web analytics

Google Sues Operators of 10-Million-Device Badbox 2.0 Botnet – Source: www.securityweek.com

Rate this post

Source: www.securityweek.com – Author: Ionut Arghire

Google on Thursday announced filing a lawsuit against the operators of the Badbox 2.0 botnet, which has ensnared more than 10 million devices running Android open source software.

These devices lack Google’s security protections, and the perpetrators pre-installed the Badbox 2.0 malware on them, to create a backdoor and abuse them for large-scale fraud and other illicit schemes.

While updates to Google Play Protect kept the malware away from devices running Google services and automatically blocked associated applications, the fresh lawsuit is meant to help the internet giant dismantle the criminal operation behind the botnet.

Badbox 2.0 “is already the largest known botnet of internet-connected TV devices, and it grows each day. It has harmed millions of victims in the United States and around the world and threatens many more,” Google notes in its complaint, a copy of which was shared with SecurityWeek.

The internet giant cautions that, while it has been used mainly for fraud, the botnet could be used for more harmful types of cybercrime, such as ransomware or distributed denial-of-service (DDoS) attacks.

In addition to pre-installing the malware on devices, Badbox 2.0’s operators also tricked users into installing infected applications that provided them with further access to their personal devices, Google says.

As part of their operation, the individuals behind Badbox 2.0 sold access to the infected devices to be used as residential proxies, and conducted ad fraud schemes by abusing these devices to create fake ad views or to exploit pay-per-click compensation models, the company continues.

The internet giant also points out that this is the second global botnet the perpetrators have built, after the initial Badbox botnet was disrupted by German law enforcement in 2023.

Advertisement. Scroll to continue reading.

“Because of the size and scope of the BadBox 2.0 Scheme, cybersecurity experts have alerted the public, and Google is seeking an injunction to disrupt its infrastructure and stop its spread,” the complaint reads.

According to Google, Badbox 2.0 is operated by multiple cybercrime groups from China, each having a different role in maintaining the botnet, such as establishing infrastructure, developing and pre-installing the malware on devices, and conducting fraud.

“The BadBox 2.0 Enterprise includes several connected threat actor groups that design and implement complex criminal schemes targeting internet-connected devices both before and after the consumer receives the device,” Google says.

“While each member of the Enterprise plays a distinct role, they all collaborate to execute the BadBox 2.0 Scheme. All of the threat actor groups are connected to one another through the BadBox 2.0 shared C2 infrastructure and historical and current business ties,” the company continues.

Related: Prometei Botnet Activity Spikes

Related: In Other News: FBI Warns of BadBox 2, NSO Disputes WhatsApp Fine, 1,000 Leave CISA

Related: BadBox Botnet Powered by 1 Million Android Devices Disrupted

Related: Germany Sinkholes Botnet of 30,000 BadBox-Infected Devices

Original Post URL: https://www.securityweek.com/google-sues-operators-of-10-million-device-badbox-2-0-botnet/

Category & Tags: Malware & Threats,BadBox,botnet,Featured,fraud,google,lawsuit – Malware & Threats,BadBox,botnet,Featured,fraud,google,lawsuit

Views: 3

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post