Skip to content

Google files lawsuit against BadBox 2.0 botnet

Kateryna Skrypnyk
Written by Kateryna Skrypnyk

Recently, Google researchers, in collaboration with HUMAN Security and Trend Micro, discovered BadBox 2.0, the largest known botnet affecting Android devices connected to the Internet. Continuing its efforts to crack down on cybercriminals, Google filed a lawsuit in New York federal court against the botnet’s organisers.

The company also announced its cooperation with the FBI to combat illegal activities. The FBI began working to eliminate BadBox 2.0 even before Google filed its lawsuit in June. Through their joint efforts, the organisations aim to enhance the protection of consumers and businesses worldwide.

Google reports 10 million infected devices

According to a statement on Google’s official website, the BadBox 2.0 botnet infected more than 10 million uncertified devices running open-source Android software (Android Open Source Project). Cybercriminals distributed pre-installed malware and used it for digital crimes.

A botnet is a network of computers or Internet-connected devices infected with malware that is controlled by a single party. In this case, it ran in the background on devices, mimicking the behaviour of a real user. According to the CPA.RIP website, the botnet performed the following actions:

  • hidden downloading of background ads through fake apps;
  • hidden launching of gambling sites;
  • simulation of clicks on ads.

The devices involved in the cybercriminal network bypassed Google’s standard security checks because they were not certified on Google Play.

Google’s advertising traffic quality team identified this threat and took action. The company updated Google Play Protect, the malware protection system built into Android. With its help, apps associated with BadBox will be blocked automatically.

‘While these measures have ensured the safety of users and partners, this lawsuit further weakens the criminal activity behind the botnet by preventing attackers from committing new crimes and fraud,’ Google said.

Methods of implementing BadBox malware

According to the lawsuit filed on July 17 in a New York federal court, 25 anonymous individuals from China allegedly used the BadBox 2.0 botnet. In addition to smartphones, they infected TVs, set-top boxes and other AOSP-based devices. Criminals deployed software during the manufacturing stage of devices for sale through marketplaces, as well as when installing applications from third-party sources.

The BadBox 2.0 botnet is an updated version of BadBox, which was taken down by German law enforcement in 2024. The first BadBox campaign, discovered in 2023, similarly infiltrated Android operating systems. At that time, Germany managed to block the domains and control infrastructure of the network, but China managed to restore it.

Now, legal action against cybercriminals is justified not only by the prevention of crime, but also by the preservation of the Android ecosystem’s image.

This is not the first such cyberattack for Google. In 2021, the company eliminated Glupteba, the largest botnet at the time, which affected about a million Windows PCs.

Glupteba – the BadBox’s predecessor

In December 2021, Google shut down a large network of computers infected with the Glupteba malware, according to Engadget. At that time, the team tracked down the organisers of Glupteba in Russia. The company sued them in the hope of setting a precedent and creating legal and liability risks for botnet operators to prevent similar activities in the future.

According to the company, the network expanded by approximately 1,000 devices per day. Glupteba operators used malware to steal personal data, mine cryptocurrencies, and redirect traffic. According to The Washington Post, hackers also used some of Google’s own services to distribute malware.

To block more than 1,000 accounts used to organise the botnet, Google coordinated its actions with internet infrastructure providers. The use of blockchain technology to protect the criminal network from being completely shut down complicated the operation.

‘Unfortunately, the use of blockchain technology as a mechanism for ensuring fault tolerance deserves attention and is becoming an increasingly common practice among cybercriminal organisations,’ Google said at the time.

This article was first published in Russian on 28 July 2025.

Subscribe HERE to SiGMA’s Top 10 News countdown and SiGMA’s weekly newsletter to stay up to date with all the latest iGaming News from the world’s iGaming authority, and benefit from subscriber-only offers. 

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.