Researchers warns that Android streaming boxes are pre-installed with malware

October 10, 2023

Researchers have discovered a number of Android streaming boxes, including the popular T95 that are being shipped with pre-installed malware. The malware, dubbed Badbox, is a complex and sophisticated piece of code that can be used to commit a variety of fraudulent activities, including ad fraud, residential proxy services, fake email and messaging accounts, and the installation of malicious code.

Badbox is believed to be spread through the regular hardware supply chain, meaning that users are unaware that their devices are infected until after they have purchased and installed them. Once installed, Badbox immediately connects to a command-and-control server to receive instructions.

In addition to the T95, Badbox has also been found on seven other set-top boxes (T95Z, T95MAX, X88, Q9, X12PLUS, and MXQ Pro 5G) as well as an Android tablet (the J5-W). These devices are all relatively inexpensive, which makes them attractive options for many users. However, researchers warn that consumers should be wary of purchasing these devices, as they may be infected with malware.

The sources for this piece include an article in ZDNET.

Top Stories

Related Articles

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time more...

April 1, 2026 Cisco suffered a cyberattack after attackers used stolen credentials from a compromised developer tool to access its more...

March 30, 2026 Google has expanded its “Results about you” tool, allowing users to remove highly sensitive personal data, including more...

March 27, 2026 Microsoft is updating GitHub Copilot to train on real-world developer interactions, expanding beyond public code datasets to more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn