Friday, July 11, 2025
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

HUMAN Exposes BADBOX 2.0 Scheme Infecting 1 Million Off-Brand Android Open Source Project Devices

March 5, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 8 mins read
5
SHARES
246
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

NEW YORK, March 05, 2025 (GLOBE NEWSWIRE) — HUMAN Security, Inc., the global cybersecurity leader in disrupting bot attacks and preventing digital fraud and abuse, announced today that in collaboration with Google, Trend Micro, Shadowserver and other partners, its Satori Threat Intelligence and Research Team has uncovered BADBOX 2.0, the largest botnet of infected connected TV (CTV) devices ever uncovered and disclosed. This multifaceted operation involves backdoored off-brand and uncertified Android Open Source Project-powered devices and builds upon an earlier scheme, BADBOX, disrupted in October 2023. Satori identified more than 1 million devices that were infected in BADBOX 2.0, up from the 74,000 in the original BADBOX scheme.

“The BADBOX 2.0 scheme is bigger and far worse than what we saw in 2023 in terms of the uptick in types of devices targeted, the number of devices infected, the different types of fraud conducted, and the complexity of the scheme,” said Gavin Reid, CISO of HUMAN. “This operation embodies the interconnected nature of modern cyberattacks and how threat actors target the customer journey and demonstrates why businesses require full-spectrum protection from the impacts of digital fraud and abuse.”

HUMAN has been closely following the BADBOX actors and corresponding malware since the publication of the original report in October 2023. HUMAN observed updates and adaptations to the malware and followed these leads to uncover the entire operation. Researchers believe several threat actor groups participated in BADBOX 2.0, each contributing to parts of the underlying infrastructure or the fraud modules that monetize the infected devices, including programmatic ad fraud, click fraud, proxyjacking, and creating and operating a botnet across 222 countries and territories. HUMAN continues to investigate additional paths to disruption with Google, Trend Micro, other partners, and law enforcement.

“We appreciate collaborating with HUMAN to take action against the BADBOX operation and protect consumers from fraud,” said Shailesh Saini, Director of Android Security & Privacy Engineering & Assurance, Google. “The infected devices are Android Open Source Project devices, not Android TV OS devices or Play Protect certified Android devices. If a device isn’t Play Protect certified, Google doesn’t have a record of security and compatibility test results. Play Protect certified Android devices undergo extensive testing to ensure quality and user safety. Users should ensure Google Play Protect, Android’s malware protection that is on by default on devices with Google Play Services, is enabled.”

BADBOX 2.0 perpetuates four types of fraud:

 1.Programmatic ad fraud of multiple varieties, including hidden ads rendered by preinstalled apps and hidden WebViews launched that navigate to a collection of ad-heavy gaming sites.
 2.Click fraud, which occurs when automated traffic from infected devices visits low-quality domains and clicks on ads, draining advertiser budgets.
 3.Residential proxy node creation, in which traffic is routed through an infected device’s IP address through a network owned and operated by the threat actors.
 4.Account takeover, fake account creation, credential stealing, sensitive information exfiltration, and DDoS attacks, all perpetuated by downstream threat actors to whom the residential proxy services were sold.
   

BADBOX 2.0 threat actors also operated over 200 re-bundled and infected versions of popular apps listed on third-party marketplaces and serving as an alternative backdoor delivery system. Satori researchers identified 24 “evil twin” apps with corresponding “decoy twin” apps on the Play Store, through which ad fraud is conducted; at its peak, the evil twin apps accounted for 5 billion fraudulent bid requests a week. BADBOX 2.0 actors operated a network of nearly 1000 ad-heavy gaming websites, which are used as a cashout mechanism.

“It takes a proactive approach to protect consumers and businesses from such a sophisticated cyber scheme like BADBOX 2.0,” said Lindsay Kaye, Vice President of Threat Intelligence at HUMAN. “Some of the fraud modules uncovered by Satori researchers had not yet been launched and may have been planned for future attacks. It’s critical to work with a cybersecurity partner that can monitor threat actors long after a threat is disclosed and protect against the type of adaptations seen in BADBOX 2.0.”

