
FBI warns over 1 million Android devices hijacked by malware
Everything that connects to the internet can be hacked by malware.
This includes your phones (both Android and iPhones) and laptops (whether Windows, Mac or even lesser-known systems like Linux). Devices like your Wi-Fi router and security cameras aren't safe either.
But who would have thought hackers are now targeting your smart TVs, streaming boxes, projectors and tablets, too? That's right, the FBI warns that bad actors have hijacked over a million of these devices with malware, turning them into unwitting participants in a global cybercrime network.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide — free when you join.
The FBI is warning that more than a million smart TVs, streaming boxes, projectors and tablets have been infected by a massive malware operation called BadBox 2.0. The malware turns home electronics into participants in a global network of cybercrime, often before the user even powers them on.
In a statement, the FBI says BadBox 2.0 is commonly found on cheap Android-based devices manufactured in mainland China. These include uncertified tablets, connected TV boxes and other Internet of Things hardware. Many of the infected devices ship with the malware preinstalled. Others are compromised during setup, often through malicious firmware updates or sideloaded apps from unofficial marketplaces.
Once infected, the devices connect to a command and control server, allowing hackers to reroute malicious traffic through home networks, load fraudulent ads in the background and carry out credential-stuffing attacks without the user knowing. Essentially, your smart TV could be quietly helping someone break into other people's accounts.
The botnet is primarily used to turn infected devices into residential proxy nodes, providing hackers with anonymous access to real home IP addresses. That means your TV or projector might unknowingly be helping cybercriminals bypass security systems, commit ad fraud or brute-force online accounts while hiding behind your internet connection.
BadBox first appeared in 2023 on generic TV boxes, such as the T95. The original botnet was briefly disrupted in Germany in 2024 when security researchers "sinkholed" the malware's command servers. That wiped out part of the operation, but not for long. Just a week later, the malware reappeared on nearly 200,000 devices, including more recognizable brands like Hisense smartphones and Yandex TVs.
By March 2025, BadBox had evolved into BadBox 2.0, with more than 1 million active infections detected by HUMAN's Satori Threat Intelligence team. The majority of devices are uncertified Android Open Source Project builds. These are not official Android TV OS products and are not protected by Google Play Protect.
Researchers say the malware has been spotted in 222 countries. A significant number of infections are concentrated in Brazil, followed by the United States, Mexico and Argentina.
The FBI, working with Google, Trend Micro, HUMAN and the Shadowserver Foundation, recently disrupted communications between more than 500,000 infected devices and their control servers. However, the botnet continues to grow as more compromised products reach consumers and remain unnoticed.
Symptoms of infection include strange app marketplaces, disabled Play Protect settings or devices advertised as being unlocked or capable of free streaming. Many of these products come from unknown brands and are sold through unofficial sellers. If you have recently purchased a budget Android TV box or projector, especially one that is not certified by Google, you may want to take a closer look.
If you're wondering whether your smart TV, streaming box, projector or tablet could be part of the BadBox 2.0 botnet, here are some warning signs and checks you can do.
1. You bought a low-cost Android-based device from an unknown or no-name brand: Devices sold online through third-party sellers or unknown brands, especially if advertised as "unlocked," "jailbroken" or offering free streaming, are at higher risk. Models like the T95 box or other generic Android TV boxes are known carriers. Specifically, the following devices have been identified as impacted by BadBox malware:
Device model: TV98, X96Q_Max_P, Q96L2, X96Q2, X96mini, S168, ums512_1h10_Natv, X96_S400, X96mini_RP, TX3mini, HY-001, MX10PRO, X96mini_Plus1, LongTV_GN7501E, Xtv77, NETBOX_B68, X96Q_PR01, AV-M9, ADT-3, OCBN, X96MATE_PLUS, KM1, X96Q_PRO, Projector_T6P, X96QPRO-TM, sp7731e_1h10_native, M8SPROW, TV008, X96Mini_5G, Q96MAX, Orbsmart_TR43, Z6, TVBOX, Smart, KM9PRO, A15, Transpeed, KM7, iSinbox, I96, SMART_TV, Fujicom-SmartTV, MXQ9PRO, MBOX, X96Q, isinbox, Mbox, R11, GameBox, KM6, X96Max_Plus2, TV007, Q9 Stick, SP7731E, H6, X88, X98K, TXCZ
2. Your device is not Google-certified: If your Android device doesn't support Google Play Protect or doesn't show the Play Protect certification in the Play Store settings, it's likely running on an uncertified version of Android. That's a major red flag. To check:
3. Suspicious behavior or strange apps: Look for unfamiliar apps you didn't install, apps labeled with foreign characters or alternative app stores on your device. BadBox-infected devices often come with shady apps preloaded.
