malware typically operates silently, with few obvious symptoms. Subtle signs may include the appearance of unfamiliar app stores, unexplained device overheating, or sudden changes to network settings. The FBI warns that devices advertising free access to premium content or marketed as “unlocked” pose a particularly high risk.

If a device is suspected of being infected, users should isolate it from the internet immediately, review all connected devices for unauthorized apps or activity, and consider performing a full reset or replacing the hardware.

To minimize risk, experts recommend:

  • Purchasing devices certified by Google Play Protect.
  • Avoiding uncertified or off-brand hardware.
  • Keeping firmware and apps updated.
  • Monitoring home network traffic for anomalies.
  • Checking security bulletins for compromised model lists and known indicators of compromise.
]]>
https://earlybirdsinvest.com/cybercriminals-target-smart-homes-as-badbox-2-0-botnet-spreads-globally/feed/ 0 40944
Vo1d malware botnet grows to 1.6 million Android TVs worldwide https://earlybirdsinvest.com/vo1d-malware-botnet-grows-to-1-6-million-android-tvs-worldwide/ https://earlybirdsinvest.com/vo1d-malware-botnet-grows-to-1-6-million-android-tvs-worldwide/#respond Thu, 27 Feb 2025 23:28:34 +0000 https://earlybirdsinvest.com/vo1d-malware-botnet-grows-to-1-6-million-android-tvs-worldwide/

Android

A new variant of the Vo1d malware botnet has grown to 1,590,299 infected Android TV devices across 226 countries, recruiting devices as part of anonymous proxy server networks.

This is according to an investigation by Xlab, which has been tracking the new campaign since last November, reporting that the botnet peaked on January 14, 2025, and currently has 800,000 active bots.

In September 2024, Dr. Web antivirus researchers found 1.3 million devices across 200 countries compromised by Vo1d malware via an unknown infection vector.

XLab’s recent report indicates that the new version of the Vo1d botnet continues its operations on a larger scale, not deterred by the previous exposure.

Moreover, the researchers underline that the botnet has evolved with advanced encryption (RSA + custom XXTEA), resilient DGA-powered infrastructure, and enhanced stealth capabilities.

Vo1d botnet size over time
Vo1d botnet size over time
Source: XLab

Massive botnet size

The Vo1d botnet is one of the largest seen in recent years, surpassing Bigpanzi, the original Mirai operation, and the botnet responsible for a record-breaking 5.6 Tbps DDoS attack handled by Cloudflare last year.

As of February 2025, nearly 25% of the infections impact Brazilian users, followed by devices in South Africa (13.6%), Indonesia (10.5%), Argentina (5.3%), Thailand (3.4%), and China (3.1%).

The researchers report that the botnet has had notable infection surges, like going from 3,900 to 217,000 bots in India within just three days.

The largest fluctuations suggest that the botnet operators may be “renting” devices as proxy servers, which are commonly used to conduct further illegal activity or botting.

“We speculate that the phenomenon of “rapid surges followed by sharp declines” may be attributed to Vo1d leasing its botnet infrastructure in specific regions to other groups. Here’s how this “rental-return” cycle could work:

Leasing Phase:

At the start of a lease, bots are diverted from the main Vo1d network to serve the lessee’s operations. This diversion causes a sudden drop in Vo1d’s infection count as the bots are temporarily removed from its active pool.

Return Phase:

Once the lease period ends, the bots rejoin the Vo1d network. This reintegration leads to a rapid spike in infection counts as the bots become active again under Vo1d’s control.

This cyclical mechanism of “leasing and returning” could explain the observed fluctuations in Vo1d’s scale at specific time points.”

❖ Xlab

The scale of its command and control (C2) infrastructure is also impressive, with the operation using 32 domain generation algorithm (DGA) seeds to produce over 21,000 C2 domains.

C2 communication is protected by a 2048-bit RSA key, so even if researchers identify and register a C2 domain, they are not able to issue commands to the bots.

Most impacted countries
Most impacted countries as of February 25
Source: XLab

Vo1d capabilities

The Vo1d botnet is a multi-purpose cybercrime tool that turns compromised devices into proxy servers to facilitate illegal operations.

Infected devices relay malicious traffic for the cybercriminals, hiding the origin of their activity and blending in with residential network traffic. This also helps the threat actors bypass regional restrictions, security filtering, and other protections.

Another function of Vo1d is ad fraud, faking user interactions by simulating clicks on ads or views on video platforms to generate revenue for fraudulent advertisers.

The malware has specific plugins that automate ad interactions and simulate human-like browsing behavior, as well as the Mzmess SDK, which distributes fraud tasks to different bots.

Given that the infection chain remains unknown, it is recommended that Android TV users follow a holistic security approach to mitigate the Vo1d threat.

The first step is buying devices from reputable vendors and trustworthy resellers to minimize the likelihood of malware being pre-loaded from the factory or while in transit.

Secondly, it’s crucially important to install firmware and security updates that close gaps that may be leveraged for remote infections.

Thirdly, users should avoid downloading apps outside of Google Play or third-party firmware images that promise extended and “unlocked” functionality.

Android TV devices should have their remote access features disabled if not needed, while taking them offline when not used is also an effective strategy. 

Ultimately, IoT devices should be isolated from valuable devices that hold sensitive data on the network level.

]]>
https://earlybirdsinvest.com/vo1d-malware-botnet-grows-to-1-6-million-android-tvs-worldwide/feed/ 0 22307