{"id":25835,"date":"2025-07-26T21:06:12","date_gmt":"2025-07-26T21:06:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/25835\/"},"modified":"2025-07-26T21:06:12","modified_gmt":"2025-07-26T21:06:12","slug":"fbi-warning-to-10-million-android-users-disconnect-your-devices-now","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/25835\/","title":{"rendered":"FBI Warning To 10 Million Android Users \u2014 Disconnect Your Devices Now"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/07\/1753563972_271_960x0.jpg\" alt=\"FBI shield seen on a smartphone.\" data-height=\"1714\" data-width=\"2571\" style=\"position:absolute;top:0\"\/><\/p>\n<p class=\"color-body light-text\" role=\"button\">Discconnect now, FBI warns 10 million Android users.<\/p>\n<p>NurPhoto via Getty Images <\/p>\n<p>Update, July 26, 2025: This story, originally published on July 25, has been updated with a statement from the researchers which initially disclosed and disrupted the BadBox 2.0 operation that the FBI and Google are tackling head-on. <\/p>\n<p>In March, I reported that one of the largest botnets of its kind ever detected had impacted over <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/06\/1-million-android-consumer-backdoors-confirmed-what-you-need-to-know\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/06\/1-million-android-consumer-backdoors-confirmed-what-you-need-to-know\/\" target=\"_self\" aria-label=\"a million Android devices\" rel=\"nofollow noopener\">a million Android devices<\/a>. That massive attack was known as BadBox, but it has now been eclipsed by <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/07\/fbi-issues-critical-cyberattack-alert---act-now-as-victims-skyrocket\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/07\/fbi-issues-critical-cyberattack-alert---act-now-as-victims-skyrocket\/\" target=\"_self\" aria-label=\"BadBox 2.0\" rel=\"nofollow noopener\">BadBox 2.0<\/a>, with at least 10 million Android devices infected. Google has taken action to protect users as best it can, as well as launching legal action against the attackers, and the FBI has urged impacted users to disconnect their devices from the internet. Here\u2019s what you need to know.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/26\/fbi-confirms-phantom-hacker-warning-for-all-android-and-iphone-users\/\" target=\"_blank\" aria-label=\"FBI Confirms Phantom Hacker Warning For All Android And iPhone Users\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/26\/fbi-confirms-phantom-hacker-warning-for-all-android-and-iphone-users\/\">ForbesFBI Confirms Phantom Hacker Warning For All Android And iPhone UsersBy Davey Winder<\/a><\/p>\n<p>The FBI, Google And Others Warn Of Android BadBox 2.0 Attacks<\/p>\n<p>The FBI cybersecurity alert, <a class=\"color-link\" href=\"https:\/\/www.ic3.gov\/PSA\/2025\/PSA250605\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.ic3.gov\/PSA\/2025\/PSA250605\" aria-label=\"I-060525-PSA\">I-060525-PSA<\/a>, could not have been clearer: ongoing attacks are targeting everything from streaming devices, digital picture frames, third-party aftermarket automobile infotainment systems and other assorted home smart devices. The devices, all low-cost and uncertified, mostly originating in China, allow attackers to access your home network and beyond by, the FBI warned, \u201cconfiguring the product with malicious software prior to the user\u2019s purchase.\u201d It has also been noted, however, that mandatory \u201csoftware updates\u201d during the installation process can also install a malicious backdoor.<\/p>\n<p>Point Wild\u2019s Threat Intelligence Lat61 Team <a class=\"color-link\" href=\"https:\/\/www.pointwild.com\/threat-intelligence\/badbox-2-0-a-global-iot-botnet-threat\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.pointwild.com\/threat-intelligence\/badbox-2-0-a-global-iot-botnet-threat\" aria-label=\"reverse-engineered\">reverse-engineered <\/a>the BadBox 2 infection chain and, as a result, uncovered new indicators of compromise that have been shared with global Computer Emergency Response Teams, as well as law enforcement. \u201cThis Android-based malware is pre-installed in the firmware of low-cost IoT devices, smart TVs, TV boxes, tablets, before they even leave the factory,\u201d Kiran Gaikwad from the LAT61 team said, \u201cIt silently turns them into residential proxy nodes for criminal operations like click fraud, credential stuffing, and covert command and control (C2) routing.\u201d<\/p>\n<p>Google, meanwhile, confirmed in a <a class=\"color-link\" href=\"https:\/\/blog.google\/technology\/safety-security\/google-taking-legal-action-against-the-badbox-20-botnet\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/blog.google\/technology\/safety-security\/google-taking-legal-action-against-the-badbox-20-botnet\/\" aria-label=\"July 17 statement\">July 17 statement<\/a> that it had \u201cfiled a lawsuit in New York federal court against the botnet\u2019s perpetrators.