BadBox (2023-2024)
Researchers at Human Security found malware preinstalled on cheap Android TV boxes and phones sold through online marketplaces. The malware ran ad fraud and turned devices into residential proxies for relaying malicious traffic.
Google disrupted the operation in part by cutting off communication channels, and some distribution networks were shut down.
Established the pattern of budget Android hardware being compromised somewhere in the supply chain for ad fraud and proxy abuse.
Midnight Mimosa follows the same playbook: firmware-level compromise of low-cost devices, monetized through ad fraud and residential proxy relay.
