10 Million Android Users Prohibited from Internet Access, This is the FBI Statement

The BadBox 2.0 Malware Threat Threatens 10 Million Android Users
Recently, around 10 million Android device users around the world were warned to immediately limit internet access on their devices. This was done because there were indications of the existence of dangerous malware called BadBox 2.0 which could cause leaks of users’ personal data.
This malware is known to enter devices through various means, including cheap devices sold online and pirated applications downloaded from sources outside the Google Play Store. With its advanced capabilities, BadBox 2.0 can take full control of the device, steal login data, access the camera and microphone without the user’s knowledge, and turn the device into part of a global botnet.
The FBI, the United States’ main law enforcement agency, has discovered that this malware attack has infected at least 10 million Android devices. Not only mobile devices, but also smart devices such as smart TVs, tablets, TV boxes, and others connected to the home network are also targets.
How to Deploy BadBox 2.0
According to analysis from the LAT61 Point Wild Threat Intelligence team, the BadBox 2.0 deployment process began even during the production stage. This malware is installed in the firmware of IoT devices, smart TVs, or tablets before the device leaves the factory. Additionally, spread can also occur through “fake” software updates installed when users first use the device.
In this way, the malware will turn into a residential proxy node used to hide the hacker’s real IP address. This makes their activity appear to come from genuine users, making it difficult for security systems to detect.
Consequences and Dangers Caused
Based on the FBI report, if a device is infected, the malware will be active when connected to the network. Data can be directly sent to the hacker’s server in real-time, and user activity can be observed and misused. To prevent this, the FBI recommends that users immediately cut off internet access on infected devices.
Steps Taken by Google
Responding to this threat, Google immediately took quick steps by updating the security features in the Android OS, namely Google Play Protect. This update aims to enable the Android system to automatically detect and block applications related to malware.
Apart from that, Google also took legal action by filing an official lawsuit in New York federal court. In this operation, Google collaborated with large institutions such as the FBI, Human Security, TrendMicro, and the Shadowserver Foundation.
Human Security CEO, Stu Solomon, appreciated Google’s move, stating that this action was an important step in fighting increasingly sophisticated cyber fraud operations.
Signs of a BadBox 2.0 Infected Device
The FBI provided several clues that Android users can identify to find out if their device is infected. Some signs include:
- The device prompts the user to disable the Google Play Protect security service.
- Claims that the device can access premium streaming content for free.
- The device is from an unknown brand or is foreign to the market.
- Users must download the application from a store outside the Google Play Store.
- There is unusual internet traffic, such as app usage notifications that never run, extraneous ads, battery draining quickly, device slowing down, or the camera/microphone activating on its own.
FBI Advisory to Users
If users find these signs, the FBI recommends immediately disconnecting the device’s internet connection, performing a factory reset, deleting suspicious applications, and avoiding installing APKs from outside Google Play. Apart from that, users are also advised to use official antivirus and update the security system regularly.
These steps are critical to preventing widespread infection and minimizing the risk of device misuse.