4. Google Play Protect is disabled: If Play Protect has been turned off without your knowledge or is missing altogether, your device may be vulnerable to compromise.
5. Your home internet is acting strange: If your network is unusually slow or your router shows unknown devices connected, one of your smart devices may be hijacked and rerouting traffic as part of a residential proxy network.
6. The device came with outdated or unofficial firmware: If your device doesn't receive software updates or has a strange update process, that's another potential sign it's not legit or may be compromised.
Want to stay safe? Here are eight practical steps you can take to protect your smart devices from BadBox 2.0 malware and other hidden Android threats.
1. Use strong antivirus software: Protecting your devices starts with powerful antivirus protection. Malware like BadBox 2.0 often comes preinstalled on cheap, uncertified Android devices, infecting them before you even power them on. A trusted antivirus app can help detect hidden threats, block malicious traffic and warn you about suspicious behavior that might otherwise go unnoticed. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
2. Only buy certified and trusted devices: Stick to devices certified by Google or other recognized platforms. Avoid generic or off-brand Android boxes, tablets and projectors, especially if they are advertised as unlocked or include free streaming. Cheap, uncertified devices are more likely to come with malware preinstalled.
3. Avoid sideloading apps from unofficial sources: Do not install apps from third-party app stores or download APK files from unknown websites. These files can contain hidden malware. Use only official app stores like the Google Play Store that scan apps for threats.
4. Check your device settings for tampering: Look for signs like Google Play Protect being turned off, the presence of unfamiliar app stores or suspicious apps running in the background. These are possible signs your device is compromised.
5. Monitor your network for unusual activity: If your internet slows down suddenly, or you notice unknown devices on your Wi-Fi, investigate. Use your router's settings or a network monitoring app to track strange behavior or unauthorized connections.
6. Disconnect and replace suspicious hardware: If a device is behaving oddly or was purchased from an untrusted source, unplug it from your network. Consider replacing it with a product from a reputable brand and a verified seller.
7. Keep your devices and apps updated: Install system and app updates regularly. Even though cheap devices may not always offer updates, keeping your software current reduces your risk. Choose brands that are known for providing reliable security patches.
8. Secure your router and home network: Your devices are only as safe as the network they're connected to. Set a strong, unique password for your Wi-Fi router and update its firmware regularly. Disable remote access unless absolutely necessary and use WPA3 encryption if available. Consider using a password manager to generate and store complex passwords. Get more details about my best expert-reviewed password managers of 2025 here.
As BadBox 2.0 continues to evolve, protecting your entire home network, not just individual devices, has become essential to staying one step ahead of cybercriminals.
It's alarming how something as simple as a budget streaming box or projector could be quietly working for cybercriminals. As smart devices become part of almost everything we do, being a careful and informed consumer matters more than ever. Small steps like buying from trusted brands and avoiding unofficial downloads can make a big difference in keeping your home and personal data safe.
