radar

ONE Sentinel

securitySecurity/THREATS/CRIT

Who Operates the Badbox 2.0 Botnet?

sourceKrebs on Security
calendar_todayJanuary 26, 2026
schedule2 min read
lightbulb

EXECUTIVE SUMMARY

Kimwolf Botmasters Expose Badbox 2.0 Botnet Operations

Summary

The article discusses the exposure of the Badbox 2.0 botnet's operations by the cybercriminals behind the Kimwolf botnet. The FBI and Google are actively investigating the individuals responsible for Badbox 2.0, which is linked to malicious software on Android TV streaming boxes.

Key Points

  • Kimwolf botnet has infected over 2 million devices.
  • Kimwolf operators shared a screenshot of the Badbox 2.0 control panel.
  • Badbox 2.0 is a large botnet based in China.
  • The botnet is powered by malware pre-installed on Android TV streaming boxes.
  • Both the FBI and Google are involved in tracking down the operators of Badbox 2.0.

Analysis

The exposure of the Badbox 2.0 botnet's control panel by Kimwolf operators highlights the interconnected nature of cybercriminal activities. The involvement of major entities like the FBI and Google underscores the severity of the threat posed by botnets that leverage pre-installed malware on consumer devices. This situation illustrates the need for enhanced security measures and vigilance in the supply chain of electronic devices.

Conclusion

IT professionals should prioritize monitoring and securing networked devices, especially those with pre-installed software, to mitigate the risks posed by botnets like Badbox 2.0. Collaborating with law enforcement and tech companies can also aid in combating such threats.