Thursday, July 31, 2025
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

HUMAN Exposes BADBOX 2.0 Scheme Infecting 1 Million Off-Brand Android Open Source Project Devices

March 5, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 8 mins read
5
SHARES
246
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

NEW YORK, March 05, 2025 (GLOBE NEWSWIRE) — HUMAN Security, Inc., the global cybersecurity leader in disrupting bot attacks and preventing digital fraud and abuse, announced today that in collaboration with Google, Trend Micro, Shadowserver and other partners, its Satori Threat Intelligence and Research Team has uncovered BADBOX 2.0, the largest botnet of infected connected TV (CTV) devices ever uncovered and disclosed. This multifaceted operation involves backdoored off-brand and uncertified Android Open Source Project-powered devices and builds upon an earlier scheme, BADBOX, disrupted in October 2023. Satori identified more than 1 million devices that were infected in BADBOX 2.0, up from the 74,000 in the original BADBOX scheme.

“The BADBOX 2.0 scheme is bigger and far worse than what we saw in 2023 in terms of the uptick in types of devices targeted, the number of devices infected, the different types of fraud conducted, and the complexity of the scheme,” said Gavin Reid, CISO of HUMAN. “This operation embodies the interconnected nature of modern cyberattacks and how threat actors target the customer journey and demonstrates why businesses require full-spectrum protection from the impacts of digital fraud and abuse.”

HUMAN has been closely following the BADBOX actors and corresponding malware since the publication of the original report in October 2023. HUMAN observed updates and adaptations to the malware and followed these leads to uncover the entire operation. Researchers believe several threat actor groups participated in BADBOX 2.0, each contributing to parts of the underlying infrastructure or the fraud modules that monetize the infected devices, including programmatic ad fraud, click fraud, proxyjacking, and creating and operating a botnet across 222 countries and territories. HUMAN continues to investigate additional paths to disruption with Google, Trend Micro, other partners, and law enforcement.

“We appreciate collaborating with HUMAN to take action against the BADBOX operation and protect consumers from fraud,” said Shailesh Saini, Director of Android Security & Privacy Engineering & Assurance, Google. “The infected devices are Android Open Source Project devices, not Android TV OS devices or Play Protect certified Android devices. If a device isn’t Play Protect certified, Google doesn’t have a record of security and compatibility test results. Play Protect certified Android devices undergo extensive testing to ensure quality and user safety. Users should ensure Google Play Protect, Android’s malware protection that is on by default on devices with Google Play Services, is enabled.”

BADBOX 2.0 perpetuates four types of fraud:

 1.Programmatic ad fraud of multiple varieties, including hidden ads rendered by preinstalled apps and hidden WebViews launched that navigate to a collection of ad-heavy gaming sites.
 2.Click fraud, which occurs when automated traffic from infected devices visits low-quality domains and clicks on ads, draining advertiser budgets.
 3.Residential proxy node creation, in which traffic is routed through an infected device’s IP address through a network owned and operated by the threat actors.
 4.Account takeover, fake account creation, credential stealing, sensitive information exfiltration, and DDoS attacks, all perpetuated by downstream threat actors to whom the residential proxy services were sold.
   

BADBOX 2.0 threat actors also operated over 200 re-bundled and infected versions of popular apps listed on third-party marketplaces and serving as an alternative backdoor delivery system. Satori researchers identified 24 “evil twin” apps with corresponding “decoy twin” apps on the Play Store, through which ad fraud is conducted; at its peak, the evil twin apps accounted for 5 billion fraudulent bid requests a week. BADBOX 2.0 actors operated a network of nearly 1000 ad-heavy gaming websites, which are used as a cashout mechanism.

“It takes a proactive approach to protect consumers and businesses from such a sophisticated cyber scheme like BADBOX 2.0,” said Lindsay Kaye, Vice President of Threat Intelligence at HUMAN. “Some of the fraud modules uncovered by Satori researchers had not yet been launched and may have been planned for future attacks. It’s critical to work with a cybersecurity partner that can monitor threat actors long after a threat is disclosed and protect against the type of adaptations seen in BADBOX 2.0.”