With over a million devices infected, who should be held accountable: manufacturers, governments or consumers? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Follow Kurt on his social channels:
Answers to the most-asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


TechCrunch
9 minutes ago
- TechCrunch
The Robinhood founder who might just revolutionize energy, if he succeeds
Baiju Bhatt is building something the space industry has largely dismissed, and it might be more groundbreaking than anyone realizes. When Baiju Bhatt stepped away from his role as Chief Creative Officer at Robinhood last year, only those close to him could have predicted his next move: launching a space company built around tech that much of the aerospace industry has written off as impractical. That's just fine with Bhatt, co-founder of the trading app that democratized investing for millions – it means less competition for his new company, Aetherflux, which has raised $60 million on its quest to prove that beaming solar power from space isn't science fiction but the next frontier of both renewable energy and national defense. 'Until you do stuff in space, if you happen to be an aerospace company, you're actually an aspiring space company,' Bhatt said on Wednesday night at a TechCrunch StrictlyVC event held in a glass-lined structure on Sand Hill Road in Menlo Park. 'I would like to transition from 'aspiring space company' to 'space company' sooner.' Bhatt's space ambitions date back to his childhood. He says that his dad, who worked as an optometrist in India, spent a decade applying to graduate physics programs in the United States, eventually taking a hard left turn and landing at NASA as a research scientist. He then proceeded to use the powers of reverse psychology on his son, says Bhatt. 'My dad worked at NASA through my whole childhood,' Bhatt said. 'He was very adamant: 'When you grow up, I'm not going to tell you you should study physics.' Which is a very effective way of convincing somebody to do exactly that.' Image Credits:Slava Blazer Photography / TechCrunch Now, at roughly the same age his father was when he joined NASA, Bhatt is making his own move into space, seemingly with an eye toward creating even more impact than at Robinhood. Techcrunch event Save $200+ on your TechCrunch All Stage pass Build smarter. Scale faster. Connect deeper. Join visionaries from Precursor Ventures, NEA, Index Ventures, Underscore VC, and beyond for a day packed with strategies, workshops, and meaningful connections. Save $200+ on your TechCrunch All Stage pass Build smarter. Scale faster. Connect deeper. Join visionaries from Precursor Ventures, NEA, Index Ventures, Underscore VC, and beyond for a day packed with strategies, workshops, and meaningful connections. Boston, MA | REGISTER NOW He's certainly taking a big swing with the effort. Traditional space solar power concepts have focused on massive geostationary satellites the size of small cities, using microwave transmission to beam energy to Earth. The scale and complexity made these projects perpetually '20 years away,' Bhatt said Wednesday night. 'Everything was too big,' Bhatt continued. 'The size of the array, the size of the spacecraft was the size of a small city. That's real science fiction stuff.' His solution is both far smaller and more nimble, he suggested. Most notably, instead of massive microwave antennas that require precise phase coordination, Aetherflux's satellites will use fiber lasers, essentially converting solar power back into focused light that can be precisely targeted at receivers on the ground. 'We take the solar power that we collect from the sun with solar panels, and we take that energy and put it into a set of diodes that turn it back into light,' Bhatt said. 'That light goes into a fiber where there's a laser, which then lets us point that down to the ground.' The idea is to launch a demonstration satellite in June of next year. National security, first While Bhatt envisions eventually building 'a true industrial-scale energy company,' he's starting with national defense – a strategic decision that could give America a significant advantage. The Department of Defense has approved funding for Aetherflux's program, recognizing the military value of beaming power to forward bases without the logistical nightmare of transporting fuel. 'It allows the U.S. to have energy out in the battlefield for deployed bases, and it doesn't have the limitation of needing to transport fuel,' Bhatt explained. The precision Bhatt is promising is pretty remarkable. Aetherflux's initial target is a laser spot 'bigger than 10 meters diameter' on the ground, but Bhatt believes they can shrink it to 'five to 10 meters, potentially even smaller than that.' These compact, lightweight receivers would be 'of little to no strategic value if captured by an adversary' and 'small enough and portable enough that you can literally bring them out into the battlefield.' While much remains to be seen, success for Aetherflux could potentially change the game for American military operations worldwide. In addition to his own father, Bhatt said that he draws inspiration from another entrepreneur who proved you can master multiple industries: Elon Musk. Importantly, like Musk, who moved from payments to revolutionize electric vehicles and space travel, Bhatt believes his outsider perspective 'is actually an advantage,' he said, echoing how fresh eyes sometimes see what industry veterans miss. Of course, unlike the iterate-fast mentality of companies like Robinhood that can roll out, and also sometimes roll back, software features, space hardware requires a higher-stakes approach. You only get one shot when your satellite launches. 