Google Just Dismantled a Cybercrime Empire That Hijacked Millions of Devices — And the Fight Isn’t Over

Google disrupted BadBox 2.0, a massive botnet that hijacked over one million cheap Android devices worldwide for ad fraud and proxy services. The operation exposed deep supply-chain vulnerabilities in uncertified hardware manufacturing that remain unresolved despite the takedown.
Google Just Dismantled a Cybercrime Empire That Hijacked Millions of Devices — And the Fight Isn’t Over
Written by Sara Donnelly

Google has struck at the heart of one of the most sprawling cybercrime operations in recent memory, disrupting a network that quietly hijacked millions of Android devices worldwide and turned them into instruments of fraud. The operation, targeting a malware strain known as BadBox 2.0, represents one of the largest botnet takedowns ever attempted against the Android platform — and it reveals just how deeply criminal enterprises have embedded themselves in the global consumer electronics supply chain.

The action, announced in partnership with cybersecurity firms Human Security, Trend Micro, and others, resulted in the removal of 24 malicious apps from the Google Play Store and the sinking of the botnet’s command-and-control infrastructure for devices running Google Play Protect. An estimated one million compromised devices were neutralized in the process. But the underlying problem — cheap, off-brand Android devices shipping with malware baked into their firmware — persists on a scale that should alarm anyone in the security industry.

Inside the BadBox 2.0 Machine

BadBox 2.0 is the successor to an earlier operation that Talk Android and other outlets have tracked since researchers first identified BadBox in 2023. The original version was notable for its distribution method: rather than tricking users into downloading infected apps, the malware came pre-installed on budget Android TV boxes, tablets, and digital projectors — devices typically manufactured in China and sold through discount online retailers and brick-and-mortar liquidation shops.

The 2.0 variant expanded the playbook considerably. According to Human Security’s detailed technical report, the upgraded operation involved at least four distinct threat actor groups working in loose coordination: SalesTracker Group, MoYu Group, Lemon Group, and LongTV. These groups divided responsibilities across the kill chain — some handled the supply-chain compromise, others developed the backdoor modules, and still others monetized the infected devices through ad fraud and residential proxy services.

The scale is staggering. Human Security identified over one million infected devices across more than 222 countries and territories, with the heaviest concentrations in Brazil, the United States, Mexico, and Argentina. The devices weren’t high-end smartphones. They were cheap, uncertified Android Open Source Project (AOSP) devices — the kind of hardware that never passes through Google’s Play Protect certification process and often ends up in the hands of price-sensitive consumers who don’t know what they’re buying.

Here’s what made BadBox 2.0 particularly insidious: the malware operated as a backdoor module called BB2DOOR, which was embedded at the firmware level before the devices ever reached consumers. Once a device connected to the internet, it silently contacted command-and-control servers and awaited instructions. The operators could then deploy additional payloads — ad fraud modules, click-injection tools, or proxy services that routed other criminals’ traffic through the compromised device’s IP address.

That last capability matters enormously. Residential proxy networks — services that let users route internet traffic through real home IP addresses — have become a booming underground commodity. They’re used for everything from credential stuffing attacks to bypassing geographic content restrictions to committing financial fraud. When your traffic appears to originate from a grandmother’s TV box in São Paulo rather than a data center in Eastern Europe, detection becomes exponentially harder.

Google’s Threat Intelligence Group confirmed the takedown in a blog post published on its safety and security page. The company said it had pushed Play Protect enforcement to disable BadBox 2.0 functionality on infected devices that had any connection to Google services, effectively severing the botnet’s ability to communicate with its operators on those units. Google also flagged the compromised devices as non-Play Protect certified, a designation that limits their access to Google apps and services.

But there’s a catch. And it’s a significant one.

Devices running pure AOSP without Google Play Services — a substantial portion of the infected hardware — remain outside Google’s reach. The company can’t push updates or enforcement actions to devices that don’t check in with its servers. Those units remain compromised, still pinging their command-and-control infrastructure, still available to their operators for whatever purpose they choose.

The Supply Chain Problem Nobody Wants to Own

The BadBox saga exposes a structural weakness in the global electronics market that has no easy fix. The Android operating system is open source. Anyone can take AOSP, build a device around it, and ship it without Google’s involvement or approval. This openness has been one of Android’s greatest strengths — it’s enabled a massive global market for affordable computing devices. It’s also created a shadow market where quality control is nonexistent and security is an afterthought.

