Android TV is a technology platform tracked across 14 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 15, 2026.
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
On March 20, 2026, the U.S. Justice Department, in collaboration with law enforcement from Canada and Germany, announced the dismantling of four significant botnets: Aisuru, KimWolf, JackSkid, and Mossad. These botnets…
Arelion's 2026 DDoS report reveals that the Aisuru botnet is responsible for approximately 33% of global DDoS attack traffic. The botnet, which utilizes over 500,000 compromised IoT and Android devices, has led to…
A Wall Street Journal investigation revealed that low-cost smart devices from Amazon and Walmart, including digital photo frames and streaming boxes, are being shipped with pre-installed malware that routes internet…
Jacob Butler, a 23-year-old from Ottawa, Canada, was arrested for operating the KimWolf DDoS botnet, which infected over 2 million devices worldwide. The botnet utilized a DDoS-for-hire model, launching more than 25,000…
The Kimwolf botnet, which emerged from the Aisuru DDoS botnet in August 2025, has rapidly infected over 2 million unofficial Android TV devices. Its operators exploited residential proxy networks for local control,…
Certain Android TV streaming boxes, particularly the Superbox models, are reported to be part of a botnet that uses users' internet connections for unauthorized activities. These devices require intrusive software that…
The Kimwolf botnet has compromised approximately 1.8 million Android devices worldwide, including smart TVs and tablets. Discovered by security researchers, this sophisticated malware represents a significant threat in…
A report from Zscaler indicates a 67% increase in malware targeting Android devices from June 2024 to May 2025. During this period, 239 malicious apps bypassed Google Play's security filters and were downloaded over 42…
Google's Threat Intelligence Group, in collaboration with industry partners, has disrupted the IPIDEA proxy network, which hijacked consumer devices such as smartphones and desktop computers. This network was used to…