'We build one spacecraft, we bolt it to the fairing inside of the SpaceX rocket, we put it in space, and it detaches, and then the thing better work,' Bhatt said. 'You can't go up there and tighten the bolt.' Asked during the sit-down how he pressure-tests that spacecraft, Bhatt said that Aetherflux is pursuing a 'hardware-rich' approach, which means building and testing components while refining designs. 'The right balance is not waiting five years, 10 years, 15 years, 20 years, as is the case with many important space programs,' he said. 'People's careers are oftentimes shorter than that.' He also noted that if Aetherflux succeeds, the implications extend far beyond military applications. Space-based solar power could provide baseload renewable energy, or solar power that works day and night, anywhere on Earth. That might mean turning upside down the ways we currently think about energy distribution, offering power to remote locations without massive infrastructure investments, and providing emergency power during disasters. Aetherflux has already hired a mix of physicists, mathematicians, and engineers from Lawrence Livermore Labs, Rivian, Cruise, and SpaceX, among other places, and Bhatt said the 25-person organization is still hiring. 'If you are the kind of person that wants to work on stuff that's super, super difficult, please come and contact us,' he told attendees. He has more than his reputation riding on what happens from here. Bhatt self-funded Aetherflux's first $10 million, and he also contributed to a more recent $50 million round that was led by Index Ventures and Interlagos, and included Bill Gates's Breakthrough Energy Ventures, Andreessen Horowitz, and NEA, among others. Its timeline is aggressive, too. The plan is to launch a demonstration satellite precisely one year from now. But there's a prototype for Bhatt's approach. GPS started as a DARPA project before becoming ubiquitous civilian infrastructure. Similarly, Aetherflux is working closely with DARPA's beaming expert, Dr. Paul Jaffe, who Bhatt called 'a pretty good friend to our company.' Jaffe also works with other companies developing similar technology, positioning DARPA as a bridge between military applications and commercial potential. 'There's this precedent of doing stuff in space where there's a really important part of working with the government,' Bhatt said. 'But we actually think, over time, as the technology matures and things like [SpaceX's reusable super heavy-lift launch vehicle] Starship really open up commercial access to space, this is not going to be just a Department of Defense thing.'


Android Authority
19 minutes ago
- Android Authority
Deal: Yaber L2S projector drops to record low price, only $134.99!
Projectors don't have to be huge and expensive anymore. Yaber proves to us that projectors can be small, cheap, and still offer a pretty pleasant viewing experience for those magical movie nights! The Yaber L2S usually costs only $199.99, but right now you can get it significantly cheaper, as it's on sale for just $134.99. Buy the Yaber L2S projector for just $134.99 ($65 off) This offer is available from Amazon. It's labeled as a 'limited time deal,' and the discount applies to both color versions available: Misty White and Charcoal White. Yaber Projector L2s Home Cinema Yaber Projector L2s Home Cinema See price at Amazon Save $65.00 Limited Time Deal! Our sister site, has already tested and reviewed the Yaber L2S projector, and our co-workers were very happy with its simple, clean, and compact design. The fan is also very quiet, which is always a concern with projectors. More importantly, it is a very simple and user-friendly projector to use, making it a great consumer product for anyone. Both maintenance and operation are very simple. As a projector, it works decently. Of course, there are many better projectors out there, but this one is way too good considering its low price. It has a Full HD 1,080p resolution and a 700-lumen brightness. The image can also be expanded up to 150 inches, so it can turn your living room into a small movie theater. Not only that, but the Yaber L2S comes with a couple of 8W JBL-powered speakers. We found them to be pretty good compared to most other projector speakers, but don't expect them to blow you away either. My only real complaint is that it has no smart TV operating system. Again, though, this thing is just $134.99 right now. You can't really get too picky, and you can easily hook a smart TV box to it, such as a Google TV Streamer, a Fire TV device, or a Roku streamer. Of course, it has an HDMI port, so you can also use any console, computer, or any other device with it. Also, the Yaber L2S has no integrated battery, so you'll have to plug it in for it to work. Again, we can't get too picky, considering the price! This is one heck of a deal if you're looking to upgrade your movie nights but would rather not spend an arm and a leg on it. At just $134.99, it is way too simple to justify this purchase! Again, this is a record-low price, and such deals don't usually last very long. Grab yours while you can.


