logo
FBI Warning To 10 Million Android Users — Disconnect Your Devices Now

FBI Warning To 10 Million Android Users — Disconnect Your Devices Now

Forbes5 days ago
Discconnect now, FBI warns 10 million Android users.
Update, July 26, 2025: This story, originally published on July 25, has been updated with a statement from the researchers which initially disclosed and disrupted the BadBox 2.0 operation that the FBI and Google are tackling head-on.
In March, I reported that one of the largest botnets of its kind ever detected had impacted over a million Android devices. That massive attack was known as BadBox, but it has now been eclipsed by BadBox 2.0, with at least 10 million Android devices infected. Google has taken action to protect users as best it can, as well as launching legal action against the attackers, and the FBI has urged impacted users to disconnect their devices from the internet. Here's what you need to know.
The FBI, Google And Others Warn Of Android BadBox 2.0 Attacks
The FBI cybersecurity alert, I-060525-PSA, could not have been clearer: ongoing attacks are targeting everything from streaming devices, digital picture frames, third-party aftermarket automobile infotainment systems and other assorted home smart devices. The devices, all low-cost and uncertified, mostly originating in China, allow attackers to access your home network and beyond by, the FBI warned, 'configuring the product with malicious software prior to the user's purchase.' It has also been noted, however, that mandatory 'software updates' during the installation process can also install a malicious backdoor.
Point Wild's Threat Intelligence Lat61 Team reverse-engineered the BadBox 2 infection chain and, as a result, uncovered new indicators of compromise that have been shared with global Computer Emergency Response Teams, as well as law enforcement. 'This Android-based malware is pre-installed in the firmware of low-cost IoT devices, smart TVs, TV boxes, tablets, before they even leave the factory,' Kiran Gaikwad from the LAT61 team said, 'It silently turns them into residential proxy nodes for criminal operations like click fraud, credential stuffing, and covert command and control (C2) routing.'
Google, meanwhile, confirmed in a July 17 statement that it had 'filed a lawsuit in New York federal court against the botnet's perpetrators.' Google also said that it has 'updated Google Play Protect, Android's built-in malware and unwanted software protection, to automatically block BadBox-associated apps.'
Human Security Behind Initial BadBox 2.0 Disclosure And Disruption
Human Security, whose Satori Threat Intelligence and Research Team originally both disclosed and disrupted the BadBox 2.0 threat campaign, said at the time that researchers believed 'several threat actor groups participated in BadBox 2.0, each contributing to parts of the underlying infrastructure or the fraud modules that monetize the infected devices, including programmatic ad fraud, click fraud, proxyjacking, and creating and operating a botnet across 222 countries and territories.' If nothing else, that provides some context to the scale of this campaign.
Now, Stu Solomon, the Human Security CEO, has issued the following statement: 'We applaud Google's decisive action against the cybercriminals behind the BadBox 2.0 botnet our team uncovered. This takedown marks a significant step forward in the ongoing battle to secure the internet from sophisticated fraud operations that hijack devices, steal money, and exploit consumers without their knowledge. Human's mission is to protect the integrity of the digital ecosystem by disrupting cybercrime at scale, and this effort exemplifies the power of collective defense. We're proud to have been deeply involved in this operation, working in close partnership with Google, TrendMicro, and the Shadowserver Foundation. Their collaboration has been invaluable in helping us expose and dismantle this threat.'
FBI Recommendations And Mitigations — Disconnect Your Devices Now
The FBI has recommended that Android users should be on the lookout for a number of potential clues that your Chinese-manufactured smart device could be infected with BadBox 2.0 malware.
When it comes to mitigation, the advice is straightforward: users should 'consider disconnecting suspicious devices from their networks,' the FBI said.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

China summons chip giant Nvidia over alleged security risks
China summons chip giant Nvidia over alleged security risks

Yahoo

time20 minutes ago

  • Yahoo

China summons chip giant Nvidia over alleged security risks

Chinese internet authorities summoned Nvidia on Thursday to discuss "serious security issues" over some of its artificial intelligence (AI) chips, as the US technology giant finds itself entangled in trade tensions between Beijing and Washington. Nvidia is a world-leading producer of AI semiconductors, but the United States effectively restricts which chips it can export to China on national security grounds. A key issue has been Chinese access to the "H20", a less powerful version of Nvidia's AI processing units that the company developed specifically for export to China. The California-based firm said earlier this month that it would resume H20 sales to China after Washington pledged to remove licensing curbs that had halted exports. But the firm still faces obstacles -- US lawmakers have proposed plans to require Nvidia and other manufacturers of advanced AI chips to include built-in location tracking capabilities. And on Thursday, Beijing's top internet regulator said it had summoned Nvidia representatives to discuss recently discovered "serious security issues" involving the H20. The Cyberspace Administration of China said it had asked Nvidia to "explain the security risks of vulnerabilities and backdoors in its H20 chips sold to China and submit relevant supporting materials". The statement posted on social media noted that, according to US experts, location tracking and remote shutdown technologies for Nvidia chips "are already matured". The announcement marked the latest complication for Nvidia in selling its advanced products in the key Chinese market, where it is in increasingly fierce competition with homegrown technology firms. - Nvidia committed - CEO Jensen Huang said during a closely watched visit to Beijing this month that his firm remained committed to serving local customers. Huang said he had been assured during talks with top Chinese officials during the trip that the country was "open and stable". "They want to know that Nvidia continues to invest here, that we are still doing our best to serve the market here," he said. Nvidia this month became the first company to hit $4 trillion in market value -- a new milestone in Wall Street's bet that AI will transform the global economy. New hurdles to the firm's operation in China come as the country's economy wavers, beset by a years-long property sector crisis and heightened trade headwinds under US President Donald Trump. Chinese President Xi Jinping has called for the country to enhance self-reliance in certain areas deemed vital for national security -- including AI and semiconductors -- as tensions with Washington mount. The country's firms have made great strides in recent years, with Huang praising their "super-fast" innovation during his visit to Beijing this month. ll-pfc/mjw/fox Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

China summons Nvidia over backdoor security concerns with AI chips
China summons Nvidia over backdoor security concerns with AI chips

Washington Post

time22 minutes ago

  • Washington Post

China summons Nvidia over backdoor security concerns with AI chips

China's cyberspace regulator said Thursday that it had summoned representatives of U.S. tech giant Nvidia to explain alleged security vulnerability risks involving its highly sought-after H20 artificial intelligence chips. This comes barely two weeks after the Trump administration suddenly reversed its ban and allowed the Silicon Valley company to resume exports of the chips to China, part of broader de-escalation ahead of trade talks.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store