Google is suing 25 unidentified cybercriminals thought to be from China for running BADBOX 2.0, a major global botnet with 10 million hacked devices. BADBOX uses internet-connected Android devices like smart TVs, streamers, digital frames, car systems, projectors, and inexpensive off-brand tablets made in China and sold worldwide.
It has infected over 10 million uncertified devices that use Android software but do not have Google’s security. On July 11th, Google sued a group called “Does 1-25” for causing serious harm.
By infosecbulletin
/ Saturday , September 12 2026
German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
By infosecbulletin
/ Friday , September 11 2026
GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
By infosecbulletin
/ Thursday , September 10 2026
A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
By infosecbulletin
/ Wednesday , September 9 2026
An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
By infosecbulletin
/ Wednesday , September 9 2026
cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
By infosecbulletin
/ Wednesday , September 9 2026
An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
The lawsuit alleges that the group of cybercriminals tarnishes Google’s reputation when fraud occurs on its platforms, causing the company to expend substantial resources to detect, deter and disrupt BADBOX, which grows every day.
“Google has shown that Defendants – through their participation in, and operation of, the BadBox 2.0 Enterprise – have threatened the security of the internet, including Google platforms, by transmitting malware through the internet to configure, deploy, and operate a botnet,” the court document reads.
Cybercriminals sell access to hijacked devices to other criminals, who use them to conceal large-scale fraud and illegal activities.
“Google is entitled to recover treble damages plus costs and attorney’s fees from the Defendants,” the complaint reads.
Google announced in a blog post that it quickly responded to a threat and updated Google Play Protect to automatically block apps associated with BadBox. However, BADBOX comes preinstalled on the devices at the firmware level and cannot be easily removed. Full report here.