Forbes
30 minutes ago
- Forbes
Veo's AI Video Memes, Vuzix Raises $5 Million, And More On AWE 2025
First there was the Talking Baby Podcast and its thousands of descendants on social media, all created using AI apps like Hedra and Hey Gen. Now Google's Veo 3 AI image generator, released at Google I/O three weeks ago, is hyperscaling meme vlogs that feature Star Wars Storm Troopers, Bigfoot, and Jesus. It's like group development of intellectual property. Who owns Bigfoot, or Jesus? Map of the Generative Video apps. Andreessen Horowitz a16z ventures released a new market map for text-to-video and image-to-video companies. With Paul Travers, founder and CEO of Vuzix, in 2018. He has been at this since 2008. Vuzix Secures $5M Investment as Veteran Smart Glasses Maker Sets Sights on Consumers. Vuzix secured a $5 million investment from Quanta Computer, a major Taiwanese ODM and Apple assembler. This marks the second tranche following a $10 million investment from Quanta in September 2024, with Vuzix aiming for a total of $20 million. CEO Paul Travers says the new funding will be used to enhance Vuzix's waveguide manufacturing, supporting the company's goal to deliver affordable, lightweight, high-performance AI smart glasses for mass-market adoption. The deal also strengthens Vuzix's partnership with Quanta and boosts its advanced waveguide production capabilities, positioning the company to better compete as the consumer smart glasses market heats up. Midjourney launches its first AI video generation model. The move into video generation is a significant expansion for the company, previously known for its popular image generator. With V1, users can upload a single image and prompt the AI to create short video clips that bring the image to life, adding motion, effects, and cinematic transitions. The service is available to Midjourney's paid subscribers. brain and chip World first: brain implant lets man speak with expression — and sing. A groundbreaking medical achievement has enabled a man who could not speak intelligibly to communicate with expressive speech and even sing, thanks to a brain implant. Electrodes were implanted in the motor cortex, the brain region responsible for speech, allowing researchers to decode his intended speech from neural activity. This technology not only restored his ability to speak with natural prosody and emotional nuance but also enabled him to sing, a world first. The 13th Augmented World Expo and Conference took place June 1 -3, 2022, in Santa Clara, CA AR/VR Market Rebounds with 18.1% Growth in Latest Quarter; Mixed and Extended Reality to Drive Long-Term Expansion, says IDC. The global AR/VR market surged by 18.1% in the latest quarter, signaling a robust rebound after a challenging period. This growth is fueled by new device launches, increased enterprise adoption, and more compelling consumer content. IDC highlights that mixed reality (MR) and extended reality (XR) devices are driving long-term expansion, as they offer more versatile applications across industries like healthcare, design, and education. The report predicts continued double-digit growth, with hardware improvements and AI-powered features accelerating adoption. As XR ecosystems mature, IDC expects broader mainstream acceptance, especially as price points decrease and content libraries expand. The market's momentum suggests immersive tech is becoming a core part of digital transformation strategies worldwide. Meow Wolf's parody grocery store anchors Area 15 in Las Vegas. Meow Wolf and Niantic Spatial explore expansion of multimedia art with AR. Known for its immersive art entertainment venues, Meow Wolf is partnering with Niantic Spatial to collaborate on location-based AR. By leveraging Niantic's location-based AR platform, Meow Wolf can extend its signature surreal storytelling beyond physical spaces. Presets can apply a 'vintage comic book style' to a video, change the lighting in a clip to a rainy ... More day, or swap out a subject's clothing to a space cadet suit. You can share edited videos directly to Facebook and Instagram. Meta AI gains video editing capabilities. This update allows creators to perform tasks like trimming, color correction, adding effects, and even generating new video content through conversational commands. Penrose founder and CEO, director Eugene Y.K. Chung Penrose Studio Calls It Quits. Eugene YK Chung, founder, CEO and director of the multi-award winning spatial 3D animation house announced the news himself in a social media post. 