Skip to content

FBI issued public warnings

www.ic3.gov • June 20, 2026

The Federal Bureau of Investigation ( FBI ) is issuing this Public Service Announcement to warn the public cyber criminals exploiting Internet of Things ( IoT ) 1 devices connected to networks to conduct criminal activity using the BADBOX 2.0 botnet 2 . Cyber criminals gain unauthorized access to networks through compromised IoT devices, such as TV streaming devices, digital projectors, aftermarket vehicle infotainment systems, digital picture frames and other products. Most of the infected devices were manufactured in China. Cyber criminals gain unauthorized access to networks by either configuring the product with malicious software prior to the users purchase or infecting the device as it downloads required applications that contain backdoors, usually during the set-up process. 3 Once these compromised IoT devices are connected to networks, the infected devices are susceptible to becoming part of the BADBOX 2.0 botnet and residential proxy services 4 known to be used for malicious activity.

BADBOX 2.0 was discovered after the original BADBOX campaign was disrupted in 2024. BADBOX was identified in 2023, and primarily consisted of Android operating system devices that were compromised with backdoor malware prior to purchase. BADBOX 2.0, in addition to compromising devices prior to purchase, can also infect devices by requiring the download of malicious apps from unofficial marketplaces. The BADBOX 2.0 botnet consists of millions of infected devices and maintains numerous backdoors to proxy services that cyber criminal actors exploit by either selling or providing free access to compromised networks to be used for various criminal activity.

The public is urged to evaluate IoT devices in their for any indications of compromise and consider disconnecting suspicious devices from their networks. The FBI has identified potential indicators that may assist in detecting malicious devices. An indicator alone does not accurately determine malicious cyber activity or a crime. The following suspicious activities/indicators do not relate to any individual, group, or business and should be observed in context.

Possible indicators of BADBOX 2.0 botnet activity include:

The following mitigation strategies can be effective steps to minimize exposure to unauthorized residential proxy networks.

Google, Human Security, Trend Micro, and the Shadowserver Foundation contributed to this product.

If you believe you have been a victim of an intrusion, please file a report with the FBI's Internet Crime Complaint Center ( IC3 ) at .

Extracted Entities

Attack Types (1)

Countries (1)

Malware (2)

Platforms (1)