HUMAN’s Ad Fraud Defense protects clients, partners and customers against a variety of ad fraud schemes, including the hidden ads and hidden WebView attacks uncovered in BADBOX 2.0. HUMAN Account Takeover Defense also protects organizations against malicious bot account takeover and account fraud attacks, including the types facilitated by the BADBOX 2.0 residential proxy capability. To learn more about the BADBOX 2.0 operation and for a list of device models affected by BADBOX 2.0, visit the HUMAN blog and read the full technical report.

About HUMAN
HUMAN is a leading cybersecurity company committed to protecting the integrity of the digital world. We ensure that every digital interaction, transaction, and connection is authentic, secure, and human. Our Human Defense Platform safeguards the entire customer journey with high-fidelity decision-making that defends against bots, fraud, and digital threats. Each week, HUMAN verifies 20 trillion digital interactions, providing unparalleled telemetry data to enable rapid, effective responses to even the most sophisticated threats. Recognized by our customers as a G2 Leader, HUMAN continues to set the standard in cybersecurity. To ensure your digital connections are trusted, visit www.humansecurity.com

Contact information:
Masha Krylova, Director of Communications
press@humansecurity.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/e72c192c-41a3-4c2f-9cef-75eea23ebd76

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

BLE Chipsets: Powering the Next Wave of Connected Devices

Next Post

GDS to Report Fourth Quarter and Full Year 2024 Financial Results Before the Open of the U.S. Market on March 19, 2025

Related Posts

GL Supports Next-Gen SIP Testing and Emulation

GAITHERSBURG, Md., July 31, 2025 (GLOBE NEWSWIRE) -- GL Communications Inc., a global leader in telecom testing solutions, addressed the press regarding their SIP protocol emulation and testing solutions. In today’s dynamic telecom environment, ensuring the reliable operation of SIP-based VoIP devices and networks is essential. This powerful platform emulates...

Read moreDetails

Duos Technologies Group, Inc. Announces Pricing of $40 Million Upsized and Oversubscribed Public Offering of Common Stock

With over $40 million in expected cash on hand, Duos is now fully capitalized to fulfill its $50 million revenue pipeline and advance deployment of an additional 65 Edge Data Centers Offering included primary participation from fundamental institutional investors, including a leading long-only mutual fund, several preeminent global investment managers,...

Read moreDetails

Telnyx expands conversational AI stack with new audio, TTS, and integration capabilities

AUSTIN, TX, July 30, 2025 (GLOBE NEWSWIRE) -- Telnyx, a global leader in communications infrastructure, today announced a wave of platform updates that enhance the core capabilities of its conversational AI stack. The release includes Azure Neural HD text-to-speech, built-in noise suppression, MCP server integration, embeddable AI Agent widgets, and...

Read moreDetails

Optus partners with Nokia to strengthen reliability of Voice with cloud-native solution supporting the deployment of new 5G enhanced voice services

Press ReleaseOptus partners with Nokia to strengthen reliability of Voice with cloud-native solution supporting the deployment of new 5G enhanced voice services Optus to utilize Nokia’s cloud-native Cloud Native Communication Suite (CNCS) to drive the deployment of new highly resilient 5G voice services and streamline network activities, enhanced automation and...

Read moreDetails

HERE and EROAD Deepen Collaboration to Transform Trucking in Australia and New Zealand

EROAD to launch first-ever vehicle-aware navigation application in Oceania, powered by HERE’s advanced platform and vehicle-specific data. Partnership addresses critical challenges in the freight sector, including safety, productivity and compliance. Australia – HERE Technologies, a global leader in digital mapping and location data, is expanding its collaboration with EROAD, a...

