Back Irishmirror.Ie Urgent 'dodgy box' warning issued to Irish households amid serious threat to devices
Millions of TV boxes and similar devices used for illegal streaming could now be riddled with what experts are calling the most severe threat to global internet security in years - the so-called 'Kimwolf' botnet.
Over recent months, cybersecurity experts have been tracking the rapid expansion of this new 'botnet' - a worldwide network of private computers and devices infected with malicious software (malware) and now under the remote control of criminal gangs.
These gangs are using off-brand Android TV boxes as Trojan Horses, sneaking pre-installed malware into the devices and networks of unsuspecting buyers.
In layman's terms - that dodgy box you bought to illegally stream Apple TV or Sky Sports could be a spy in your living room, stealing your most sensitive data and infecting other devices anywhere on the globe.
It's estimated that 400,000 Irish homes now have these so-called 'dodgy boxes', and just last week reports emerged claiming that Sky is seeking permission to use personal data to track individual users of these devices .
These compromised devices can both leak sensitive information from that device and spread the infection to other devices, which then join the 'botnet' as the malware multiplies at an alarming rate.
As many as two million devices worldwide could be infected with the Kimwolf malware, which not only forces compromised systems to further disseminate harmful and abusive traffic - such as ad fraud, account takeover attempts and mass 'content scraping' - but also utilises the internet to launch distributed denial-of-service (DDoS) attacks, reports Cork Beo .
These are large-scale assaults on websites and information systems intended to incapacitate them. They're similar to the attack that targeted The Health Service Executive (HSE) in May 2021.
This ransomware cyberattack, believed to have been masterminded by a Russian-based criminal network, caused all of its IT systems across the country to be shut down for months.
The latest significant botnet concern, known as 'Kimwolf', uses 'residential proxy networks'. These are favoured by people seeking to anonymise their web traffic and localise it to a specific region, thereby circumventing firewalls and other security measures.
The malware that commandeers devices is often concealed within dodgy mobile apps and games. However, one of the primary distribution methods is through unofficial Android TV boxes sold by online merchants.
These are popularly known as 'dodgy boxes' and are used to illegally access and stream subscription video content and premium pay-per-view sports channels like Sky Sports.
Available through Amazon and a host of other online retailers, these devices come under a dizzying array of unbranded models and makes. However, they carry a hidden danger: pre-installed malware that can infect anyone who connects them to their devices and networks.
These TV boxes are now being exploited as Trojan Horses by criminal syndicates, primarily based in Russia and Asia, with the fraudulent activity believed to be costing billions of dollars.
Utilising a concealed tool known as Byteconnect SDK, they can covertly install apps on our devices, earning a referral fee for each one without the device owner ever being aware. They can also run a DDoS-for-hire service, leasing out their entire 2-million-device army to other criminals aiming to disable a major website or network - as was the case with the HSE in 2021.
For those seeking further information on how to safeguard themselves or report suspected fraud, Ireland's National Cybersecurity Centre offers a wealth of online resources here .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
