Off-brand IoT devices are still vulnerable to BadBox botnet, FBI says
FBI警告称,名为BadBox 2.0的恶意软件已感染全球数百万物联网设备,包括电视、投影仪等,形成僵尸网络用于犯罪活动。该软件通过预装或可疑更新传播,已致至少100万台设备感染,建议用户检查并断开可疑设备,定期更新固件以提高安全。 2025-6-6 14:16:26 Author: therecord.media(查看原文) 阅读量:10 收藏

A stubborn malware campaign has now infected millions of connected devices worldwide, and the resulting botnet is being exploited for criminal activity, according to the FBI.

BadBox 2.0 targets internet of things (IoT) hardware such as “TV streaming devices, digital projectors, aftermarket vehicle infotainment systems, digital picture frames and other products,” the bureau’s Internet Crime Complaint Center (IC3) said in an alert this week.

The malware can come pre-installed in off-brand or aftermarket devices, or arrive alongside software updates from sketchy sources, the bureau said. It’s essentially a continuation of the BadBox campaign stifled by German law enforcement in December.  

Analysts at cybersecurity company HUMAN warned about BadBox 2.0 in March, saying at the time that it had infected at least 1 million Android devices, typically manufactured and shipped from China. The original BadBox campaign was only credited with tens of thousands of infections.

The botnet allows cybercriminals to mask their activity by making it appear to come from legitimate home networks. In some cases the operators sell access to the botnet to other cybercriminals, the alert said.

“The public is urged to evaluate IoT devices in their home for any indications of compromise and consider disconnecting suspicious devices from their networks,” the FBI said.

The alert said customers should be wary of using Android devices that come from unfamiliar sources, are sold as unlocked or advertised as for free content. Signs of compromise include the presence of suspicious app marketplaces and requests to disable Google Play Protect security features.

Cybersecurity experts also recommend updating the firmware on IoT devices whenever possible.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/iot-devices-vulnerable-to-badbox-botnet-fbi
如有侵权请联系:admin#unsafe.sh