'After an unforgettable decade, we have decided - together with our board and shareholders - to close Penrose Studios. In the early days a handful of believers crowded my SoMa apartment, convinced that stories could surround us. Over time we pushed technical boundaries and crafted experiences that shaped that endured was commitment: teammates who burned midnight oil, investors who backed uncharted frontiers, partners who opened doors, and explorers who slipped on headsets to enter our worlds. My heartfelt thanks go out to all of you. Wired Magazine called Penrose's VR film "the first VR Film masterpiece!" In 2017, I wrote a Forbes column titled 'Meet the D.W. Griffith of VR', praising Chung's pioneering work in immersive storytelling. Penrose's 'Arden's Wake' won Best VR at the Venice Film Festival in 2018. Unfortunately, being the best isn't always enough. AR In VR: 15 Years Of Augmented World Expo With Ori Inbar Augmented World Expo (AWE) started in 2010 with 300 attendees and has grown into a major XR event with thousands of participants and hundreds of exhibitors. Ori Inbar, co-founder and CEO, explains that AR and VR were once separate but now share the stage because they serve complementary roles. Inbar notes that while mobile AR is widely used for things like social media and shopping, the best immersive experiences still happen in VR headsets. He believes we'll eventually see a single device that merges AR and VR capabilities. For now, each device has its strengths, and the field continues to advance with better hardware, wider fields of view, and more practical applications The Coolest VR Gear and Games I Saw at Augmented World Expo 2025 Last week, AWE in Long Beach showcased the latest in AR, VR, and MR technology. Highlights included the unveiling of Qualcomm's Snapdragon AR1+ Gen 1 chip, set to power next-generation smart glasses. The expo, running since 2010, provided a platform for attendees to experience cutting-edge devices, applications, and immersive content. From e-bikes to advanced headsets and productivity apps, the event emphasized the rapid evolution of XR technology and its growing impact on work, entertainment, and social interaction. A look into Google's Android XR strategy and its big gaming push At Augmented World Expo 2025, Google executives outlined their vision for Android XR as the unifying platform for XR smart glasses. Panels covered the Android XR roadmap, emphasizing support for headsets and smart glasses, and highlighted partnerships with Samsung, Qualcomm, and Unity. Google was in full developer romance mode, promising robust tools and monetization opportunities. Google is betting on cross-device compatibility and developer buy-in to drive the next wave of immersive experiences, positioning Android XR as a cornerstone for future spatial computing innovation. VR Bungee Jumping Simulation Tips You Over In Real Life At AWE, the Anywhere Bungee VR simulation offered attendees a uniquely intense experience. Using a Quest 3 headset and a see-saw, users were strapped in and suspended to simulate a bungee jump off a Tokyo skyscraper. In case you're wondering, while I was a witness, I was not a participant. This column is also a podcast hosted by its author, Charlie Fink, Ted Schilowitz, former studio executive and co-founder of Red Camera, and Rony Abovitz, founder of Magic Leap. This week our guest is Cnet reporter Scott Stein. We can be found on Spotify, iTunes, and YouTube. What We're Reading Tony Vitillo Interview Second Life Founder Philip Rosedale on the Metaverse (Skarred Ghost blog)