HUMAN’s Ad Fraud Defense protects clients, partners and customers against a variety of ad fraud schemes, including the hidden ads and hidden WebView attacks uncovered in BADBOX 2.0. HUMAN Account Takeover Defense also protects organizations against malicious bot account takeover and account fraud attacks, including the types facilitated by the BADBOX 2.0 residential proxy capability. To learn more about the BADBOX 2.0 operation and for a list of device models affected by BADBOX 2.0, visit the HUMAN blog and read the full technical report.

About HUMAN
HUMAN is a leading cybersecurity company committed to protecting the integrity of the digital world. We ensure that every digital interaction, transaction, and connection is authentic, secure, and human. Our Human Defense Platform safeguards the entire customer journey with high-fidelity decision-making that defends against bots, fraud, and digital threats. Each week, HUMAN verifies 20 trillion digital interactions, providing unparalleled telemetry data to enable rapid, effective responses to even the most sophisticated threats. Recognized by our customers as a G2 Leader, HUMAN continues to set the standard in cybersecurity. To ensure your digital connections are trusted, visit www.humansecurity.com

Contact information:
Masha Krylova, Director of Communications
press@humansecurity.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/e72c192c-41a3-4c2f-9cef-75eea23ebd76

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

BLE Chipsets: Powering the Next Wave of Connected Devices

Next Post

GDS to Report Fourth Quarter and Full Year 2024 Financial Results Before the Open of the U.S. Market on March 19, 2025

Related Posts

World AI Show Wraps Up Landmark Indonesia Edition, Announces 46th Global Edition in Kuala Lumpur, Malaysia

World AI Show Indonesia concludes with high-level dialogues, government and industry engagement on artificial intelligence innovation as Trescon names Kuala Lumpur the next stop for its global AI series following Indonesia's successful showcase. JAKARTA, ID / ACCESS Newswire / July 10, 2025 / The highly anticipated Indonesia edition of World...

Read moreDetails

MSG91 Offers a Great SMS API Pricing Framework

Image: https://www.globalnewslines.com/uploads/2025/07/1752148294.jpgMSG91 operates as a cloud-based messaging service that connects businesses with customers across different communication channels. The platform handles text messaging, email delivery, and WhatsApp communications for companies spanning various industries. Thousands of organizations depend on MSG91's infrastructure to send everything from transaction alerts to marketing campaigns, with the...

Read moreDetails

Ripple partners with Bank of New York Mellon, XRP soars – LET Mining launches new cloud mining strategy for XRP holders

New York City, July 10, 2025 (GLOBE NEWSWIRE) -- Ripple has established a partnership with the oldest bank on Wall Street, and BNY Mellon has become the custodian of RLUSD, which will take Ripple's stablecoin strategy to the next level and herald its long-term commitment to infrastructure construction. With the...

Read moreDetails

Superior Supplement Manufacturing Expands Pet Supplement Manufacturing Services with Enhanced Contract Manufacturing Support

Fountain Valley, CA, July 10, 2025 (GLOBE NEWSWIRE) -- Superior Supplement Manufacturing today announced a significant expansion of its pet supplement manufacturing services, enhancing its ability to support clients with comprehensive contract manufacturing solutions across multiple product formats. The expanded services include advanced support for pet soft chews, capsules, tablets,...

Read moreDetails

BAY Miner Cloud Mining App Now Live: Earn Cryptocurrency Daily with No Technical Skills Needed

Jersey City, NJ, July 10, 2025 (GLOBE NEWSWIRE) -- BAY Miner has officially launched its revolutionary cloud mining app, designed for beginners and crypto enthusiasts alike. With this all-in-one platform, users can now earn cryptocurrency passively—without any hardware, setup, or technical knowledge. The digital finance world is evolving fast, and...

