A recently unsealed Google lawsuit reveals the company’s battle against what experts call the largest Android botnet in history.
The BadBox 2.0 network compromised 10 million devices worldwide, turning them into tools for cybercrime.

The BadBox Evolution
Google first encountered the original BadBox botnet in 2023, working with German law enforcement to tackle 74,000 infected Android devices. However, this initial threat paled compared to what came next.
BadBox 2.0 emerged as a far more serious problem. HUMAN’s Satori Threat Intelligence team discovered the expanded network, which infected over one million devices across 222 countries.
The botnet operated by secretly clicking ads, stealing accounts, launching DDoS attacks, and spreading additional malware. We first reported on BadBox 2.0 back in March 2025.

Cheap Streaming Devices Under Attack
The investigation found that most infected devices were inexpensive Chinese-manufactured set-top boxes.
These “fully loaded” boxes attract users seeking free streaming content but lack Google’s security protections since they run Android’s open-source software without official certification.
The compromised devices included streaming boxes, smartphones, tablets, laptops, car entertainment systems, and digital projectors. Users remained unaware their devices had become part of a criminal network.
Hide Your Digital Fingerprint

Four Criminal Groups Identified
Google’s lawsuit identifies four distinct criminal organizations behind BadBox 2.0:
- Infrastructure Group: Controls the command servers
- Backdoor Malware Group: Creates and installs malicious software
- Evil Twin Group: Develops fraud apps with hidden advertisements
- Ad Games Group: Runs fake gaming apps that generate secret ad revenue
Legal Victory Grants Broad Powers
In May, Google filed suit in New York federal court against 25 unnamed defendants believed to be operating from China. The company won a preliminary injunction in July, granting extensive authority to combat the botnet.
Google can now block traffic to specific IP addresses and domains. The court also authorized seizing control of domain names through registrars to cripple the network’s operations.
Prevention Remains Challenging
The FBI recommends avoiding unofficial app marketplaces and monitoring home networks for suspicious activity. However, users seeking free streaming content have limited alternatives to these risky platforms.

Google’s complaint suggests the entire supply chain is compromised, with malware often preinstalled during manufacturing. Even clean devices can become infected when users download seemingly legitimate apps carrying malicious code.
Final Thoughts
This case shows why users should avoid purchasing cheap Android TV boxes from unofficial retailers and unknown brands. These devices often come with preinstalled malware or lack proper security updates, making them easy targets for cybercriminals.
Stick to verified Android TV/Google TV devices from reputable manufacturers to protect your home network. The money saved on a bargain streaming box isn’t worth the risk of becoming part of a criminal botnet.
For more information on this story, refer to Google’s press release, the report from Human Security, and the official legal documentation (PDF).
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.