Read moreDetails

Quick Custom Intelligence Secures Eight-Figure Investment from Curve Partners to Accelerate Growth

SAN DIEGO, July 30, 2025 (GLOBE NEWSWIRE) -- Quick Custom Intelligence (QCI), a leading provider of Generative AI-driven analytics and operational software for casinos and resorts, today announced that it has secured a significant minority growth investment from Curve Partners. This strategic funding backs QCI’s current management team – led...

Read moreDetails

Silicon Motion Announces Results for the Period Ended June 30, 2025

Business Highlights Second quarter of 2025 sales increased 19% Q/Q and decreased 6% Y/Y SSD controller sales: 2Q of 2025 increased 0% to 5% Q/Q and decreased 15% to 20% Y/Y eMMC+UFS controller sales: 2Q of 2025 increased 40% to 45% Q/Q and increased 10% to 15% Y/Y SSD solutions...

Read moreDetails

UCFXMarkets Announces New Strategic Partnership with Leading Wealth Management Firms to Drive Diversified Portfolio Solutions

UCFXMarkets reviews are attracting significant attention as the company officially announced a strategic partnership with several leading wealth management firms to deliver next-generation portfolio diversification solutions to institutional and high-net-worth clients in the New York Metro area. This announcement marks a major step in expanding the platform’s footprint across North...

Read moreDetails

TSS, Inc. to Host Second Quarter 2025 Financial Results Conference Call on August 6, 2025

GEORGETOWN, TX / ACCESS Newswire / July 30, 2025 / TSS, Inc. (Nasdaq:TSSI), a data center services company that provides AI and high-performance computing integration, deployment and related services, will report results for its second quarter ended June 30, 2025 on August 6, 2025. The Company will conduct a conference...

Read moreDetails

Resoomer’s DocStudio: Switch to augmented reading online

In a fast-paced technological world, information overload becomes a challenge, making it difficult to access the essence of any information in a short time. Keeping this problem in mind, Resoomer launched DocStudio, an innovative online cognitive studio designed to redefine document analysis and foster augmented reading . Resoomer is deployed...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    82 shares
    Share 33 Tweet 21
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    45 shares
    Share 18 Tweet 11
  • Top 5 Wallets for Seamless Multi-Chain Trading in 2025

    42 shares
    Share 17 Tweet 11
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    64 shares
    Share 26 Tweet 16
  • Red Cat Partners with ESAero to Support Manufacturing for Teal’s Black Widow™

    6 shares
    Share 2 Tweet 2
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

Web 3.0 and AI Summit 2025

2025-09-11
Frankfurt
Summit

Latest on Web3Wire

  • BlackBerry, Global Affairs Canada, and TMU’s Rogers Cybersecure Catalyst Expand World-Class Cybersecurity Training in Malaysia
  • GL Supports Next-Gen SIP Testing and Emulation
  • Duos Technologies Group, Inc. Announces Pricing of $40 Million Upsized and Oversubscribed Public Offering of Common Stock
  • Telnyx expands conversational AI stack with new audio, TTS, and integration capabilities
  • Optus partners with Nokia to strengthen reliability of Voice with cloud-native solution supporting the deployment of new 5G enhanced voice services

RSS Latest on Block3Wire

  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age
  • Cathedra Bitcoin Announces Leasing of 2.5-MW Bitcoin Mining Facility
  • Global Web3 Payments Leader, Banxa, Announces Integration With Metis to Usher In Next Wave of Cryptocurrency Users
  • Dexalot Launches First Hybrid DeFi Subnet on Avalanche

RSS Latest on Meta3Wire

  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
  • MetatronAI.com Unveils Revolutionary AI-Chat Features and Interface Upgrades
  • Purely.website – Disruptive new platform combats rising web hosting costs
  • WEMADE and Metagravity Sign Strategic Alliance MOU to Collaborate on Blockchain Games for the Metaverse
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Whitepaper | Tokenomics

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Media Portfolio: Block3Wire | Meta3Wire

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!
Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.