Read moreDetails

Authentified: Forging Real Connections in a Spam-Filled World

FOLSOM, CA / ACCESS Newswire / July 10, 2025 / You can leave behind endless cold emails and spammy online networking. Authentified, created by the persistent Shilpi Padhy, is changing how professional networks work. The company is replacing the executive networking platform white noise with genuine, valuable relationships built on...

Read moreDetails

Global Revenue Cycle Management Market Size To USD 728.7 Billion by 2032 | Leading Players: McKesson, Cerner, GE Healthcare and others

Global Revenue Cycle Management Market Size According to a research report published by Spherical Insights & Consulting, the Revenue Cycle Management Market Size is projected to Grow from USD 266.37 Billion in 2022 to USD 728.7 Billion by 2032, expanding at a CAGR of 10.59% during the forecast period 2022-2032The...

Read moreDetails

WinnerMining builds a green and reliable cloud mining platform to enable users to steadily participate in the growth of digital assets

New York, NY, July 10, 2025 (GLOBE NEWSWIRE) -- With the rapid development of cryptocurrencies in the past decade, the global financial landscape is undergoing an unprecedented transformation. In this wave, WinnerMining, an innovative smart cloud mining platform in the UK, stands out and is committed to providing global investors...

Read moreDetails

Varonis Announces Date of Second Quarter 2025 Financial Results

MIAMI, July 10, 2025 (GLOBE NEWSWIRE) -- Varonis Systems, Inc. (Nasdaq: VRNS), the leader in data security, announced that it will report its second quarter 2025 financial results following the close of the U.S. financial markets Tuesday, July 29, 2025. In conjunction with this announcement, Varonis will host a conference...

Read moreDetails

Rapid7 to Report Second Quarter 2025 Financial Results on August 7

BOSTON, July 10, 2025 (GLOBE NEWSWIRE) -- Rapid7, Inc. (NASDAQ: RPD), a leader in threat detection and exposure management, today announced that the company will release its second quarter 2025 financial results on Thursday, August 7, 2025, after the financial markets close. The company will host a conference call that...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    71 shares
    Share 28 Tweet 18
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    59 shares
    Share 24 Tweet 15
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    39 shares
    Share 16 Tweet 10
  • Top 5 Wallets for Seamless Multi-Chain Trading in 2025

    38 shares
    Share 15 Tweet 10
  • CertiK Cements Institutional Presence After CEO’s Strategic Engagements in Hong Kong

    6 shares
    Share 2 Tweet 2
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

Web 3.0 and AI Summit 2025

2025-09-11
Frankfurt
Summit

Latest on Web3Wire

  • World AI Show Wraps Up Landmark Indonesia Edition, Announces 46th Global Edition in Kuala Lumpur, Malaysia
  • MSG91 Offers a Great SMS API Pricing Framework
  • Ripple partners with Bank of New York Mellon, XRP soars – LET Mining launches new cloud mining strategy for XRP holders
  • Superior Supplement Manufacturing Expands Pet Supplement Manufacturing Services with Enhanced Contract Manufacturing Support
  • BAY Miner Cloud Mining App Now Live: Earn Cryptocurrency Daily with No Technical Skills Needed

RSS Latest on Block3Wire

  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age
  • Cathedra Bitcoin Announces Leasing of 2.5-MW Bitcoin Mining Facility
  • Global Web3 Payments Leader, Banxa, Announces Integration With Metis to Usher In Next Wave of Cryptocurrency Users
  • Dexalot Launches First Hybrid DeFi Subnet on Avalanche

RSS Latest on Meta3Wire

  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
  • MetatronAI.com Unveils Revolutionary AI-Chat Features and Interface Upgrades
  • Purely.website – Disruptive new platform combats rising web hosting costs
  • WEMADE and Metagravity Sign Strategic Alliance MOU to Collaborate on Blockchain Games for the Metaverse
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Whitepaper | Tokenomics

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Media Portfolio: Block3Wire | Meta3Wire

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!
Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.