\u201d Google also said that it has \u201cupdated Google Play Protect, Android\u2019s built-in malware and unwanted software protection, to automatically <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/30\/new-android-google-play-security-update-23-million-apps-blocked\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/30\/new-android-google-play-security-update-23-million-apps-blocked\/\" target=\"_self\" aria-label=\"block BadBox-associated apps\" rel=\"nofollow noopener\">block BadBox-associated apps<\/a>.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/26\/microsofts-critical-password-warning---users-have-5-days-to-act\/\" target=\"_blank\" aria-label=\"Microsoft\u2019s Critical Password Warning \u2014 Users Have 5 Days To Act\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/26\/microsofts-critical-password-warning---users-have-5-days-to-act\/\">ForbesMicrosoft\u2019s Critical Password Warning \u2014 Users Have 5 Days To ActBy Davey Winder<\/a><\/p>\n<p>Human Security Behind Initial BadBox 2.0 Disclosure And Disruption<\/p>\n<p>Human Security, whose Satori Threat Intelligence and Research Team originally both disclosed and disrupted the BadBox 2.0 threat campaign, said at the time that <a class=\"color-link\" href=\"https:\/\/www.humansecurity.com\/newsroom\/human-exposes-badbox-2-0-scheme\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.humansecurity.com\/newsroom\/human-exposes-badbox-2-0-scheme\/\" aria-label=\"researchers believed\">researchers believed<\/a> \u201cseveral threat actor groups participated in BadBox 2.0, each contributing to parts of the underlying infrastructure or the fraud modules that monetize the infected devices, including programmatic ad fraud, click fraud, proxyjacking, and creating and operating a botnet across 222 countries and territories.\u201d If nothing else, that provides some context to the scale of this campaign.<\/p>\n<p>Now, Stu Solomon, the Human Security CEO, has issued the following statement: \u201cWe applaud Google\u2019s decisive action against the cybercriminals behind the BadBox 2.0 botnet our team uncovered. This takedown marks a significant step forward in the ongoing battle to secure the internet from sophisticated fraud operations that hijack devices, steal money, and exploit consumers without their knowledge. Human\u2019s mission is to protect the integrity of the digital ecosystem by disrupting cybercrime at scale, and this effort exemplifies the power of collective defense. We\u2019re proud to have been deeply involved in this operation, working in close partnership with Google, TrendMicro, and the Shadowserver Foundation. Their collaboration has been invaluable in helping us expose and dismantle this threat.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/25\/gmail-and-samsung-account-deletions---why-94-of-you-must-act-now\/\" target=\"_blank\" aria-label=\"Gmail And Samsung Account Deletions Fend Off Zombie Attacks\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/25\/gmail-and-samsung-account-deletions---why-94-of-you-must-act-now\/\">ForbesGmail And Samsung Account Deletions Fend Off Zombie AttacksBy Davey Winder<\/a><br \/>\nFBI Recommendations And Mitigations \u2014 Disconnect Your Devices Now<\/p>\n<p>The FBI has recommended that Android users should be on the lookout for a number of potential clues that your Chinese-manufactured smart device could be infected with BadBox 2.0 malware.<\/p>\n<p> Any requirement for Google Play Protect services to be disabled.<br \/>\n Any streaming devices that are advertised as being fully unlocked or capable of delivering completely free content.<br \/>\n Any devices that come from unrecognized brands.<br \/>\n The use of unknown and unofficial app marketplaces, where software must be downloaded during setup.<br \/>\n Any unexplained or suspicious internet traffic.<\/p>\n<p>When it comes to mitigation, the advice is straightforward: users should \u201cconsider disconnecting suspicious devices from their networks,\u201d the FBI said.<\/p>\n","protected":false},"excerpt":{"rendered":"Discconnect now, FBI warns 10 million Android users. NurPhoto via Getty Images Update, July 26, 2025: This story,&hellip;\n","protected":false},"author":2,"featured_media":25836,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[16217,16220,4223,16216,16221,16219,16214,16215,16213,59,16218,86,56,54,55],"class_list":{"0":"post-25835","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-android-attack-confirmed","9":"tag-android-malware-attack","10":"tag-android-security","11":"tag-badbox","12":"tag-badbox-2-0","13":"tag-cisa","14":"tag-fbi-android-warning","15":"tag-fbi-attack-warning","16":"tag-fbi-warning","17":"tag-gb","18":"tag-google-confirms-android-attacks","19":"tag-technology","20":"tag-uk","21":"tag-united-kingdom","22":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/25835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=25835"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/25835\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/25836"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=25835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=25835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=25835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}