The devices at the center of BadBox 2.0 were manufactured by companies with little brand recognition and less accountability. They’re sold under dozens of labels, often through third-party marketplace listings on Amazon, AliExpress, and similar platforms. Consumers see an Android TV box for $30 and assume it works like any other Android device. They have no way of knowing that the firmware contains a backdoor.

Germany’s Federal Office for Information Security (BSI) took action against BadBox-infected devices as early as December 2024, sinkholing traffic from approximately 30,000 devices within its borders. The BSI’s intervention was notable because it represented a government agency stepping in where market forces had failed — effectively taking control of the malware’s communication channels to prevent further exploitation.

But 30,000 devices in Germany is a rounding error against the million-plus global total. And the BSI’s authority stops at its national borders.

Trend Micro’s researchers, who collaborated on the disruption effort, noted in their analysis that the threat actors behind BadBox 2.0 had refined their operations significantly since the first iteration. The original BadBox relied primarily on pre-installed firmware compromises. Version 2.0 added a second infection vector: apps distributed through the Google Play Store that could activate dormant backdoor functionality on devices that already contained the BB2DOOR module. This two-pronged approach meant the operators could expand their botnet both through hardware supply chains and through software distribution — a belt-and-suspenders strategy that made the operation remarkably resilient.

The 24 apps Google removed from the Play Store had collectively been downloaded hundreds of thousands of times. Some were disguised as utility apps or health and fitness trackers. Others masqueraded as simple games. All contained code designed to communicate with BadBox 2.0 infrastructure and facilitate ad fraud or proxy routing.

Ad fraud was the primary revenue engine. The infected devices generated fraudulent ad impressions and clicks at industrial scale, siphoning money from legitimate advertisers and the broader digital advertising supply chain. Human Security estimated that the BadBox 2.0 network was capable of producing billions of fraudulent bid requests per day — a volume that could drain millions of dollars monthly from programmatic advertising budgets.

So who pays? Ultimately, every brand that buys digital advertising. The fraud tax embedded in programmatic ad spending has been estimated at anywhere from 15% to 30% of total spend, depending on the channel and methodology. Operations like BadBox 2.0 are a significant contributor to that waste.

The coordination required to pull off this disruption was considerable. Google worked with Human Security, Trend Micro, the Shadowserver Foundation, and several internet service providers to simultaneously sinkhole command-and-control domains, push device-level protections, and remove malicious apps. The effort required months of intelligence gathering and careful timing — moving too early on any single element would have tipped off the operators and allowed them to migrate their infrastructure.

Yet even this coordinated strike has limitations. The threat actors behind BadBox 2.0 have demonstrated an ability to adapt. When the original BadBox operation was partially disrupted in 2023, they retooled, expanded their network of manufacturing partners, and added new monetization strategies. There’s every reason to expect they’ll do the same again.

For the Android device market, the implications are clear. Google’s Play Protect certification exists for a reason — it establishes a baseline of security and software integrity that uncertified devices simply don’t meet. But the certification program is voluntary for manufacturers, and the economic incentives for producing cheap, uncertified devices remain strong. Consumers in emerging markets, where BadBox infections are most concentrated, often can’t afford certified alternatives.

What Comes Next

The cybersecurity industry has been tracking supply-chain compromises with increasing urgency. The BadBox operations represent one of the most visible examples of what happens when hardware manufacturing, software distribution, and criminal monetization converge into a single integrated business model. These aren’t opportunistic hackers exploiting a vulnerability. They’re organized enterprises running a vertically integrated fraud operation, from factory floor to ad exchange.

Google has signaled it will continue to invest in detection and disruption capabilities. The company’s blog post emphasized that Play Protect now covers over two billion active devices and that its threat detection models are continuously updated to identify new variants of known malware families. But the company also acknowledged, implicitly, the limits of its authority over the broader Android hardware market.

For enterprises and consumers alike, the takeaway is uncomfortable but straightforward: the cheapest device is rarely the cheapest option. The true cost of a $30 Android TV box may include your network being used as a proxy for criminal activity, your bandwidth consumed by ad fraud bots, and your IP address appearing in logs associated with credential stuffing attacks.

The BadBox 2.0 disruption is a win. A significant one. But the infrastructure that enabled it — fragmented global supply chains, an open-source operating system that anyone can modify, and a consumer market that prioritizes price above all else — isn’t going anywhere. The next variant is likely already in development, if not already shipping in a cardboard box from a factory floor in Shenzhen.

And that’s the part of this story that no sinkhole operation can fix.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us